Skip to main content
EU NIS2 Implementing Regulation 2024/2690

EU NIS2 Implementing Regulation

Commission Implementing Regulation (EU) 2024/2690 with ENISA Technical Implementation Guidance — the detailed technical and methodological requirements behind NIS2 Article 21 for digital infrastructure and ICT service providers. Available on the Premium plan.

From NIS2 Article 21
to concrete technical requirements

The Implementing Regulation (EU) 2024/2690 turns the high-level cybersecurity risk-management measures of the NIS2 Directive into detailed, auditable requirements for DNS service providers, TLD name registries, cloud computing and data centre providers, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers.

ENISA's Technical Implementation Guidance explains how to meet each requirement in practice and which evidence to keep. In Unicis, the regulation is a separate framework next to the EU NIS2 Directive, so you can track Article 21 measures and the detailed technical requirements independently and map between them.

Every control includes Implementation Guidance and Examples of Evidence, available in English, German, Spanish, French, and Italian.

2024
Adopted 17 October
10
Article 21 areas detailed
5
Languages
ENISA
Implementation guidance

Implement NIS2 technical requirements with ENISA guidance

Track every requirement with guidance and evidence examples, alongside the NIS2 Directive and your other frameworks.

What the regulation requires

The regulation details the technical and methodological requirements for the cybersecurity risk-management measures of Article 21(2).

1

Policy on the security of network and information systems

Documented security policy approved by management, with defined roles, responsibilities, and regular review.

2

Risk management policy

Risk management framework, risk assessment, treatment plans, and acceptance of residual risk.

3

Incident handling

Monitoring and logging, incident detection, classification, response, and reporting, including significant-incident criteria.

4

Business continuity and crisis management

Backup management, disaster recovery, business continuity plans, and crisis management.

5

Supply chain security

Supplier policy, supplier risk assessment, contractual security requirements, and supplier monitoring.

6

Security in acquisition, development, and maintenance

Secure development lifecycle, configuration and change management, security testing, and vulnerability handling.

7

Assessing effectiveness of measures

Monitoring, measurement, independent reviews, and testing of risk-management measures.

8

Cyber hygiene and training

Basic cyber hygiene practices and security awareness training for staff and management.

9

Cryptography

Cryptography policy, key management, and protection of data in transit and at rest.

10

HR security, access control, and asset management

Joiners-movers-leavers, identity and access management, privileged access, and asset inventory.

11

Multi-factor authentication and secured communications

MFA or continuous authentication and secured voice, video, text, and emergency communications.

12

Environmental and physical security

Protection of facilities and infrastructure against physical and environmental threats.

Built for implementation, not just reference

ENISA implementation guidance

Practical guidance on every control, shown directly in the control view.

Examples of evidence

See what auditors and supervisory authorities expect and link it to tasks as evidence.

Mapped to other frameworks

Control mappings to the NIS2 Directive, ISO 27001, CyFun, and more, so evidence is reused across frameworks.

How Unicis covers NIS2 Implementing Regulation

Unicis Platform Modules

Who does the regulation apply to?

Providers in the digital infrastructure and ICT service management sectors, and certain digital providers, that fall under NIS2. Other NIS2 entities can use it as a detailed reference for the technical measures expected of them.

DNS & TLD providersCloud ProvidersData CentresCDN ProvidersManaged Service ProvidersManaged Security ServicesOnline MarketplacesSearch EnginesSocial NetworksTrust Service Providers

Multi-Framework Support

13 Compliance Frameworks Supported

From the minimum viable security baseline to enterprise-grade standards — coverage for every compliance requirement.

Community (Free) Premium Ultimate

Meet the NIS2 technical requirements with Unicis

Track the Implementing Regulation with ENISA guidance, evidence examples, and cross-framework mapping. Available on the Premium plan.