EU NIS2 Implementing Regulation
Commission Implementing Regulation (EU) 2024/2690 with ENISA Technical Implementation Guidance — the detailed technical and methodological requirements behind NIS2 Article 21 for digital infrastructure and ICT service providers. Available on the Premium plan.
From NIS2 Article 21
to concrete technical requirements
The Implementing Regulation (EU) 2024/2690 turns the high-level cybersecurity risk-management measures of the NIS2 Directive into detailed, auditable requirements for DNS service providers, TLD name registries, cloud computing and data centre providers, content delivery networks, managed service and managed security service providers, online marketplaces, search engines, social networking platforms, and trust service providers.
ENISA's Technical Implementation Guidance explains how to meet each requirement in practice and which evidence to keep. In Unicis, the regulation is a separate framework next to the EU NIS2 Directive, so you can track Article 21 measures and the detailed technical requirements independently and map between them.
Every control includes Implementation Guidance and Examples of Evidence, available in English, German, Spanish, French, and Italian.
Implement NIS2 technical requirements with ENISA guidance
Track every requirement with guidance and evidence examples, alongside the NIS2 Directive and your other frameworks.
What the regulation requires
The regulation details the technical and methodological requirements for the cybersecurity risk-management measures of Article 21(2).
Policy on the security of network and information systems
Documented security policy approved by management, with defined roles, responsibilities, and regular review.
Risk management policy
Risk management framework, risk assessment, treatment plans, and acceptance of residual risk.
Incident handling
Monitoring and logging, incident detection, classification, response, and reporting, including significant-incident criteria.
Business continuity and crisis management
Backup management, disaster recovery, business continuity plans, and crisis management.
Supply chain security
Supplier policy, supplier risk assessment, contractual security requirements, and supplier monitoring.
Security in acquisition, development, and maintenance
Secure development lifecycle, configuration and change management, security testing, and vulnerability handling.
Assessing effectiveness of measures
Monitoring, measurement, independent reviews, and testing of risk-management measures.
Cyber hygiene and training
Basic cyber hygiene practices and security awareness training for staff and management.
Cryptography
Cryptography policy, key management, and protection of data in transit and at rest.
HR security, access control, and asset management
Joiners-movers-leavers, identity and access management, privileged access, and asset inventory.
Multi-factor authentication and secured communications
MFA or continuous authentication and secured voice, video, text, and emergency communications.
Environmental and physical security
Protection of facilities and infrastructure against physical and environmental threats.
Built for implementation, not just reference
ENISA implementation guidance
Practical guidance on every control, shown directly in the control view.
Examples of evidence
See what auditors and supervisory authorities expect and link it to tasks as evidence.
Mapped to other frameworks
Control mappings to the NIS2 Directive, ISO 27001, CyFun, and more, so evidence is reused across frameworks.
How Unicis covers NIS2 Implementing Regulation
Unicis Platform Modules
Who does the regulation apply to?
Providers in the digital infrastructure and ICT service management sectors, and certain digital providers, that fall under NIS2. Other NIS2 entities can use it as a detailed reference for the technical measures expected of them.
Multi-Framework Support
13 Compliance Frameworks Supported
From the minimum viable security baseline to enterprise-grade standards — coverage for every compliance requirement.
Meet the NIS2 technical requirements with Unicis
Track the Implementing Regulation with ENISA guidance, evidence examples, and cross-framework mapping. Available on the Premium plan.
Record of Processing Activities
Transfer Impact Assessment
Privacy Impact Assessment
Cybersecurity Controls
Cybersecurity Risk Management
Asset Inventory Management
Interactive Awareness Program