Skip to content
01 / Applicability 02 / Control focus 03 / VISIONCYBERX
VISIONCYBERX / GRCEU law · assess applicability
NIS 2 DIRECTIVE
NIS2
EU directive on cybersecurity governance and incident reporting for essential and important entities.
Scope comes first.
First establish entity and service scope under the relevant national transposition. Governance, proportionate risk measures and reporting duties follow the applicable law.
What to map.
- Entity classification and leadership
- Risk measures and supply-chain security
- Incident decisions and reporting
Our approach.
We map obligations to control owners, suppliers and operational evidence.
Interpretation
This overview is not a certification or legal determination. Verify the current official text and assess your entity, services, country and contractual obligations.