Skip to content
Menu ▾
Patent pending

Regulayer  /  The 146 laws  /  Security standards

EU · NIS2 (Dir 2022/2555)

Cybersecurity risk mgmt & incident reporting.

Applies to: EU essential & important entities.

What the signed record shows

Incident handling/logging and records supporting 24h/72h/1-month reporting.

The proof is a signed, tamper-evident record. Anyone can check it, free, without an account, and nothing has to leave the building to make it. Evidence, not a promise.

Citation: Arts 21/23 (transposition 17 Oct 2024)

In the same family

What to do about it

Seven days free, then $349 a month.

A signed record of which AI you used and what you checked, sealed to the exact file you deliver, made on your own machine and checkable free by anyone you send it to.

Start the free weekOr verify a real record, free →

Part of the Regulayer proof catalogue: 146 laws and standards, one sealed engine. This page is a product description, not legal advice.

What the statute requires, section by section

Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union ("NIS2"). Member-State transposition deadline: 17 October 2024. Provisions this mapper evidences from the per-event signed record:

Art. 21
Cybersecurity risk-management measures (incl. incident handling, logging, and the security of network and information systems).
Art. 23
Reporting obligations for significant incidents: early warning (within 24 hours), incident notification (within 72 hours) and a final report (within one month). NIS2 is a Directive implemented through national law; obligations bind essential and important entities as designated by each Member State.

Taken from the Regulayer entry for this instrument, which is built against the primary text.

This is the duty on the business. For what a lawyer in Europe must disclose about using AI in a filing, see Europe: the EU AI Act, the CCBE guides, and what Germany tells its lawyers.