Abstract network of glowing blue nodes lit by an unbroken light ribbon on one side and spaced light pulses on the other, representing continuous versus periodic monitoring

NIS2 Continuous Monitoring: The Rule Says “Continuously or in Periodic Intervals” — Here’s When Each Wins

Point 3.2.2 of the Annex to Commission Implementing Regulation (EU) 2024/2690 is the sentence that settles this question, and almost nobody quotes it: “To the extent feasible, monitoring shall be automated and carried out either continuously or in periodic intervals, subject to business capabilities.”

Read the middle of it again. The Regulation sets continuous and periodic monitoring side by side as alternatives and states no preference. A documented, risk-justified interval is not a gap under that clause, and every guide telling you NIS2 requires continuous monitoring of your network is reporting a conclusion the binding text does not carry.

What is true is narrower and more useful. Two other clauses in the same Annex impose continuous duties with no qualifier at all — and neither is about your network. Meanwhile the Directive’s enforcement machinery prices detection latency without once using the word “monitoring”. That is where the real pressure toward continuous assurance comes from, and it points somewhere other than where the market is looking.

This article provides general information only and does not constitute legal or regulatory advice. NIS2 implementation varies by member state and sector — always verify requirements against your national transposition law and your national competent authority’s guidance.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Does This Apply to You?

Two questions decide it: whether NIS2 catches your organisation, and whether the Implementing Regulation binds you directly or only sets the benchmark you are measured against. That distinction matters here, because every clause quoted below sits in the Implementing Regulation rather than the Directive.

Your situation What governs your monitoring How to read point 3.2.2
Medium or large entity in an Annex I or II sector and in one of the eleven digital categories named in Article 21(5) — DNS, TLD registries, cloud, data centres, CDNs, MSPs, MSSPs, online marketplaces, search engines, social platforms, trust service providers CIR 2024/2690 binds you directly It is law. The choice between continuous and periodic is yours — and so is the burden of documenting why
Medium or large entity in an Annex I or II sector, outside those eleven Article 21(2) as transposed nationally; the CIR is the most detailed statement of what those measures mean Treat it as the reference standard supervisors work from, not a rule binding on its own terms
Below the size thresholds but caught by an Article 2(2) special case National transposition law As above — confirm with your national competent authority, since scope rules vary

Reporting portals, additional thresholds and sector rules differ by member state. Confirm anything jurisdictional with your national competent authority before acting on it.

What “Continuous” Actually Means in the Text

In plain terms: the word appears five times in the whole Annex, and only twice does it create an obligation you cannot argue your way out of. Neither of those two is the one everyone is buying tooling for.

Every occurrence, with the qualifier the drafters attached. This is a reading of the legal text, not a maturity model.

Annex point What has to be continuous Qualifier in the text Effect
2.1.2(h) “continuously monitor the implementation of the risk treatment measures” None. It sits inside 2.1.2’s bare “the relevant entities shall” Binding continuous duty
13.3.2(d) “continuously monitor their premises for unauthorised physical access” None. The opener is “For that purpose, the relevant entities shall” Binding continuous duty
3.2.2 Monitoring of network and information systems “To the extent feasible”, “subject to business capabilities”, and framed as “either continuously or in periodic intervals” A documented choice
11.7.1 “continuous authentication mechanisms”, offered as an alternative to multi-factor authentication “where appropriate, in accordance with the classification of the asset to be accessed” Optional technique
13.1.2(f) “continuous effectiveness” of power, climate control and connectivity The 13.1.2 opener is “where appropriate” Conditional

So the Implementing Regulation obliges you to watch your car park without a break, and to keep a live view of whether your risk-treatment actions are actually being carried out — but explicitly permits you to scan your network on a schedule. The sixth appearance of the word, in Recital 29, concerns redundant air conditioning and says entities “could consider” it.

The Directive is quieter still. “Continuous” occurs twice: Recital 32, on the continuous operation of the DNS, and Article 21(2)(j), where “continuous authentication solutions” are one option “where appropriate”. The only mention of real-time monitoring anywhere is Article 11(3)(a) — a task assigned to CSIRTs, who provide that assistance to entities “upon request”. A service offered to you, not a duty imposed on you.

Set against that, the Annex uses the phrase “at planned intervals” thirty times and “at least annually” three times. The drafters had a default rhythm in mind, and it was periodic.

Germany’s federal cybersecurity authority splits it the same way. In the BSI IT-Grundschutz Compendium, module DER.1 makes enabling built-in detection a Basic requirement — “If IT systems or applications have features that can be used to detect security-relevant events, these MUST be enabled and used” (DER.1.A5). Watching them constantly is a Standard requirement, one tier down: “All log data SHOULD be actively monitored and analysed as constantly as possible” (DER.1.A6). Switching detection on is a must; never taking your eyes off it is a should. IT-Grundschutz is a national baseline standard, not NIS2 law.

The Pressure the Text Creates Anyway

If the frequency is your choice, why is the whole market converging on continuous? Because four provisions make slow discovery expensive, and none of them regulates monitoring directly.

