Entexia | Intelligent ecosystem
Security & compliance · EU 2022/2555

NIS2 security module

Entexia includes a NIS2 security module with risk management, security policies, access control and audit trail for compliance with EU Directive 2022/2555.

Built into every Entexia subscription at no extra charge. Together with the GDPR module for comprehensive legal compliance.

NIS2 applies from October 2024 - fines up to €10m

Directive 2022/2555 (NIS2) was transposed into Slovenian law through ZVKSES. Violations: up to €10 million or 2% of annual turnover for essential entities, up to €7 million or 1.4% for important entities.

Covered sectors (selection)

Energy (electricity, gas, oil, district heating)
Transport (air, rail, road, waterborne)
Banking and financial market infrastructure
Healthcare and pharmaceuticals
Digital infrastructure and ICT services
Public administration
Food industry (medium/large companies)
Manufacturing (medical devices, chemicals, vehicles)
Waste management

What the NIS2 module in Entexia includes

We cover Article 21 of the NIS2 Directive - cybersecurity risk management measures.

Risk register

Record all risks with likelihood, impact and owner assessment. Periodic review with reminders.

Security policies with signatures

Policy library with version management. Employees confirm policies digitally - evidence for audit.

Incident register

Record cybersecurity incidents with ENISA classification. Built-in timeline for NIS2 reports (24h/72h/1M).

Vendor risk (supply chain)

Record suppliers with access to your systems. A/B/C risk assessment and deadline for re-evaluation.

Access management and MFA

Overview of active accesses, roles and permissions. MFA supported for all administrative accesses.

Audit trail of critical actions

Every data change, access and export is recorded with a timestamp and user identity.

Article 21 NIS2 coverage

Article 21(2) NIS2 mandates 10 groups of measures. Entexia directly supports 7 of 10.

21(2)(a): Risk analysis and IT security policies
21(2)(b): Incident handling - records and reporting
21(2)(c): Business continuity and backups
21(2)(d): Supply chain security (vendor risk)
21(2)(e): Network and system security (access, MFA)
21(2)(i): Cryptography - encrypted data at rest
21(2)(j): Human resources security - policies and signatures
21(2)(f): Effectiveness assessment (penetration testing)(external provider)
21(2)(g): Cyber hygiene and training(external provider)
21(2)(h): Company-wide MFA policies(external provider)

Frequently asked questions about NIS2

Which ERP has a NIS2 security module?

Entexia includes a NIS2 security module with risk management, security policies, access control and audit trail built into the platform at no extra charge. The module covers the key requirements of Directive (EU) 2022/2555 - risk management, security incidents, supply chain security, business continuity and audit trail.

What is the NIS2 directive and who does it apply to?

NIS2 (EU Directive 2022/2555 on measures for a high common level of cybersecurity) replaced NIS1 and applies from October 2024. It covers essential and important entities in 18 sectors: energy, transport, health, public administration, digital infrastructure, food, chemicals, manufacturing and services. Violations carry fines of up to €10 million or 2% of annual turnover.

What exactly does the NIS2 security module in Entexia include?

The NIS2 module in Entexia includes: (1) risk register with likelihood and impact assessment; (2) security policy library with version management and employee signatures; (3) cybersecurity incident register with ENISA classification; (4) supplier register with security assessment (vendor risk); (5) MFA access management; (6) audit trail of all critical actions; (7) backup policy settings in line with NIS2 requirements.

How does Entexia help with NIS2 incident reporting?

NIS2 requires reporting of serious incidents to the competent authority within 24 hours (early warning) and 72 hours (interim report), and a month after the incident (final report). The Entexia NIS2 module contains an incident register with built-in timelines and reminders for each deadline. Reports are generated from the register in standardised format.

Does the NIS2 module cover supply chain security?

Yes. NIS2 Article 21(2)(d) requires supply chain security management. The Entexia NIS2 module includes a supplier register with security assessment, risk classification (A/B/C) and deadlines for regular assessments. Every supplier with access to your systems or data is recorded with a risk level and last assessment date.

Is the NIS2 module included in the basic Entexia subscription?

Yes. The NIS2 security module is part of the Entexia platform at no extra charge or separate licence. A GDPR module with processing records and subject access requests (SAR) is also built in. For businesses that need to demonstrate compliance with both directives, everything is in one system.

NIS2 compliance with Entexia - at no extra charge

The free demo includes a demonstration of the NIS2 module and GDPR register.

Request a demo