EntexiaIntelligent ecosystem
Modules/NIS2 / Cybersecurity
NIS2 / Cybersecurity

NIS2 compliance
not guessing.

10-point self-assessment, policies from templates, incident and training records — everything NIS2 requires, without guessing.

10
NIS2 areas in self-assessment
24h
incident report deadline
ISO 27001
aligned
NIS2 Self-Assessment — Example
Do you have a written security policy?
Do you use MFA for all privileged access?
Do you have an inventory of all IT assets?
Do you have a security incident reporting procedure?
Are employees trained to recognize phishing attacks?
Do you have a documented backup and DR plan?
Score4 / 10 — Medium risk
6 areas require immediate action

10 NIS2 self-assessment questions

How many Yes answers do you have? In Entexia you get guidance for every No.

1Do you have a written security policy?
2Do you use MFA for all privileged access?
3Do you have an inventory of all IT assets?
4Do you have a security incident reporting procedure?
5Are employees trained to recognize phishing attacks?
6Do you have a documented backup and DR plan?
7Do you assess vendor risks (VRM)?
8Do you conduct regular penetration tests?
9Do you have SIEM or security monitoring configured?
10Do you have a BCP (business continuity plan)?

Why cybersecurity is not optional

up to €10M
NIS2 non-compliance fine for essential entities (NIS2 Art. 34) — for important entities up to €7M
$4.88M
average cost of a cyber incident for EU organizations (IBM Cost of a Data Breach 2024)
82%
of cyber attacks target employees (phishing, social engineering) — training is proven defense (Verizon DBIR 2024)

All NIS2 requirements in one place

NIS2 compliance checklist

Interactive Yes/No questionnaire across 10 key NIS2 areas. Red/green visualization. Risk score automatic.

Policies and procedures

Library of NIS2 policy templates: ISMS, security policy, password policy, BCP/DR plan. Customize in minutes.

Asset inventory (CMDB)

What software and hardware do you manage? Entexia keeps records with owners, versions, and risks.

Incident reporting (ENISA)

Security incident report within 24h to ENISA? Entexia tracks the timeline, classification, and regulatory report.

Security training

Phishing simulations, GDPR basics, password policies — for all employees. Training completion records per NIS2.

Backup and DR plan

Document RTO/RPO, test restore procedures, and responsibilities. NIS2 requires a proven DR plan, not just a strategy.

Frequently asked questions

Does NIS2 apply to me as an SME?
NIS2 (EU 2022/2555) directly binds 'medium' and 'large' entities in 18 sectors. SMEs are indirectly affected as suppliers to larger entities. We recommend an assessment by 2025.
When must I report a security incident?
NIS2 requires: early warning within 24h, initial report within 72h, and final report within 30 days. Entexia tracks the timeline and reminds you of deadlines.
What is the minimum set of controls for NIS2 compliance?
Minimum: risk management, security policy, MFA, backup+DR, employee training, incident procedure, asset inventory. Entexia covers all with templates.
Does Entexia replace an ISMS/ISO 27001 auditor?
No. Entexia is a tool for managing evidence and self-assessment. For formal ISO 27001 certification or NIS2 audit, you need an accredited auditor.
How long must I retain NIS2 documentation?
NIS2 doesn't specify a minimum retention period, but for most EU regulations 5 years applies. Entexia stores all evidence in DMS with an audit trail.
Does the module support ISO 27001 in addition to NIS2?
Yes. Controls and policies in Entexia are aligned with ISO 27001 Annex A, NIST CSF, and NIS2. The same evidence often covers multiple frameworks simultaneously.

Interactive element

NIS2 self-check — where do you stand?

Self-check

NIS2 self-check — where do you stand?

Answered: 0/10
1.
Do you have a cybersecurity risk management policy?
2.
Do you have an incident reporting procedure (24h/72h)?
3.
Do you maintain a critical asset inventory?
4.
Do you regularly test your backups?
5.
Do you have an access control policy (MFA, privileged access)?
6.
Do you have a supplier risk management procedure?
7.
Do you regularly conduct security training for employees?
8.
Do you have a disaster recovery plan (DRP)?
9.
Do you have a vulnerability and patch management procedure?
10.
Do you maintain a security audit log?

Self-check based on publicly available requirements of NIS2 Directive (EU 2022/2555), Art. 21. Not legal advice.

Explore NIS2 module in Entexia

NIS2 compliance. Not guessing.

7-day free trial. No credit card.