what has happened
The European Union published Implementing Regulation (EU) 2024/2690, which develops technical and methodological requirements related to cybersecurity risk management measures and criteria to determine when an incident can be considered significant in certain digital services.
Why it matters
NIS2 does not remain an abstract obligation. The regulations go down to operational terrain: measures, processes, incidents and evidence. For technology providers or companies within critical supply chains, this marks the type of control that clients and auditors will ask for.
What to check now
Review if you provide digital or managed services, if you are part of the supply chain of an essential or important entity, and if your incident procedures allow you to classify impact, duration, affected users and communication.
Relationship with ISO 27001
ISO 27001 helps to organize the ISMS, but NIS2 also requires looking at governance, management responsibility, continuity, incidents and third parties with a European regulatory logic.
Checklist for companies
- Map of digital services provided.
- Classification of critical clients.
- Incident procedure with severity criteria.
- Evidence of risk management.
- Review of contracts and notification obligations.
Do you want to check if this affects your company?
We can help you translate the news or standard into concrete actions: scope, gaps, evidence and priorities.
Request diagnosis