Directive (EU) 2022/2555

NIS2, for a software company

Since 18 October 2024 NIS2 reaches a company by its entity type and its size, 67 types across the two Annexes; the question is which one you are.

Which type of entity in Annex I or II are you?
How large is the company?

Answer above to read the determination for your case; the full tool takes your answers with it.

Continue in the free determination

Five tools, free, no account

Every free template on one page

Two instruments and a registry

The Directive, applied from

18 October 2024

A directive binds through national law. 25 of the 27 member states had communicated at least one transposing measure to the Commission on 12 September 2026; the register names the act each calls its NIS2 law.

The Implementing Regulation

13 sections, direct effect

Implementing Regulation (EU) 2024/2690 fixes the technical measures and the incident thresholds for cloud and other digital providers, the same text in every state, no transposition needed. It was written from ISO 27001.

The registry, by

17 January 2025

Cloud computing, data centre, managed service, marketplace, search and social networking providers had to submit their name, addresses, member states served and IP ranges to their competent authority for ENISA's registry, under Article 27.

16 articles, from the primary sources

Which law, and what it adds to ISO 27001

Reporting

What buyers ask for

Eleven of the thirteen Article 21 sections are an ISO 27001 system; the other two are records

StandardOS keeps the ISO 27001 records that answer eleven of the Implementing Regulation's thirteen sections, the incident record the Article 23 clocks run from, and the evidence a supervisor or an auditor asks for, in one workspace, in six languages.

Dates are read from the Directive's Articles 27 and 41 and never typed on this page. This is not legal advice, and the Directive is the text to read: Directive (EU) 2022/2555.