Article 32(7)(b) makes the duration of the infringement a factor. When competent authorities take enforcement measures they must take due account, as a minimum, of eight listed elements; the second is how long the breach ran. Article 34(3) carries the same list into fine-setting — ceilings may reach up to at least €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important entities, whichever is higher, subject to national implementing law and supervisory discretion. Two organisations with an identical control failure are therefore not identically exposed: the one that found it in three days and the one that found it at the annual review are separated by roughly eleven months of aggravating factor. That is the economic case for continuous assurance, and the clearest place the Directive puts a price on elapsed time.

Article 21(4) starts a clock you cannot start yourself. An entity “that finds that it does not comply” with the Article 21(2) measures must take corrective action “without undue delay”. The trigger is finding, so the deadline is fast while the search preceding it is unregulated. A programme that looks once a year has not breached 21(4) — it has arranged to trigger it as late as possible, which is exactly the state 32(7)(b) reads back to it.

Article 23(4)(a) starts its 24-hour early-warning clock “of becoming aware”, not at compromise. Late detection does not breach the reporting deadline — it means the significance assessment and early warning are drafted from a cold start on an incident that has had weeks to spread, and the seriousness and damage factors in Article 32(7)(a) and (d) notice the difference.

Article 32(4)(g) is the regulator’s own continuous-monitoring instrument. Enforcement powers for essential entities include designating “a monitoring officer with well-defined tasks for a determined period of time to oversee the compliance of the entities concerned with Articles 21 and 23”. If your assurance rhythm does not satisfy a supervisor, the Directive lets them impose one — alongside the Article 32(2) powers of regular and targeted audits, ad hoc audits after a significant incident, and security scans.

Article 20(1) closes the loop from inside: management bodies must approve the risk-management measures, oversee their implementation, and can be held liable for infringements. Oversight of an implementation is a present-tense verb applied to a moving object. On building that reporting line, see our guide to NIS2 audit readiness.

Six Control Areas Where Continuous Earns Its Cost

Continuous instrumentation is not free, and applying it everywhere is how monitoring programmes become unaffordable and then get quietly abandoned. The question per control is not “how important is this?” but “how fast does the answer go stale?” Six areas fail that test badly enough to justify the spend. The first two are legal obligations; the rest are recommendations built on the interval clauses named beside them.

Control area Governing point Why the interval matters
Risk-treatment implementation status 2.1.2(h) — legal rule, unqualified The Annex says continuously, full stop. A quarterly progress slide is not a live view of implementation, and 2.3.3 requires the results to reach the management bodies
Physical access to premises 13.3.2(d) — legal rule, unqualified Also non-negotiable, and routinely overlooked because it is filed under facilities rather than security
Privileged access and authentication events 3.2.3(d), (e) — log categories; 11.3 privileged accounts Credential misuse is measured in minutes. ENISA’s indicative thresholds under 3.2.4 include three or more account lockouts within 15 minutes and two or more privilege escalations within 24 hours — invisible to a weekly review
Configuration drift on critical systems 6.3.2(b) — enforce secure configurations “for newly installed systems as well as for systems in operation over their lifetime” “Over their lifetime” is a continuous phrase inside a periodic chapter. A baseline checked at planned intervals tells you the state on the day you checked
Vulnerability exposure 6.10.2(b) scans “at planned intervals”; 6.10.2(c) critical items addressed “without undue delay” The scan is expressly periodic, the remediation clock immediate. A long interval does not breach (b) — it means (c) starts late, and 32(7)(b) counts the gap
Supplier and service-provider changes 5.1.6 — monitor and act on changes in suppliers’ practices “at planned intervals and when significant changes… occur” The trigger is external and unannounced. Interval-only review means you hear about your provider’s breach from the news

Everything not on this list is a legitimate candidate for a planned interval, documented against the risk assessment carried out under point 2.1.

Automated Controls vs Manual Evidence: The Half-Life Test

The automation debate is usually framed as which controls can be automated — an axis already covered in our guide to automated NIS2 compliance. The sharper question is how fast a piece of evidence stops being true after you collect it: its half-life. Automate where the half-life is short; collect manually where it is long.

A signed board resolution approving the risk-management measures has a half-life measured in years: it is a historical fact, and re-collecting it monthly adds nothing. A screenshot of firewall rules lasts about one change window. An access-rights export is stale the moment somebody joins, leaves or changes team — which is why 11.5.4 requires identities to be reviewed regularly and deactivated “without delay” when no longer needed. Collecting short-half-life evidence by hand produces a document that was accurate at capture and misleading by the time an auditor reads it. That is worse than no evidence, because it invites a finding about the accuracy of your records rather than the state of your controls.

The trade-off runs the other way too, and this is the part automation vendors skip. Automated evidence is precise but narrow: it captures the state of a system, never the judgement applied to it. Point 7.2 requires you to determine what is monitored, by what methods, when monitoring happens, who is responsible, when the results are analysed and who analyses them — six determinations, every one a decision rather than telemetry, and no collector emits any of them. Our guide to NIS2 security metrics and KPIs covers that measurement layer. Risk acceptance is the same: a pipeline can prove a vulnerability went unpatched for 40 days, but only a person can produce the documented, substantiated reasoning that makes those 40 days defensible.

