NIS2 — Network and Information Security Directive

NIS2 — Network and Information Security Directive — 92% of in-scope requirements covered.

42 requirements · 42 in scope (37 enforced · 1 designed · 4 advisory). The 92% is weighted over the in-scope base.

Source: Directive (EU) 2022/2555 — Article 20 (Governance / management-body accountability + liability + training), Article 21 (Risk-management measures: 10 categories with sub-clauses + 21(3) supplier-vulnerability + 21(4) corrective measures), Article 23 (Reporting obligations: 4-stage timeline + voluntary disclosure + recipient notification + CSIRT response), Article 32 (Supervision and enforcement of essential entities). Deep-mapping expanded 2026-05-29 (Wave-Ralph-B) from 15 to 46 with full Article 21 sub-clause decomposition and Article 32 supervisory powers. · License: EU directives are published in the Official Journal and reproducible for non-commercial reference purposes.

By category

CategoryReqsEnforcedDesignedAdvisoryDeferredCoverage
Article 21 — Risk-management measures (detailed)1212000100%
Article 21 — Risk-management measures8701091%
Article 23 — Reporting obligations (detailed)8701091%
Article 23 — Reporting obligations22000100%
Article 20 — Governance (detailed)33000100%
Article 24 — Governance11000100%
Article 32 — Supervision and enforcement (essential entities)8512075%

