The NIS2 Directive (Directive (EU) 2022/2555)
Reaches ICT service agreements with an essential or important entity in the EU or EEA outside the financial sector (health, energy, water, transport, telecommunications, public administration, research, certain manufacturing and digital providers): the supply chain security measures of Art. 21(2)(d) and 21(3), and the incident clock of Art. 23 (early warning within 24 hours, notification within 72). Financial entities read DORA instead.
On the register, tick "NIS2" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: NIS2 Directive (Directive (EU) 2022/2555).
What it expects, term by term
| security schedule | Art. 21(2)(d) · Art. 21(3)On an ICT service arrangement |
|---|---|
| breach clock | Art. 23(1) · Art. 23(4)(a) · Art. 23(4)(b)On an ICT service arrangement |
The clauses, quoted
5Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.
NIS2 Art. 21(2)(d) Supply chain security, covering the relationship with each direct supplier and service providerThe Directive scopes this deliberately at direct suppliers and service providers, which makes the first artefact an inventory of who those parties are and which of them touch the network and information systems behind the service. From there the entity has to manage the security-related aspects of each relationship: what the supplier may access, what security obligations bind it, what happens on incident, and what happens at exit. Contract terms are the enforcement mechanism, so contracts that predate NIS2 and carry no security clauses are a live gap rather than a legacy inconvenience. Managed service providers and managed security service providers deserve separate attention because they hold privileged access into the estate, which makes their compromise the entity's incident.
Where it usually falls short: Inventory built from the procurement system, so shadow and free-tier services are missing
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 21(3) Take account of supplier-specific vulnerabilities and of Union coordinated supply chain risk assessmentsDeciding what supply chain measures are appropriate is not left to general judgement. The entity has to take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of those parties' products and cybersecurity practices including their secure development procedures. Separately, it must take into account the results of the Union level coordinated security risk assessments of critical supply chains carried out under Article 22(1). That second limb creates an external input the entity has to watch for and respond to: when a coordinated assessment lands on a technology the entity uses, the outcome has to reach the supplier risk decisions rather than stop at a policy team. Evidence of consideration is what is being asked for, including reasoned decisions not to change anything.
Where it usually falls short: Supplier assessment reduced to a questionnaire score with no view of that supplier's actual weaknesses
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(1) Notify significant incidents to the CSIRT or competent authority, and warn affected service recipientsThe core reporting duty attaches to any incident with a significant impact on the provision of the entity's services. Article 23(3) fixes the threshold: an incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. Capable of causing matters, because it brings in near-miss and contained events that could have gone further. Notification goes to the CSIRT or, where the Member State so provides, the competent authority, without undue delay, and must carry whatever lets the recipient determine cross-border impact. Where appropriate the entity must also tell the recipients of its services about significant incidents likely to affect service delivery. The Directive states that notifying does not of itself increase the notifying entity's liability, which removes one common reason for delay.
Where it usually falls short: Threshold applied only to realised impact, so contained incidents capable of severe disruption go unreported
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(a) Submit an early warning within 24 hours of becoming aware of a significant incidentThe first stage of the layered reporting regime falls due without undue delay and in any event within 24 hours of becoming aware of the significant incident. The early warning is deliberately light: where applicable it indicates whether the incident is suspected of being caused by unlawful or malicious acts, and whether it could have cross-border impact. It is not a full assessment and waiting for one is the classic way to miss the deadline. Two operational points decide whether an entity can meet this. First, becoming aware has to be defined and evidenced, because the clock starts there and an entity that cannot say when it knew cannot show it reported in time. Second, submission has to be possible at any hour, since a Friday night detection has the same 24 hours as a Tuesday morning one. The CSIRT or authority is expected to respond within 24 hours where possible, so the channel is two-way.
Where it usually falls short: Awareness treated as the moment of executive briefing rather than of qualified detection
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
NIS2 Art. 23(4)(b) Submit an incident notification within 72 hours, with an initial assessment and indicators of compromiseWithin 72 hours of becoming aware, the entity updates the early warning and provides an initial assessment of the significant incident covering its severity and impact, together with indicators of compromise where those are available. The 72 hours runs from awareness, not from the early warning, so the two clocks start together. Trust service providers are held to a shorter deadline: for significant incidents affecting the provision of their trust services they must notify within 24 hours. The practical demand here is investigative rather than administrative, since the entity needs enough forensic capability within three days to characterise severity and impact honestly and to extract indicators worth sharing. Producing indicators requires that the telemetry existed before the incident.
Where it usually falls short: 72 hours counted from the early warning rather than from awareness
NIS2 Directive (Directive (EU) 2022/2555) in The Art of Service standards library
See what it expects of your list
Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.
Check my contract list