Regulated Customer Contract Checker
Regimes · NIS2

The NIS2 Directive (Directive (EU) 2022/2555)

Reaches ICT service agreements with an essential or important entity in the EU or EEA outside the financial sector (health, energy, water, transport, telecommunications, public administration, research, certain manufacturing and digital providers): the supply chain security measures of Art. 21(2)(d) and 21(3), and the incident clock of Art. 23 (early warning within 24 hours, notification within 72). Financial entities read DORA instead.

On the register, tick "NIS2" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: NIS2 Directive (Directive (EU) 2022/2555).

What it expects, term by term

security scheduleArt. 21(2)(d) · Art. 21(3)On an ICT service arrangement
breach clockArt. 23(1) · Art. 23(4)(a) · Art. 23(4)(b)On an ICT service arrangement

The clauses, quoted

5

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

NIS2 Art. 21(2)(d) Supply chain security, covering the relationship with each direct supplier and service provider

The Directive scopes this deliberately at direct suppliers and service providers, which makes the first artefact an inventory of who those parties are and which of them touch the network and information systems behind the service. From there the entity has to manage the security-related aspects of each relationship: what the supplier may access, what security obligations bind it, what happens on incident, and what happens at exit. Contract terms are the enforcement mechanism, so contracts that predate NIS2 and carry no security clauses are a live gap rather than a legacy inconvenience. Managed service providers and managed security service providers deserve separate attention because they hold privileged access into the estate, which makes their compromise the entity's incident.

Evidence an auditor accepts: Inventory of direct suppliers and service providers, flagged for access to in-scope systems; Risk assessment per supplier proportionate to the access and criticality involved; Contractual security clauses, including incident notification obligations and audit or assurance rights
Where it usually falls short: Inventory built from the procurement system, so shadow and free-tier services are missing
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 21(3) Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessments

Deciding what supply chain measures are appropriate is not left to general judgement. The entity has to take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of those parties' products and cybersecurity practices including their secure development procedures. Separately, it must take into account the results of the Union level coordinated security risk assessments of critical supply chains carried out under Article 22(1). That second limb creates an external input the entity has to watch for and respond to: when a coordinated assessment lands on a technology the entity uses, the outcome has to reach the supplier risk decisions rather than stop at a policy team. Evidence of consideration is what is being asked for, including reasoned decisions not to change anything.

Evidence an auditor accepts: Per-supplier assessment records that address that supplier's own vulnerabilities and secure development practice; A watch process for Union coordinated supply chain risk assessments and the outputs it has captured; Decision records showing how each relevant coordinated assessment was reflected in supplier measures
Where it usually falls short: Supplier assessment reduced to a questionnaire score with no view of that supplier's actual weaknesses
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(1) Notify significant incidents to the CSIRT or competent authority, and warn affected service recipients

The core reporting duty attaches to any incident with a significant impact on the provision of the entity's services. Article 23(3) fixes the threshold: an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Capable of causing matters, because it brings in near-miss and contained events that could have gone further. Notification goes to the CSIRT or, where the Member State so provides, the competent authority, without undue delay, and must carry whatever lets the recipient determine cross-border impact. Where appropriate the entity must also tell the recipients of its services about significant incidents likely to affect service delivery. The Directive states that notifying does not of itself increase the notifying entity's liability, which removes one common reason for delay.

Evidence an auditor accepts: The documented significance test, expressed against the Article 23(3) limbs including capable of causing; The determination record for each candidate incident, including reasoned decisions not to report; Notifications as submitted, with timestamps, and the identity of the receiving CSIRT or authority
Where it usually falls short: Threshold applied only to realised impact, so contained incidents capable of severe disruption go unreported
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(a) Submit an early warning within 24 hours of becoming aware of a significant incident

The first stage of the layered reporting regime falls due without undue delay and in any event within 24 hours of becoming aware of the significant incident. The early warning is deliberately light: where applicable it indicates whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact. It is not a full assessment and waiting for one is the classic way to miss the deadline. Two operational points decide whether an entity can meet this. First, becoming aware has to be defined and evidenced, because the clock starts there and an entity that cannot say when it knew cannot show it reported in time. Second, submission has to be possible at any hour, since a Friday night detection has the same 24 hours as a Tuesday morning one. The CSIRT or authority is expected to respond within 24 hours where possible, so the channel is two-way.

Evidence an auditor accepts: The definition of becoming aware and the evidence trail that fixes that moment per incident; Submitted early warnings with timestamps, measured against the 24-hour limit; Out-of-hours submission capability, including named authorised submitters and their credentials
Where it usually falls short: Awareness treated as the moment of executive briefing rather than of qualified detection
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(b) Submit an incident notification within 72 hours, with an initial assessment and indicators of compromise

Within 72 hours of becoming aware, the entity updates the early warning and provides an initial assessment of the significant incident covering its severity and impact, together with indicators of compromise where those are available. The 72 hours runs from awareness, not from the early warning, so the two clocks start together. Trust service providers are held to a shorter deadline: for significant incidents affecting the provision of their trust services they must notify within 24 hours. The practical demand here is investigative rather than administrative, since the entity needs enough forensic capability within three days to characterise severity and impact honestly and to extract indicators worth sharing. Producing indicators requires that the telemetry existed before the incident.

Evidence an auditor accepts: Submitted notifications with timestamps measured from the awareness moment; The initial severity and impact assessment as submitted, and the basis for it; Indicators of compromise shared, and the telemetry and tooling they were derived from
Where it usually falls short: 72 hours counted from the early warning rather than from awareness
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list