[{"data":1,"prerenderedAt":167},["ShallowReactive",2],{"wissen-en-nis2":3,"wissen-related-en-nis2":157},{"id":4,"title":5,"body":6,"description":136,"extension":137,"lang":138,"meta":139,"navigation":140,"path":141,"related":142,"seo":147,"short":148,"sitemap":149,"stem":150,"synonyms":151,"updated":155,"__hash__":156},"wissenEn\u002Fen\u002Fwissen\u002Fnis2.md","NIS2 Directive",{"type":7,"value":8,"toc":124},"minimark",[9,13,18,21,25,28,62,65,69,72,76,79,83,86,90,93,97],[10,11,12],"p",{},"NIS2 is Directive (EU) 2022\u002F2555 on measures for a high common level of cybersecurity across the Union. It replaces the NIS Directive of 2016, considerably widens the circle of affected companies and obliges \"essential\" and \"important\" entities to documented risk management, reporting obligations for security incidents and securing the supply chain. Member states had to transpose the directive into national law by October 2024; in Austria this is done through the Network and Information System Security Act (NISG), in Germany through the NIS2 Implementation Act. The respective national legal status is decisive.",[14,15,17],"h2",{"id":16},"why-nis2-matters","Why NIS2 matters",[10,19,20],{},"According to European Commission estimates, NIS2 affects more than 100,000 companies in the EU, including many mid-sized businesses that were previously not subject to any cybersecurity regulation. Eighteen sectors are covered, among them energy, transport, health, drinking water, digital infrastructure, public administration, postal services, waste, chemicals, food, manufacturing, digital services and research. Typically, medium-sized companies with 50 or more employees or EUR 10 million in turnover in one of these sectors are covered, in some sectors regardless of size. Management is liable for implementation; fines reach up to EUR 10 million or 2 percent of worldwide turnover for essential entities.",[14,22,24],{"id":23},"what-nis2-requires","What NIS2 requires",[10,26,27],{},"Article 21 lists ten minimum measures, including:",[29,30,31,35,38,41,44,47,50,53,56,59],"ul",{},[32,33,34],"li",{},"risk analysis and information system security policies",[32,36,37],{},"incident handling",[32,39,40],{},"business continuity, backup and crisis management",[32,42,43],{},"supply chain security, including relationships with suppliers and service providers",[32,45,46],{},"security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure",[32,48,49],{},"policies to assess the effectiveness of measures",[32,51,52],{},"cyber hygiene and training",[32,54,55],{},"cryptography and encryption",[32,57,58],{},"access control and asset management",[32,60,61],{},"multi-factor authentication and secured communication",[10,63,64],{},"Reporting obligations: early warning within 24 hours of becoming aware of a significant incident, notification within 72 hours, final report within one month.",[14,66,68],{"id":67},"how-blacklensio-supports-nis2-implementation","How blacklens.io supports NIS2 implementation",[10,70,71],{},"blacklens.io provides the technical evidence for several Article 21 measures: a continuously updated asset inventory across external, internal and cloud systems (asset management), a documented vulnerability workflow with prioritisation, assignment and retest (vulnerability handling), monitoring of ransomware leak sites against your supplier watchlist (supply chain), detection of missing MFA and phishing-resistant authentication in the identity inventory (access control), and dark web monitoring for compromised credentials. Executive and vulnerability reports can be generated on a schedule and serve as evidence for auditors and authorities. The platform does not replace organisational measures, training or emergency plans, but it provides the technical data basis for them.",[14,73,75],{"id":74},"am-i-affected-by-nis2","Am I affected by NIS2?",[10,77,78],{},"If your company operates in one of the 18 sectors and has at least 50 employees or EUR 10 million in annual turnover, very likely yes. Smaller companies can also be affected if they are contractually obliged as suppliers to an affected entity. Binding information comes from the national implementation acts and the competent authority.",[14,80,82],{"id":81},"is-an-annual-pentest-enough-for-nis2","Is an annual pentest enough for NIS2?",[10,84,85],{},"No. NIS2 requires ongoing risk management and a procedure for handling vulnerabilities, not a point-in-time check. A pentest is a sensible building block for validation, but it replaces neither the inventory nor continuous monitoring.",[14,87,89],{"id":88},"what-does-the-supply-chain-have-to-do-with-my-it-security","What does the supply chain have to do with my IT security?",[10,91,92],{},"NIS2 obliges you to assess risks at suppliers and service providers. If a supplier falls victim to ransomware, your data may be affected or your production may stop. Monitoring leak sites against a supplier watchlist makes such incidents visible, often before the supplier itself informs you.",[14,94,96],{"id":95},"related-terms","Related terms",[29,98,99,106,112,118],{},[32,100,101],{},[102,103,105],"a",{"href":104},"\u002Fen\u002Fwissen\u002Fvulnerability-management","Vulnerability Management",[32,107,108],{},[102,109,111],{"href":110},"\u002Fen\u002Fwissen\u002Fdarknet-monitoring","Dark Web Monitoring",[32,113,114],{},[102,115,117],{"href":116},"\u002Fen\u002Fwissen\u002Fcontinuous-threat-exposure-management","Continuous Threat Exposure Management (CTEM)",[32,119,120],{},[102,121,123],{"href":122},"\u002Fen\u002Fwissen\u002Fattack-surface-management","Attack Surface Management (ASM)",{"title":125,"searchDepth":126,"depth":126,"links":127},"",3,[128,130,131,132,133,134,135],{"id":16,"depth":129,"text":17},2,{"id":23,"depth":129,"text":24},{"id":67,"depth":129,"text":68},{"id":74,"depth":129,"text":75},{"id":81,"depth":129,"text":82},{"id":88,"depth":129,"text":89},{"id":95,"depth":129,"text":96},"NIS2 explained: who is affected, which risk management measures and reporting obligations apply, how transposition works in Austria and Germany and how blacklens.io provides technical evidence.","md","en",{},true,"\u002Fen\u002Fwissen\u002Fnis2",[143,144,145,146],"vulnerability-management","darknet-monitoring","continuous-threat-exposure-management","attack-surface-management",{"title":5,"description":136},"NIS2 is EU Directive 2022\u002F2555 on network and information security, which obliges essential and important entities to risk management, incident reporting and supply chain security.",{"loc":141},"en\u002Fwissen\u002Fnis2",[152,153,5,154],"NIS-2","Directive (EU) 2022\u002F2555","NISG","2026-09-14","JvvIEEnOc7NmEfMQKEpLg36e7eJ1vMgFq1Df9O6NU4I",[158,160,162,165],{"path":122,"title":123,"short":159},"Attack surface management is the continuous discovery, assessment and reduction of every point through which an attacker can reach a company: external, internal and in the cloud.",{"path":116,"title":117,"short":161},"CTEM is a programme described by Gartner with five phases (scoping, discovery, prioritisation, validation, mobilisation) that reduces the attack surface continuously instead of at points in time.",{"path":110,"title":163,"short":164},"Dark Web Monitoring (Darknet Monitoring)","Dark web monitoring continuously searches underground forums, marketplaces, leak sites and stealer logs for a company's credentials, devices and data and reports hits before they are abused.",{"path":104,"title":105,"short":166},"Vulnerability management is the ongoing process of detecting vulnerabilities in systems, prioritising them by risk, fixing them and evidencing the fix.",1789638256013]