Logo
StreamLex Home
Logo
StreamLex Home
Laws
Laws
Recitals
Recitals
About Us
News
Recitals
Trackers
Resources
Newsletter
Terms of Use
Privacy Notice
LinkedIn
undefined | StreamLex

NIS2 Technical Implementation Guidance

NIS2 Technical Implementation Guidance

This document outlines non‑binding guidance for the “relevant entities” —such as cloud providers, DNS registries, CDNs, MSSPs and trust-service providers—supporting the technical and methodological requirements set out by Commission Implementing Regulation (EU) 2024/2690 on cybersecurity risk management under Article 21(2) of NIS2. It provides implementation advice, suggested evidence, and mappings to standards and good practices across 13 requirement domains like risk policy, incident handling, supply‑chain security, cryptography, HR security, access control, asset management, and environmental security. It is based on collaboration with the European Commission, NIS Cooperation Group, and relevant expert authorities.

Metadata

Author: European Union Agency for Cybersecurity (ENISA)

Status: Adopted / Published

Adoption date: 2025-06-26

Last updated: 02 Sept 2025

Category: Guidance

Subcategory: Official guidance

Relevant laws and articles:

NIS2
21
Source URL:https://www.enisa.europa.eu/publications/nis2-technical-implementation-guidance
Additional Materials:

ENISA Technical Implementation Guidance Mapping table version 1.1

ENISA Technical Implementation Guidance Mapping table version 1.2

View Documents

Viewing: NIS2 Technical Implementation Guidance

© 2026 StreamLex

NewsletterAbout UsTerms of UsePrivacy NoticeManage Cookies

© 2026 StreamLex