ENISA’s guidance under point 3.2.2 lists SIEM systems and EDR or XDR tooling as examples of evidence, not requirements — which is exactly the status they have. For the tooling question on its own, see our NIS2 SIEM requirements guide; for the document as a whole, our overview of the ENISA technical implementation guidance, which is non-binding throughout.

What Each Role Should Do Next

CISO or IT security manager. Produce a one-page frequency register: each control area, its governing Annex point, the rhythm you chose, and the risk-assessment finding behind that choice. Start with the two unqualified continuous duties, 2.1.2(h) and 13.3.2(d) — they are the likeliest to be missing, and the second is probably owned by facilities.

Compliance officer. Your exposure is documentary. Point 2.2.3 requires compliance monitoring “at planned intervals and when significant incidents or significant changes to operations or risks occur”, so those trigger conditions must be written down and demonstrably fired at least once. Then check that compliance-monitoring and point 7 measurement results actually reach the management bodies, as 2.3.3 requires.

Board or senior management. Ask one question at the next review: how long would it take us to find out that a control we approved has stopped working? That number is what Article 32(7)(b) is eventually applied to — and Article 20(1) makes overseeing the implementation your obligation, not the CISO’s.

Smaller entity without a security operations team. Point 3.2.2’s “subject to business capabilities” is there for you. Enable the detection features already in the systems you own, set the alarm thresholds 3.2.4 asks for, pick a review interval you will genuinely keep, and write down why it suits your risk profile. A kept quarterly rhythm with a documented rationale is more defensible than an unkept continuous ambition.

Frequently Asked Questions

Does NIS2 require continuous monitoring?

Not of your network and information systems. Point 3.2.2 of the Annex to CIR 2024/2690 offers the two as alternatives — “either continuously or in periodic intervals, subject to business capabilities”. Two other points in the same Annex do impose unqualified continuous duties: 2.1.2(h), on the implementation of risk-treatment measures, and 13.3.2(d), on physical access to premises. National transposition may be stricter, so confirm with your competent authority.

Is a quarterly vulnerability scan enough?

Point 6.10.2(b) requires scans “at planned intervals”, so quarterly is compatible with the clause on its face, provided the interval is justified by your risk assessment and you record the results. The pressure sits in the next sub-point: 6.10.2(c) requires vulnerabilities identified as critical to be addressed “without undue delay”. A long interval delays the start of that obligation rather than removing it, and Article 32(7)(b) treats duration as a factor.

Do we have to buy a SIEM to comply?

No provision names one. ENISA lists SIEM, EDR and XDR under point 3.2.2 as examples of evidence an entity might present, and that guidance is expressly non-binding. The binding text asks for procedures and tools that detect events, monitoring designed to minimise false positives and false negatives, the log categories in 3.2.3, alarm thresholds under 3.2.4, and a qualified response when an alarm fires.

What does a supervisor actually look at?

Under Article 32(2), competent authorities may subject essential entities to on-site inspections and off-site supervision, regular and targeted audits by an independent body or the authority itself, ad hoc audits justified by a significant incident, and security scans. Article 32(4)(g) additionally lets them designate a monitoring officer to oversee compliance with Articles 21 and 23 for a set period. Article 32(8) requires preliminary findings to be notified, with a reasonable window to respond, before measures are adopted.

How do we document the choice between continuous and periodic?

In practice three things travel together: the control, the interval, and the point 2.1 risk-assessment finding that justifies it. Point 7.2 then asks you to determine what is monitored, by what methods, when, who is responsible, when results are analysed, and who analyses them. Write those six down per control area and the frequency question answers itself for an auditor.

Sources

  1. Directive (EU) 2022/2555 (NIS2) — EUR-Lex — Articles 11(3)(a), 20(1), 21(2), 21(4), 21(5), 23(4)(a), 32(2), 32(4)(g), 32(7), 32(8), 34(3)–(5); Recital 32
  2. Commission Implementing Regulation (EU) 2024/2690 — EUR-Lex — Annex points 2.1.2(h), 2.1.4, 2.2.1–2.2.3, 2.3.3, 3.2.1–3.2.4, 5.1.6, 6.3.2(b), 6.10.2, 7.1–7.3, 11.5.4, 11.7.1, 13.1.2(f), 13.3.2(d); Recital 29
  3. ENISA, Technical Implementation Guidance on cybersecurity risk-management measures, version 1.0 (June 2025) — non-binding guidance and evidence examples under Annex points 3.2.2 and 3.2.4
  4. BSI, IT-Grundschutz Compendium (English edition), module DER.1 “Detecting Security-Relevant Events”, requirements DER.1.A5 and DER.1.A6 — bsi.bund.de (de-linked: the BSI download endpoint rejects automated requests). A national baseline standard, not NIS2 law

This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: