Entexia | Intelligent ecosystemThe heartbeat of your enterprise
Modules/Cybersecurity
NIS2 / Cybersecurity

NIS2 compliance
not guessing.

10-point self-assessment, policies from templates, incident and training records — everything NIS2 requires, without guessing.

10
NIS2 areas in self-assessment
24h
incident report deadline
ISO 27001
aligned
NIS2 Self-Assessment — Example
Ali imate pisno varnostno politiko?
Ali uporabljate MFA za vse privilegirane dostope?
Ali imate inventar vseh IT sredstev?
Ali imate postopek prijave varnostnih incidentov?
Ali so zaposleni usposobljeni za prepoznavanje phishing napadov?
Ali imate dokumentiran backup in DR plan?
Score4 / 10 — Medium risk
6 areas require immediate action

10 NIS2 self-assessment questions

How many Yes answers do you have? In Entexia you get guidance for every No.

1Ali imate pisno varnostno politiko?
2Ali uporabljate MFA za vse privilegirane dostope?
3Ali imate inventar vseh IT sredstev?
4Ali imate postopek prijave varnostnih incidentov?
5Ali so zaposleni usposobljeni za prepoznavanje phishing napadov?
6Ali imate dokumentiran backup in DR plan?
7Ali vrednotite tveganja dobaviteljev (VRM)?
8Ali izvajate redne penetracijske teste?
9Ali imate konfiguriran SIEM ali varnostni monitoring?
10Ali imate BCP (plan neprekinjenega poslovanja)?

Why cybersecurity is not optional

up to €10M
NIS2 non-compliance fine for essential entities (NIS2 Art. 34) — for important entities up to €7M
4,88 $M
average cost of a cyber incident for EU organizations (IBM Cost of a Data Breach 2024)
82%
of cyber attacks target employees (phishing, social engineering) — training is proven defense (Verizon DBIR 2024)

All NIS2 requirements in one place

NIS2 compliance checklist

Interactive Yes/No questionnaire across 10 key NIS2 areas. Red/green visualization. Risk score automatic.

Policies and procedures

Library of NIS2 policy templates: ISMS, security policy, password policy, BCP/DR plan. Customize in minutes.

Asset inventory (CMDB)

What software and hardware do you manage? Entexia keeps records with owners, versions, and risks.

Incident reporting (ENISA)

Security incident report within 24h to ENISA? Entexia tracks the timeline, classification, and regulatory report.

Security training

Phishing simulations, GDPR basics, password policies — for all employees. Training completion records per NIS2.

Backup and DR plan

Document RTO/RPO, test restore procedures, and responsibilities. NIS2 requires a proven DR plan, not just a strategy.

Frequently asked questions

Does NIS2 apply to me as an SME?
NIS2 (EU 2022/2555) directly binds 'medium' and 'large' entities in 18 sectors. SMEs are indirectly affected as suppliers to larger entities. We recommend an assessment by 2025.
When must I report a security incident?
NIS2 requires: early warning within 24h, initial report within 72h, and final report within 30 days. Entexia tracks the timeline and reminds you of deadlines.
What is the minimum set of controls for NIS2 compliance?
Minimum: risk management, security policy, MFA, backup+DR, employee training, incident procedure, asset inventory. Entexia covers all with templates.
Does Entexia replace an ISMS/ISO 27001 auditor?
No. Entexia is a tool for managing evidence and self-assessment. For formal ISO 27001 certification or NIS2 audit, you need an accredited auditor.
How long must I retain NIS2 documentation?
NIS2 doesn't specify a minimum retention period, but for most EU regulations 5 years applies. Entexia stores all evidence in DMS with an audit trail.
Does the module support ISO 27001 in addition to NIS2?
Yes. Controls and policies in Entexia are aligned with ISO 27001 Annex A, NIST CSF, and NIS2. The same evidence often covers multiple frameworks simultaneously.

Interactive element

NIS2 self-check — where do you stand?

Self-check

NIS2 self-check — where do you stand?

Answered: 0/10
1.
Do you have a cybersecurity risk management policy?
2.
Do you have an incident reporting procedure (24h/72h)?
3.
Do you maintain a critical asset inventory?
4.
Do you regularly test your backups?
5.
Do you have an access control policy (MFA, privileged access)?
6.
Do you have a supplier risk management procedure?
7.
Do you regularly conduct security training for employees?
8.
Do you have a disaster recovery plan (DRP)?
9.
Do you have a vulnerability and patch management procedure?
10.
Do you maintain a security audit log?

Self-check based on publicly available requirements of NIS2 Directive (EU 2022/2555), Art. 21. Not legal advice.

Explore NIS2 module in Entexia

NIS2 compliance. Not guessing.

7-day free trial. No credit card.