Frameworks

NIS2, with management accountability built in.

NIS2 widened who is covered and made leadership personally accountable. TruOps gives leadership the evidence to stand behind.

NIS2 · readinessevidence current
NIS2 · coverage by Article 21 measure
Risk analysis & policiessatisfied · 99%
Incident handlingsatisfied · 96%
Business continuitypartial · 53%
Supply chain securitypartial · 59%
Secure developmentsatisfied · 95%
Effectiveness assessmentpartial · 75%
Cyber hygiene & trainingsatisfied · 96%
Cryptographysatisfied · 87%
Access control & MFAsatisfied · 96%
The same work also counts toward
ISO 2700140% · partials shown
DORA78% · partials shown
NIST CSF78% · partials shown

Mappings are typed exact, partial, or inferred, each with a citation.

Illustrative example
In short

The NIS2 Directive, Directive (EU) 2022/2555, expands EU cybersecurity requirements to essential and important entities across many sectors. Member states had to transpose it by 17 October 2024. It requires cybersecurity risk-management measures (Article 21), staged incident reporting (an early warning within 24 hours, a notification within 72 hours, and a final report within one month), and accountability for management bodies.

This page is for you if
  • Management is personally accountable and wants evidence, not a slide
  • You are essential or important and supply-chain security is still email
  • Incident reporting clocks (24h / 72h / 1 month) have no program behind them
Instrument
Directive (EU) 2022/2555
Transposition deadline
17 October 2024
Covers
Essential and important entities across many sectors
Incident reporting
24 hours · 72 hours · 1 month

Risk-management measures

Article 21 sets minimum measures, including:

  • Risk analysis and information system security policies
  • Incident handling, business continuity, and crisis management
  • Supply chain security, including relationships with suppliers
  • Security in acquisition, development, and maintenance, including vulnerability handling
  • Assessing the effectiveness of measures; cyber hygiene and training
  • Cryptography, human resources security, access control, asset management, and multi-factor authentication

The actual challenge

NIS2 made leadership liable for measures they cannot currently see. The gap is not a missing policy; it is missing proof that Article 21 is operating.

  • National transposition differs; the control set is still a consultant matrix.
  • Suppliers are in-scope and unassessed.
  • Effectiveness of measures is supposed to be tested; it is attested.

Bring one real document. Watch the program get set up from it.

What you are probably using today

Almost nobody starts NIS2 from zero. You already have a program somewhere. TruOps is built to take that over, not make you start again.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
SOC 2 automation toolsThey are strong at certification: automated tests, a broad framework library, and often a trust center. Maturity scoring, custom frameworks, and deep risk or vendor work can sit outside that model.Keep the automation. Run any framework as the anchor, map the rest with partials shown as partial, and run vendor and risk on the same engine. Upload the policies and reports you already have.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

Penalties and accountability

Management bodies must approve and oversee measures and can be held liable. Maximum fines reach at least €10 million or 2% of worldwide turnover for essential entities, and €7 million or 1.4% for important entities, depending on national law.

How TruOps helps with NIS2

Pick NIS2 as your anchor, or map it to the framework you already run. TruOps keeps NIS2's own structure, down to the individual requirement, and shows coverage per requirement as satisfied, partial, or open, with the evidence behind each.

Upload what you have (prior reports, policies, spreadsheets) and TruOps pre-fills your NIS2 assessment with cited answers. Connected tools keep technical controls current on the schedule you set, and failed checks become findings with a recommended fix.

If this is your situation

Bring the Article 21 mapping you have. TruOps turns it into an assessed, evidenced program, with suppliers on the vendor portal and status leadership can stand behind.

How TruOps helps

Anchor or map
Run NIS2 as your spine or map it to another framework; work counts once.
Pre-filled assessment
Your NIS2 assessment opens with the answers your evidence supports already filled, each cited.
Honest coverage
Partial coverage is reported as partial, with the remaining requirements listed.
Continuous monitoring
Technical controls checked against your tools hourly to quarterly.
Findings with fixes
Failed checks become grouped findings with a recommended action.
Audit-ready snapshots
Results saved as of their date, with the evidence trail attached.

Questions

Who does NIS2 apply to?

Medium and large entities in sectors listed in the directive, classified as essential or important, plus some smaller entities designated by member states. Exact scope depends on national transposition.

What are the NIS2 incident reporting deadlines?

An early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.

Does NIS2 cover suppliers?

Yes. Supply chain security is one of the required measures, which makes vendor risk management part of NIS2 compliance.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

Does TruOps replace our auditor, QSA, or certification body?

No. Only a licensed auditor, QSA, C3PAO, or accredited certification body can issue the opinion. TruOps gets the evidence current, cited, and dated so fieldwork is a review, not an archaeology project.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.