Skip to content
Cybsis

Standard

NIS2 Directive (EU) 2022/2555

Mapped throughout Cybsis, never sold as a framework of its own — you demonstrate NIS2 conformity through the standard your national law actually obliges.

EUReference framework — not sold separately

Nobody implements a directive. NIS2 binds Member States, not entities; what binds you is the transposing national law — in Estonia that is KüTS, and the audit obligation it carries keys on E-ITS. So Cybsis treats NIS2 as a mapping target rather than an implementation surface: you run E-ITS or ISO 27001, and NIS2 conformity falls out of controls you are already evidencing.

The mapping is shipped, not promised: 101 control mappings — 54 to ISO 27001, 39 to E-ITS, 8 to the AI Act — alongside the incident-reporting profile and the KüTS legal chain. Continuous monitoring inherits along the NIS2 → ISO 27001 path, so a control you evidence once answers in both directions.

For financial entities the question does not arise. DORA is lex specialis and displaces NIS2 outright — you are not running both. See DORA.