Back to engagement patterns
    Engagement pattern

    NIS2 readiness for an important entity

    How readiness is shaped for an entity in the important tier: the scope test, the Article 21 measures, the reporting chain and the evidence behind them.

    Compliance3 Sept 20265 min read

    Directive (EU) 2022/2555ISO/IEC 27001:2022
    On this page

    Scope

    An important entity carries the same substantive duties as an essential entity. The risk-management measures in Article 21 and the reporting obligations in Article 23 apply to both tiers 1. Supervision is what differs. Article 33 supervises important entities ex post, on evidence, indication or information of non-compliance 2. Readiness for this tier is therefore not a reduced programme. It is the same programme, held so the case can be made from records that already exist.

    In scope: the tier determination, the entity data owed to the competent authority, the ten measure families in Article 21(2), the notification chain, and management-body approval and training.

    Out of scope: sector-specific Union acts that displace the directive under Article 4, national transposition detail, and day-to-day security operations, which are a capability rather than a governance artefact.

    Phases

    PhasePurposePlanning horizonCloses when
    1. Tier determinationPlace the entity against the sector annexes and the size ceilings referred to in Article 3usually planned over 2–4 weeksA written determination names sector, subsector, entity type and tier
    2. Measure gap assessmentTest each of the ten families in Article 21(2) against what actually operatesusually planned over 6–10 weeksEvery family has a status, an owner and a treatment decision
    3. Evidence and reporting buildProduce the registers, the policies and the notification chain, then rehearse itusually planned over 3–5 monthsA rehearsal yields an early warning, a notification and a final report
    4. Governance handoverMove approval, review and training into the management body's own cycleusually planned over 4–6 weeksThe management body has approved the measures on its own record
    Horizons are planning input. They describe how this shape of work is usually scheduled, never how long anything took.

    Deliverables

    DeliverableRequired byWho maintains it afterwards
    Scope and tier determinationArticle 3(1) and (2)Compliance owner
    Entity registration recordArticle 3(4), including a two-week change duty 3Compliance owner
    Policies on risk analysis and information system securityArticle 21(2), point (a)Security function
    Incident-handling procedure and notification runbookArticle 21(2), point (b), and Article 23(4)Security function
    Continuity, backup and crisis-management planArticle 21(2), point (c)Continuity owner
    Supplier requirements and supplier assessment recordArticle 21(2), point (d), and Article 21(3)Procurement and security
    Effectiveness-assessment procedureArticle 21(2), point (f)Internal audit
    Management-body approval record and training logArticle 20(1) and (2) 4The management body

    Roles

    RoleSideAccountable for
    Management bodyOrganisationApproving the measures, overseeing implementation, following training
    Compliance ownerOrganisationTier determination, registration data, evidence set
    Security functionOrganisationThe measures themselves and the notification chain
    ProcurementOrganisationSupplier requirements and the assessment record
    AdviserExternalMethod, gap assessment, rehearsal design, handover

    What the authority asks

    Failure modes

    Mapping

    ObligationArticleEvidence that answers it
    Be placed in the correct tierArt. 3(1), 3(2)Tier determination, annex extract
    Give the authority current entity dataArt. 3(4)Registration record, change log
    Have the management body approve and overseeArt. 20(1)Signed approval, oversight minutes
    Train the management bodyArt. 20(2)Training log, curriculum
    Operate all-hazards risk-management measuresArt. 21(2), points (a)–(j)Policy set plus operating records
    Take supplier-specific factors into accountArt. 21(3)Supplier assessment record
    Correct known non-compliance without undue delayArt. 21(4)Corrective action register
    Notify a significant incident on the statutory clockArt. 23(4)(a)–(d)Early warning, notification, final report
    Obligation to article to evidence. Article numbers are those of Directive (EU) 2022/2555.

    References

    1. European Parliament and Council. Directive (EU) 2022/2555 (NIS 2 Directive). OJ L 333, 27.12.2022, p. 80. https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng 5
    2. The sector annexes are titled Sectors of high criticality and Other critical sectors 6.
    3. Administrative fines for infringement of Article 21 or 23 are set per tier in Article 34(4) and 34(5) 7.

    Sources

    1. 1Directive (EU) 2022/2555, Arts 21 and 23, CELEX 32022L2555 · verified 2026-09-03
    2. 2Directive (EU) 2022/2555, Art. 33(1), CELEX 32022L2555 · verified 2026-09-03
    3. 3Directive (EU) 2022/2555, Art. 3(4), CELEX 32022L2555 · verified 2026-09-03
    4. 4Directive (EU) 2022/2555, Art. 20, CELEX 32022L2555 · verified 2026-09-03
    5. 5Directive (EU) 2022/2555, full text, CELEX 32022L2555 · verified 2026-09-03
    6. 6Directive (EU) 2022/2555, sector annexes, CELEX 32022L2555 · verified 2026-09-03
    7. 7Directive (EU) 2022/2555, Art. 34(4)–(5), CELEX 32022L2555 · verified 2026-09-03