---
title: "NIS2 Compliance"
description: "Incident reporting, supply chain security, and operational readiness under NIS2."
canonical: https://www.orbiqhq.com/eu-regulations/nis2
html: https://www.orbiqhq.com/eu-regulations/nis2
publisher: Orbiq GmbH
language: en
---
# NIS2 Compliance

Incident reporting, supply chain security, and operational readiness under NIS2.

- [NIS2 Art. 21 & 23: Reporting and Supply Chain Beyond ISMS](/eu-regulations/incident-reporting-supply-chain-nis2-articles-21-23.md) - NIS2 Article 21 and 23 require operational incident reporting (24h and 72h) and supply chain risk management. An ISMS helps governance, but not day to day execution.
- [NIS2 Compliance: How to Achieve and Maintain It (2026)](/eu-regulations/nis2-compliance.md) - A practical guide to NIS2 compliance — step-by-step requirements, gap analysis, implementation roadmap, and tools you need. Learn how to achieve and maintain NIS2 compliance for your organisation.
- [What Is NIS2? The Complete Guide to the EU NIS2 Directive (2026)](/eu-regulations/what-is-nis2.md) - What is NIS2? The EU NIS2 Directive (2022/2555) requires organisations in 18 critical sectors to implement cybersecurity measures, report incidents, and manage supply chain security. Complete guide covering requirements, penalties, timeline, and how to comply.
- [Vendor Assurance Under NIS2: What Article 21 Requires](/eu-regulations/vendor-assurance-nis2.md) - NIS2 Article 21(2)(d) requires continuous supply chain security. Point-in-time vendor assessments are no longer sufficient. Learn what the directive expects and how to meet it operationally.
- [NIS2 Supply Chain Security: Requirements and Gaps (2026)](/eu-regulations/nis2-supply-chain-security.md) - NIS2 supply chain security requirements under Article 21(2)(d) demand continuous vendor oversight — not annual questionnaires. Learn what's required, where your ISMS falls short, and how to build the operational layer you need.
- [NIS2 Requirements: Complete Guide to What You Must Do (2026)](/eu-regulations/nis2-requirements.md) - All NIS2 requirements in one place — the 10 Article 21 risk management measures, incident reporting timelines, management liability, registration obligations, and 2026 enforcement updates.
- [NIS2 Incident Reporting: Meeting the 24-Hour Deadline (2026)](/eu-regulations/nis2-incident-reporting-24-hour-deadline.md) - NIS2 incident reporting requires a 24-hour early warning, 72-hour notification, and one-month final report. Learn what qualifies as a significant incident, what each report must contain, and how to build the operational capability to report under pressure.
- [You're NIS2-Affected — Now What? The Gaps Beyond ISMS](/eu-regulations/nis2-affected-operational-gaps-isms.md) - You've checked whether your organization falls under NIS2. The answer is yes. You have an ISMS. And now you're discovering: between what your ISMS covers and what NIS2 operationally requires, there's a gap. This article shows where it lies – and how to close it.
- [NIS2 Compliance Checklist: Complete Article 21 Requirements (2026)](/eu-regulations/nis2-compliance-checklist-article-21.md) - The complete NIS2 compliance checklist covering all ten Article 21 risk management measures. Assess your readiness, identify gaps between your ISMS and NIS2 requirements, and prioritise your compliance roadmap.
- [Incident Response Plan vs. Management System Under NIS2](/eu-regulations/nis2-incident-response-plan-vs-management-system.md) - Every ISMS has an incident response plan. NIS2 requires an incident management system. The difference isn't semantic – it's operational. What an IMS must concretely deliver, which components it needs, and how to make the transition from plan to system.
- [NIS2 Audit Readiness: From Documentation to Evidence](/eu-regulations/nis2-audit-readiness-continuous-evidence.md) - NIS2 gives supervisory authorities the right to request evidence at any time. Not at your next audit. Not with advance notice. Any time. What this means for your evidence management – and why most organizations aren't prepared for it.
- [ISO 27001 Is Not NIS2 Compliance: What's Actually Missing](/eu-regulations/iso27001-not-nis2-compliance.md) - ISO 27001 provides the governance foundation for NIS2 – but not the operational execution. What's missing between ISMS documentation and actual NIS2 compliance, and why that's been a concrete problem since December 6, 2025.
- [NIS2 Third-Party Risk Docs: What Auditors Want to See](/eu-regulations/nis2-third-party-risk-documentation-audit-evidence.md) - The specific evidence and documentation artifacts auditors check during NIS2 supply chain security assessments. Supplier registers, risk classifications, incident communication records, and how a trust center produces audit-ready third-party risk documentation as a natural byproduct.
- [NIS2 Directive (2026): Requirements, Deadlines & Scope](/eu-regulations/nis2-directive.md) - NIS2 Directive (EU 2022/2555): who's in scope (sectors + size thresholds), Article 21 security measures, 24-hour incident reporting, and how to comply.
- [DORA vs NIS2: Key Differences and Overlaps Explained](/eu-regulations/dora-vs-nis2.md) - DORA and NIS2 compared: scope, legal form, incident reporting timelines, penalties, and how lex specialis resolves the overlap between them.
- [EU Compliance Software: Complete Buyer's Guide (2026)](/eu-regulations/eu-compliance-software.md) - How to choose EU compliance software in 2026. Covers NIS2, DORA, GDPR, and CRA requirements, key features to evaluate, EU data residency risks, and how Orbiq compares.
- [BSI IT-Grundschutz 2026: Grundschutz++ & Certification](/eu-regulations/bsi-it-grundschutz.md) - BSI IT-Grundschutz explained: 111 building blocks, BSI Standards 200-1 to 200-4, the Grundschutz++ reform, certification, NIS2 link and costs.
- [Compliance Software for Germany: Buyer's Guide 2026](/eu-regulations/compliance-software-comparison.md) - Comparing the best compliance software for German companies in 2026. Covers ISMS, GRC, NIS2, DSGVO/GDPR, BSI IT-Grundschutz, and EU data residency requirements.
- [NIS2: Internal Proof vs External Proof](/eu-regulations/nis2-internal-proof-vs-external-proof.md) - Most organizations focus on internal controls. NIS2 raises the bar by expecting evidence for both your own security posture and the ecosystem you operate in.