NIS2 Readiness Guide

Last updated: 21 May 2026

This guide helps NetSenX customers understand their obligations under the NIS2 Directive (Directive (EU) 2022/2555) and how NetSenX supports compliance.

Important: This guide is for informational purposes only and does not constitute legal advice. Customers are responsible for determining their own NIS2 obligations with qualified legal counsel.

1. Entity Classification Helper

NIS2 categorizes entities into Essential and Important based on sector and size.

Essential Entities (Annex I)

SectorExamplesSize Threshold
EnergyElectricity, oil, gas, hydrogen, district heatingLarge (250+ employees or EUR 50M+ turnover)
TransportAir, rail, water, roadLarge
BankingCredit institutionsLarge
Financial Market InfrastructureTrading venues, CCPsLarge
HealthHospitals, laboratories, pharma, medical devicesLarge
Drinking WaterWater supply and distributionLarge
WastewaterWastewater treatmentLarge
Digital InfrastructureDNS, TLDs, cloud, data centers, CDNs, trust servicesLarge
ICT Service Management (B2B)MSPs, MSSPsLarge
Public AdministrationCentral government entitiesN/A
SpaceSpace operationsLarge

Important Entities (Annex II)

SectorExamplesSize Threshold
Postal and CourierPostal service providersMedium (50+ employees or EUR 10M+ turnover)
Waste ManagementWaste collection and treatmentMedium
ChemicalManufacturing and distributionMedium
FoodProduction, processing, distributionMedium
ManufacturingMedical devices, electronics, machinery, vehiclesMedium
Digital ProvidersOnline marketplaces, search engines, social platformsMedium
ResearchResearch organizationsMedium

How NetSenX Helps

NetSenX provides automated entity classification tools within the compliance dashboard, helping you determine whether your organization falls under Essential or Important entity categories based on your sector, size, and operations.

2. Art. 21 Cybersecurity Measures Mapping

NIS2 Art. 21 requires entities to implement appropriate and proportionate technical, operational, and organizational measures. Here is how NetSenX maps to each requirement:

Art. 21 MeasureNIS2 RequirementNetSenX Capability
(a) Risk analysis and IS policiesPolicies on risk analysis and information system securityRisk scoring dashboard, policy templates, asset inventory
(b) Incident handlingIncident handling proceduresAutomated incident detection, classification, and response workflows
(c) Business continuityBusiness continuity, backup management, disaster recovery, crisis managementHigh-availability architecture, automated backup monitoring
(d) Supply chain securitySupply chain security including supplier assessmentsThird-party risk monitoring, vendor traffic analysis
(e) Network securitySecurity in network and information system acquisition, development, maintenance, including vulnerability handling and disclosureContinuous network monitoring, vulnerability correlation, CVD policy
(f) Effectiveness assessmentPolicies and procedures to assess the effectiveness of cybersecurity risk management measuresCompliance scoring, automated control testing, audit reports
(g) Cyber hygiene and trainingBasic cyber hygiene practices and cybersecurity trainingSecurity posture dashboard, user behavior analytics
(h) CryptographyPolicies and procedures regarding the use of cryptography and encryptionEncrypted traffic analysis (without decryption), TLS compliance monitoring
(i) HR and access controlHuman resources security, access control policies, asset managementNetwork access monitoring, identity-aware traffic analysis
(j) MFA and secure commsUse of multi-factor authentication, secured voice/video/text, secured emergency communicationAuthentication monitoring, anomaly detection on comms channels

3. Incident Reporting Workflow (Art. 23)

NIS2 Art. 23 establishes strict incident reporting timelines. NetSenX automates and supports each phase:

Reporting Timeline

Incident Detection
       |
       v
  [0-24 hours] ──── Early Warning to CSIRT/Competent Authority
       |              - Is the incident likely caused by unlawful/malicious acts?
       |              - Could it have cross-border impact?
       |
       v
  [0-72 hours] ──── Incident Notification to CSIRT/Competent Authority
       |              - Initial assessment of severity and impact
       |              - Number of affected users/services
       |              - Indicators of compromise (IoCs)
       |
       v
  [Upon request] ── Intermediate Report
       |              - Updated status and handling measures
       |
       v
  [1 month max] ─── Final Report to CSIRT/Competent Authority
                      - Detailed description of the incident
                      - Root cause analysis
                      - Mitigation measures applied
                      - Cross-border impact assessment

NetSenX Breach SLA

As your NDR provider, we commit to the following SLAs for incidents detected by the NetSenX platform:

PhaseSLANIS2 Requirement
Early WarningWithin 24 hours of detectionArt. 23(4)(a) — 24 hours
Incident NotificationWithin 72 hours of detectionArt. 23(4)(b) — 72 hours
Intermediate ReportUpon request from authorityArt. 23(4)(c)
Final ReportWithin 1 month of notificationArt. 23(4)(d) — 1 month

How NetSenX Automates Reporting

  1. Detection: AI-driven anomaly detection identifies significant incidents in real-time
  2. Classification: Automated severity scoring against NIS2 thresholds
  3. Early Warning Generation: Pre-filled early warning template with IoCs, within 24 hours
  4. Notification Preparation: Structured incident notification with impact assessment
  5. Evidence Collection: Automated PCAP, flow data, and timeline evidence gathering
  6. Final Report Assembly: Comprehensive report template with root cause analysis

4. Customer Obligations

Important: While NetSenX provides tools and automation to support NIS2 compliance, customers bear the ultimate responsibility for:

  • Determining their entity classification (Essential or Important)
  • Registering with the relevant national authority in their Member State
  • Submitting incident reports to their national CSIRT or competent authority
  • Implementing all Art. 21 measures appropriate to their risk profile
  • Conducting regular risk assessments and updating security measures
  • Ensuring supply chain security across all vendors, not only NetSenX
  • Board-level oversight — NIS2 Art. 20 requires management bodies to approve and oversee cybersecurity measures

NetSenX does not submit incident reports on behalf of customers. We provide the data, automation, and templates to make compliance efficient, but the legal obligation rests with the entity.

5. Resources


TriStiX S.L. — NIF B-26925016 Registered in the Registro Mercantil de Alicante, Spain

This document does not constitute legal advice. Consult qualified legal counsel for NIS2 compliance guidance specific to your organization.