Every requirement → the KYE™ artefact that enforces it

IDTitleStatusKYE™ enforcement
nis2.A21.2.aArticle 21(2)(a) — Policies on risk analysis and information system security, encompassing technical, operational and organisational measures based on an all-hazards approach.enforcedaudit_events: kye.risk.score.v1, kye.risk_assessment.v1, kye.compliance.attestation.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nis2.A21.2.bArticle 21(2)(b) — Incident handling, including procedures for detection, analysis, containment, eradication, recovery and post-incident review.enforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.signal.revocation.cascaded.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
workers: kye-incident-detector, kye-authority-revocation-orchestrator
nis2.A21.2.cArticle 21(2)(c) — Business continuity, including backup management and disaster recovery, and crisis management.enforcedaudit_events: kye.spof.path_to_full.v1, kye.audit_retention_policy.v1, kye.compliance.attestation.v1
engines: internal, internal, internal
workers: kye-d1-backup-worker, kye-dr-orchestrator, kye-audit-archiver
registries: internal
constitution_refs: constitution/51-NO-SPOF.md, constitution/30-AUDIT-WORM-RETENTION.md
nis2.A21.2.dArticle 21(2)(d) — Supply-chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.enforcedaudit_events: kye.subprocessor.v1, kye.federation.cross_org_delegation.v1, kye.agent.mcp_allow_list.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/52-DELEGATED-AGENT-BINDING.md, constitution/51-NO-SPOF.md
nis2.A21.2.eArticle 21(2)(e) — Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.enforcedaudit_events: kye.signal.drift.detected.v1, kye.evidence.tool_call_pin.v1, kye.compliance.attestation.v1, kye.ci.failure.classified.v1
engines: internal, internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/52-DELEGATED-AGENT-BINDING.md, constitution/13-RESILIENCE-LOOP.md, constitution/41-ERROR-HORIZONS.md
workers: kye-drift-detector
nis2.A21.2.fArticle 21(2)(f) — Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.enforcedaudit_events: kye.assurance.audit_pilot.v1, kye.assurance.audit_replay_report.v1, kye.compliance.attestation.v1
engines: internal, internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
workers: kye-audit-replay-orchestrator
nis2.A21.2.gArticle 21(2)(g) — Basic cyber-hygiene practices and cybersecurity training.enforcedaudit_events: kye.training.completion.v1, kye.comms.dispatched.v1
engines: internal, internal, internal
constitution_refs: constitution/10-PARTNER.md, constitution/39-LEARN-RAIL.md
nis2.A21.2.hArticle 21(2)(h) — Policies and procedures regarding the use of cryptography and, where appropriate, encryption.enforcedaudit_events: kye.audit.event.v1, kye.compliance.attestation.v1, kye.signing.multisig_envelope.v1
engines: internal, internal, internal
registries: internal
constitution_refs: constitution/51-NO-SPOF.md
nis2.A21.2.iArticle 21(2)(i) — Human-resources security, access-control policies and asset management.enforcedaudit_events: kye.authority.grant.v1, kye.purpose.permission.v1, kye.signal.revocation.cascaded.v1, kye.relationship.member_of.v1, kye.revocation.event.v1
engines: internal, internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
workers: kye-pdp, kye-authority-revocation-orchestrator
nis2.A21.2.jArticle 21(2)(j) — Use of multi-factor authentication or continuous authentication solutions, secured voice / video / text communications and secured emergency communication systems where appropriate.enforcedaudit_events: kye.authority.grant.v1, kye.purpose.permission.v1, kye.signing.multisig_envelope.v1
engines: internal, internal, internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/51-NO-SPOF.md
nis2.A21.3Article 21(3) — When considering which appropriate measures to take under paragraph 2(d), entities shall take into account the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers and service providers, including their secure development procedures.enforcedaudit_events: kye.subprocessor.v1, kye.compliance.attestation.v1, kye.risk.score.v1
engines: internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nis2.A21.4Article 21(4) — Where an entity finds it does not comply with the measures provided for in paragraph 2, it shall, without undue delay, take all necessary, appropriate and proportionate corrective measures.enforcedaudit_events: kye.signal.drift.detected.v1, kye.signal.incident.opened.v1, kye.signal.revocation.cascaded.v1
engines: internal, internal, internal
constitution_refs: constitution/34-RECONCILIATION-ENGINE.md, constitution/41-ERROR-HORIZONS.md
nis2.A21.1Policies on risk analysis and information system security.enforcedaudit_events: kye.risk.score.v1, kye.risk.authority_register.v1
engines: internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
rule_packs: kye:rule-pack:public-sector-governance
nis2.A21.2Incident handling.enforcedaudit_events: kye.signal.incident.opened.v1, kye.signal.incident.closed.v1, kye.signal.revocation.cascaded.v1
engines: internal, internal
workers: kye-incident-detector, kye-authority-revocation-orchestrator
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nis2.A21.5Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.enforcedaudit_events: kye.signal.drift.detected.v1, kye.ci.failure.classified.v1
engines: internal
workers: kye-drift-detector
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/41-ERROR-HORIZONS.md
nis2.A21.6Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.enforcedaudit_events: kye.compliance.attestation.v1, kye.assurance.audit_pilot.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
workers: kye-audit-replay-orchestrator
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nis2.A21.7Basic cyber hygiene practices and cybersecurity training.advisoryaudit_events: kye.training.completion.v1
constitution_refs: constitution/10-PARTNER.md
nis2.A21.8Policies and procedures regarding the use of cryptography and, where appropriate, encryption.enforcedaudit_events: kye.signing.multisig_envelope.v1
engines: internal, internal, internal
constitution_refs: constitution/51-NO-SPOF.md
nis2.A21.9Human resources security, access control policies and asset management.enforcedaudit_events: kye.authority.grant.v1, kye.purpose.permission.v1, kye.revocation.event.v1
engines: internal, internal, internal
workers: kye-pdp, kye-authority-revocation-orchestrator
constitution_refs: constitution/12-PURPOSE-PERMISSION.md
nis2.A21.10The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.enforcedaudit_events: kye.signing.multisig_envelope.v1, kye.purpose.permission.v1
engines: internal, internal
constitution_refs: constitution/12-PURPOSE-PERMISSION.md, constitution/51-NO-SPOF.md
nis2.A23.1.earlyArticle 23(4)(a) — Early-warning notification within 24 hours of becoming aware of a significant incident, indicating whether the significant incident is suspected of being caused by unlawful or malicious acts or could have a cross-border impact.enforcedaudit_events: kye.signal.incident.opened.v1, kye.comms.dispatched.v1, kye.cross_border.transfer.v1
engines: internal, internal
workers: kye-incident-detector, kye-comms-engine-worker
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
nis2.A23.1.updateArticle 23(4)(b) — Incident notification (within 72 hours) updating the early warning and providing an initial assessment of the significant incident, including its severity, impact, and where available the indicators of compromise.enforcedaudit_events: kye.signal.incident.opened.v1, kye.evidence.pack.v1, kye.risk.score.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
