Noru

NIS2 compliance software: what to look for

Who the directive covers, what it actually requires, and the questions that separate tools that support it from tools that mention it.

NIS2 compliance software supports the cybersecurity risk-management measures and incident reporting that Directive (EU) 2022/2555 requires of essential and important entities. Two things distinguish a real implementation from a marketing checkbox: whether the tool can evidence the Article 21 measures continuously — risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, cryptography, access control — and whether it can actually run the Article 23 reporting clock, which starts with an early warning within 24 hours of becoming aware of a significant incident. Because NIS2 is a directive, national transpositions differ, so check jurisdiction handling too.

What to look for

Does it evidence the Article 21 measures continuously?

The measures are outcomes — risk analysis, incident handling, continuity, supply chain security, vulnerability handling, cryptography, access control, and testing their effectiveness. Ask how the tool shows each one is operating now, not that a policy describing it exists.

Can it run the reporting clock?

Article 23 requires an early warning within 24 hours of awareness, a fuller notification within 72 hours, and a final report within a month. A tool that cannot start, track and evidence that timeline is not helping with the part of NIS2 most likely to go wrong under pressure.

How does it handle national transposition?

Member states implement the directive in their own law, with their own competent authorities and, in places, their own thresholds. Check whether the tool models the jurisdictions you operate in or offers a single generic interpretation.

Does it connect supply chain risk to the same programme?

Supply chain security is an Article 21 measure, not an adjacent concern. If vendor assessments live in a separate product with a separate register, you will be reconciling two views of the same risk.

Does it reuse what you already run for ISO 27001?

Most NIS2 measures overlap heavily with an existing ISMS. A platform that maps controls once and reuses the evidence should make NIS2 substantially cheaper if you are already certified; one that treats it as a fresh framework will not.

The kinds of tool on the market

Four shapes of vendor, described by category rather than by name. Which one fits depends on how fast your systems change and how much judgement you need to buy in.

Broad enterprise suites

Large, modular GRC platforms that cover most regimes through separately licensed modules, usually with a long implementation and a dedicated administrator.

Best fit: Large organisations with a compliance team big enough to own configuration, and budget that tolerates a multi-module licence.

Point tools

Focused products that do one job well — consent, DSAR intake, cookie scanning, vendor questionnaires — and integrate loosely with whatever else you run.

Best fit: Teams with one acute, well-bounded problem, who accept that the register tying everything together lives somewhere else.

Consultancies and managed services

People rather than software: an external DPO or advisory retainer that produces the documentation on your behalf, often in documents you then own.

Best fit: Organisations without in-house expertise who need judgement more than tooling, and who can accept that the output is a snapshot.

Compliance operations platforms

Systems that connect to what you already run, derive the records from live signals, and keep them current between audits rather than regenerating them before one.

Best fit: Teams whose systems change faster than documents can be maintained by hand, and who need to evidence a current state on demand.

Where Noru fits

Noru maps NIS2 measures into the same control library as ISO 27001, SOC 2 and the rest, so evidence collected once counts toward every framework that asks for it rather than being gathered again.

Controls are monitored continuously from connected systems, so the Article 21 measures have a current state and a history rather than a policy document and a review date.

Third-party and supply chain risk sits in the same programme rather than a separate tool, which is what Article 21's supply chain measure actually asks for.

FAQ

Common questions

Talk to us

Who does NIS2 apply to?

Essential and important entities operating in the sectors set out in the directive's annexes, generally above size thresholds, along with certain entities designated regardless of size. Because implementation is national, the precise scope in your country comes from the transposing law rather than the directive alone.

What does NIS2 actually require?

Appropriate and proportionate cybersecurity risk-management measures under Article 21 — covering risk analysis, incident handling, business continuity, supply chain security, secure development, vulnerability handling, cryptography, access control and testing — plus incident reporting under Article 23 and accountability at management level.

What are the NIS2 incident reporting deadlines?

For a significant incident: an early warning to the competent authority or CSIRT within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month.

Does ISO 27001 certification make us NIS2 compliant?

No, but it takes you a long way. The Article 21 measures overlap substantially with an ISO 27001 ISMS. What certification does not cover is the reporting obligations, the management accountability provisions, and whatever your national transposition adds.

How does NIS2 relate to DORA?

They target different populations. DORA is the financial sector's operational resilience regulation and applies as lex specialis to entities within its scope; NIS2 covers a broader set of sectors. Some groups fall under both for different entities, which is a good reason to run them from one control library.

See Noru against your own systems

A 45-minute walkthrough against your frameworks, your integrations and your evidence.