NIS2 Readiness Guide
Last updated: 21 May 2026
This guide helps NetSenX customers understand their obligations under the NIS2 Directive (Directive (EU) 2022/2555) and how NetSenX supports compliance.
Important: This guide is for informational purposes only and does not constitute legal advice. Customers are responsible for determining their own NIS2 obligations with qualified legal counsel.
1. Entity Classification Helper
NIS2 categorizes entities into Essential and Important based on sector and size.
Essential Entities (Annex I)
| Sector | Examples | Size Threshold |
|---|---|---|
| Energy | Electricity, oil, gas, hydrogen, district heating | Large (250+ employees or EUR 50M+ turnover) |
| Transport | Air, rail, water, road | Large |
| Banking | Credit institutions | Large |
| Financial Market Infrastructure | Trading venues, CCPs | Large |
| Health | Hospitals, laboratories, pharma, medical devices | Large |
| Drinking Water | Water supply and distribution | Large |
| Wastewater | Wastewater treatment | Large |
| Digital Infrastructure | DNS, TLDs, cloud, data centers, CDNs, trust services | Large |
| ICT Service Management (B2B) | MSPs, MSSPs | Large |
| Public Administration | Central government entities | N/A |
| Space | Space operations | Large |
Important Entities (Annex II)
| Sector | Examples | Size Threshold |
|---|---|---|
| Postal and Courier | Postal service providers | Medium (50+ employees or EUR 10M+ turnover) |
| Waste Management | Waste collection and treatment | Medium |
| Chemical | Manufacturing and distribution | Medium |
| Food | Production, processing, distribution | Medium |
| Manufacturing | Medical devices, electronics, machinery, vehicles | Medium |
| Digital Providers | Online marketplaces, search engines, social platforms | Medium |
| Research | Research organizations | Medium |
How NetSenX Helps
NetSenX provides automated entity classification tools within the compliance dashboard, helping you determine whether your organization falls under Essential or Important entity categories based on your sector, size, and operations.
2. Art. 21 Cybersecurity Measures Mapping
NIS2 Art. 21 requires entities to implement appropriate and proportionate technical, operational, and organizational measures. Here is how NetSenX maps to each requirement:
| Art. 21 Measure | NIS2 Requirement | NetSenX Capability |
|---|---|---|
| (a) Risk analysis and IS policies | Policies on risk analysis and information system security | Risk scoring dashboard, policy templates, asset inventory |
| (b) Incident handling | Incident handling procedures | Automated incident detection, classification, and response workflows |
| (c) Business continuity | Business continuity, backup management, disaster recovery, crisis management | High-availability architecture, automated backup monitoring |
| (d) Supply chain security | Supply chain security including supplier assessments | Third-party risk monitoring, vendor traffic analysis |
| (e) Network security | Security in network and information system acquisition, development, maintenance, including vulnerability handling and disclosure | Continuous network monitoring, vulnerability correlation, CVD policy |
| (f) Effectiveness assessment | Policies and procedures to assess the effectiveness of cybersecurity risk management measures | Compliance scoring, automated control testing, audit reports |
| (g) Cyber hygiene and training | Basic cyber hygiene practices and cybersecurity training | Security posture dashboard, user behavior analytics |
| (h) Cryptography | Policies and procedures regarding the use of cryptography and encryption | Encrypted traffic analysis (without decryption), TLS compliance monitoring |
| (i) HR and access control | Human resources security, access control policies, asset management | Network access monitoring, identity-aware traffic analysis |
| (j) MFA and secure comms | Use of multi-factor authentication, secured voice/video/text, secured emergency communication | Authentication monitoring, anomaly detection on comms channels |
3. Incident Reporting Workflow (Art. 23)
NIS2 Art. 23 establishes strict incident reporting timelines. NetSenX automates and supports each phase:
Reporting Timeline
Incident Detection
|
v
[0-24 hours] ──── Early Warning to CSIRT/Competent Authority
| - Is the incident likely caused by unlawful/malicious acts?
| - Could it have cross-border impact?
|
v
[0-72 hours] ──── Incident Notification to CSIRT/Competent Authority
| - Initial assessment of severity and impact
| - Number of affected users/services
| - Indicators of compromise (IoCs)
|
v
[Upon request] ── Intermediate Report
| - Updated status and handling measures
|
v
[1 month max] ─── Final Report to CSIRT/Competent Authority
- Detailed description of the incident
- Root cause analysis
- Mitigation measures applied
- Cross-border impact assessment
NetSenX Breach SLA
As your NDR provider, we commit to the following SLAs for incidents detected by the NetSenX platform:
| Phase | SLA | NIS2 Requirement |
|---|---|---|
| Early Warning | Within 24 hours of detection | Art. 23(4)(a) — 24 hours |
| Incident Notification | Within 72 hours of detection | Art. 23(4)(b) — 72 hours |
| Intermediate Report | Upon request from authority | Art. 23(4)(c) |
| Final Report | Within 1 month of notification | Art. 23(4)(d) — 1 month |
How NetSenX Automates Reporting
- Detection: AI-driven anomaly detection identifies significant incidents in real-time
- Classification: Automated severity scoring against NIS2 thresholds
- Early Warning Generation: Pre-filled early warning template with IoCs, within 24 hours
- Notification Preparation: Structured incident notification with impact assessment
- Evidence Collection: Automated PCAP, flow data, and timeline evidence gathering
- Final Report Assembly: Comprehensive report template with root cause analysis
4. Customer Obligations
Important: While NetSenX provides tools and automation to support NIS2 compliance, customers bear the ultimate responsibility for:
- Determining their entity classification (Essential or Important)
- Registering with the relevant national authority in their Member State
- Submitting incident reports to their national CSIRT or competent authority
- Implementing all Art. 21 measures appropriate to their risk profile
- Conducting regular risk assessments and updating security measures
- Ensuring supply chain security across all vendors, not only NetSenX
- Board-level oversight — NIS2 Art. 20 requires management bodies to approve and oversee cybersecurity measures
NetSenX does not submit incident reports on behalf of customers. We provide the data, automation, and templates to make compliance efficient, but the legal obligation rests with the entity.
5. Resources
- NIS2 Directive full text (EUR-Lex)
- ENISA NIS2 guidance
- NetSenX Security Disclosure Policy
- NetSenX DPA Template
TriStiX S.L. — NIF B-26925016 Registered in the Registro Mercantil de Alicante, Spain
This document does not constitute legal advice. Consult qualified legal counsel for NIS2 compliance guidance specific to your organization.