workers: kye-incident-detector
nis2.A23.1.intermediateArticle 23(4)(c) — Intermediate report (upon request of the CSIRT or, where applicable, the competent authority) on relevant status updates.enforcedaudit_events: kye.comms.dispatched.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/38-COMMS-RAIL.md
nis2.A23.1.finalArticle 23(4)(d) — Final report no later than one month after submission of the incident notification, with detailed description of the incident, threat type, root cause, mitigation measures, and cross-border impact.enforcedaudit_events: kye.signal.incident.closed.v1, kye.evidence.pack.v1, kye.assurance.audit_replay_report.v1, kye.cross_border.transfer.v1
engines: internal, internal
workers: kye-audit-replay-orchestrator
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/21-DELEGATED-AUDITABILITY.md
nis2.A23.2Article 23(2) — Where appropriate, communicate to the recipients of their services that are potentially affected by a significant cyber threat any measures or remedies that those recipients can take in response.enforcedaudit_events: kye.comms.dispatched.v1, kye.transparency.statement.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
workers: kye-comms-engine-worker
nis2.A23.3Article 23(3) — Where appropriate, and in particular where the significant cyber threat is likely to materialise, the entity shall inform the recipients of those services of the threat itself.enforcedaudit_events: kye.comms.dispatched.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md
nis2.A23.5Article 23(5) — Member-state CSIRT shall provide the notifying entity, without undue delay and where possible within 24 hours, a response including initial feedback on the significant incident and, upon request, guidance on possible mitigation measures.advisoryaudit_events: kye.comms.dispatched.v1, kye.signal.incident.opened.v1
constitution_refs: constitution/38-COMMS-RAIL.md
nis2.A23.6Article 23(6) — Where applicable, voluntarily notify significant incidents, significant cyber threats and near-misses to the CSIRT or, where applicable, the competent authority.enforcedaudit_events: kye.signal.incident.opened.v1, kye.comms.dispatched.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
nis2.A23.1Early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident.enforcedaudit_events: kye.signal.incident.opened.v1, kye.comms.dispatched.v1
engines: internal, internal
workers: kye-incident-detector, kye-comms-engine-worker
constitution_refs: constitution/13-RESILIENCE-LOOP.md, constitution/38-COMMS-RAIL.md
nis2.A23.4Notification of recipients of services affected by a significant cybersecurity threat that may impact them.enforcedaudit_events: kye.comms.dispatched.v1, kye.transparency.statement.v1
engines: internal
workers: kye-comms-engine-worker
constitution_refs: constitution/38-COMMS-RAIL.md
nis2.A24.1.approveArticle 20(1) — Management bodies of essential and important entities shall approve the cybersecurity risk-management measures taken by those entities in order to comply with Article 21, oversee its implementation, and can be held liable for infringements by the entities.enforcedaudit_events: kye.governedui.approval.v1, kye.governedui.action_proposal.v1, kye.compliance.attestation.v1
engines: internal, internal
governedui_modules: kye.governedui.module.action_approval.v1, kye.governedui.module.approval_queue.v1
constitution_refs: constitution/36-GOVERNEDUI.md
nis2.A24.1.trainingArticle 20(2) — Member states shall ensure that members of management bodies are required to follow training and shall encourage essential and important entities to offer similar training to their employees on a regular basis.enforcedaudit_events: kye.training.completion.v1, kye.compliance.attestation.v1
engines: internal, internal
constitution_refs: constitution/10-PARTNER.md, constitution/39-LEARN-RAIL.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
nis2.A24.1.liabilityArticle 20(1) — Liability of management bodies for infringements: management bodies can be held liable when they fail to comply with the obligations under this Directive.enforcedaudit_events: kye.governedui.approval.v1, kye.audit.event.v1, kye.compliance.attestation.v1
engines: internal
constitution_refs: constitution/30-AUDIT-WORM-RETENTION.md, constitution/36-GOVERNEDUI.md
nis2.A24.1Management bodies of essential and important entities approve the cybersecurity risk-management measures taken to comply with Article 21, oversee implementation, and can be held liable for infringements; members of management bodies must follow training and offer similar training to staff.enforcedaudit_events: kye.governedui.approval.v1, kye.compliance.attestation.v1, kye.training.completion.v1, kye.authority.grant.v1
engines: internal, internal, internal, internal
governedui_modules: kye.governedui.module.action_approval.v1, kye.governedui.module.approval_queue.v1
constitution_refs: constitution/36-GOVERNEDUI.md, constitution/21-DELEGATED-AUDITABILITY.md
nis2.A32.1Article 32(1) — Member states shall ensure that the supervisory measures imposed on essential entities are effective, proportionate and dissuasive, taking into account the circumstances of each individual case.advisoryaudit_events: kye.compliance.attestation.v1
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nis2.A32.2.aArticle 32(2)(a) — Power to require on-site inspections and off-site supervision, including random checks, conducted by trained professionals.enforcedaudit_events: kye.assurance.audit_pilot.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nis2.A32.2.bArticle 32(2)(b) — Power to require regular and targeted security audits carried out by an independent body or a competent authority.enforcedaudit_events: kye.assurance.audit_pilot.v1, kye.evidence.pack.v1, kye.subprocessor.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md, constitution/49-UNIVERSAL-ENGAGEMENT-RAIL.md
nis2.A32.2.cArticle 32(2)(c) — Power to require ad hoc audits, including where justified by a significant incident or an infringement of the Directive.enforcedaudit_events: kye.signal.incident.opened.v1, kye.assurance.audit_replay_report.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nis2.A32.2.dArticle 32(2)(d) — Power to require security scans based on objective, non-discriminatory, fair and transparent risk-assessment criteria.enforcedaudit_events: kye.risk.score.v1, kye.evidence.decision_map.v1
engines: internal, internal
constitution_refs: constitution/13-RESILIENCE-LOOP.md
nis2.A32.2.eArticle 32(2)(e) — Power to request information necessary to assess the cybersecurity risk-management measures adopted by the entity.enforcedaudit_events: kye.compliance.attestation.v1, kye.evidence.pack.v1
engines: internal, internal
constitution_refs: constitution/21-DELEGATED-AUDITABILITY.md
nis2.A32.4.bindingArticle 32(4)(b)-(c) — Power to issue binding instructions and orders, including ordering implementation of recommendations from a security audit within a reasonable deadline.designedaudit_events: kye.governedui.action_proposal.v1, kye.governedui.approval.v1, kye.compliance.attestation.v1
governedui_modules: kye.governedui.module.action_approval.v1
constitution_refs: constitution/36-GOVERNEDUI.md
nis2.A32.4.disclosureArticle 32(4)(g) — Power to make public, where appropriate, the names of the natural and legal persons responsible for the breach of obligations.advisoryaudit_events: kye.transparency.statement.v1, kye.comms.dispatched.v1
engines: internal
constitution_refs: constitution/38-COMMS-RAIL.md

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.