NIS2 Readiness · Add-on Module

Prepare cybersecurity compliance as operational governance.

NIS2 readiness cannot remain a policy exercise. Directive obligations require documented measures, named responsibilities, and governance records that can be shown to supervisory authorities.

EAB extends its AI governance infrastructure into NIS2 — so cybersecurity obligations become part of the same record as EU AI Act compliance, not a separate system.

Module 04 · Directive (EU) 2022/2555 (NIS2)
Art. 21 cybersecurity measures structured and tracked
Named responsibility per measure
Evidence record per obligation area
Incident reporting documentation (Art. 23)
Supply chain security governance
Shared audit trail with EU AI Act module
Art. 21 measures
10
NIS2 Art. 21 cybersecurity measure categories tracked.
Governance features
6
Measures, incidents, supply chain, evidence, audit trail.
Shared audit trail
One
Same record as EU AI Act — not a parallel system.
Duplicate evidence
Zero
Evidence collected once, referenced where obligations overlap.
The NIS2 readiness problem

“Most organisations that are subject to NIS2 are also using AI systems. Managing cybersecurity governance and AI governance in separate tools means auditors see two partial records — and neither one tells the complete story.”

EAB Design Principle · Integrated Compliance Infrastructure
Module coverage

What the NIS2 Readiness module covers.

The NIS2 Readiness module addresses the governance gap between cybersecurity obligations and the evidence record that NIS2 supervisory authorities expect. Article 21 requires documented cybersecurity risk management measures — ten categories, each requiring implementation evidence and named responsibility.

EAB structures NIS2 obligations as governed records — each measure with an owner, an implementation state, and an evidence record. Article 23 incident reporting requirements are documented with structured timelines and response records. Supply chain security obligations are addressed through the vendor governance layer.

For organisations that use AI systems covered by the EU AI Act, the NIS2 module operates within the same governance infrastructure — so the AI system record, the cybersecurity measure record, and the incident record are one coherent governance artefact, not three separate documents.

Module Includes
  • Art. 21Ten cybersecurity measure categories documented
  • Art. 21Named responsibility and evidence per measure
  • Art. 23Incident reporting documentation and timelines
  • Art. 21(d)Supply chain security governance
  • Art. 21(a)Risk analysis and policy documentation
  • AuditNIS2 governance export for supervisory authority
  • IntegrationShared with EU AI Act record
What’s included

Six NIS2 governance capabilities.

Each capability is connected to the shared system inventory, evidence layer, and audit trail.

Art. 21 · Risk

Cybersecurity Risk Management

Article 21 requires appropriate and proportionate cybersecurity risk management measures. EAB documents each measure in a structured record — with the security objective it addresses, the implementation state, and the responsible owner.

Art. 21 · Measures

Ten Measure Categories Tracked

All ten Article 21 measure categories — from policies on information security to access control, encryption, and business continuity — are tracked as separate governance objects with individual evidence and ownership records.

Integration

NIS2 – AI Act Bridge

AI systems subject to the EU AI Act often also require NIS2-compliant cybersecurity measures. This module connects the NIS2 governance record to the AI Act system record — so cybersecurity evidence supports both compliance frameworks simultaneously.

Art. 23

Incident Reporting Documentation

Article 23 requires significant incident notification within defined timeframes. EAB documents incident events with a structured timeline, notification records, response measures, and resolution status — all within the governance audit trail.

Art. 21(d)

Supply Chain Security

Supply chain security obligations under NIS2 are addressed through vendor governance records — documenting security requirements for each supplier, evidence of compliance, and the procurement context. Connected to the GDPR vendor governance layer where applicable.

Audit

Supervisory Authority Export

NIS2 supervisory authorities may request evidence of cybersecurity risk management. EAB exports a structured NIS2 governance record — measure documentation, evidence, incident history, and responsibility attribution — ready for submission.

Platform integration

Not a separate tool. Part of the same record.

The NIS2 Readiness module uses the same AI system inventory as the EU AI Act module. Cybersecurity measures are linked to the systems they protect — systems that are already registered and governed in EAB.

Evidence uploaded for NIS2 cybersecurity measures is available in the same evidence layer as EU AI Act evidence. Where the same security measure supports both EU AI Act Art. 15 and NIS2 Art. 21 obligations, it is documented once and referenced in both obligation records.

At audit time, a supervisory authority reviewing NIS2 compliance sees the cybersecurity record alongside the AI governance record — one coherent governance infrastructure, not two parallel systems that need reconciliation.

Shared with EU AI Act
  • SystemsSame system inventory — NIS2 measures linked to registered AI systems
  • EvidenceShared evidence layer — security evidence referenced across frameworks
  • TrailOne audit trail — NIS2 and AI Act governance in one record
  • RolesSame role model — owners and supervisors carry across modules
Add-on module

Add NIS2 Readiness to your compliance layer.

Available as an add-on for Professional and Enterprise. Shares one system inventory, one evidence layer, and one audit trail with the EU AI Act module.

EU-hosted · Anchored to CELEX 32024R1689

Get in Touch
Request More Information

Tell us about your organization and what you’re looking to address. We’ll follow up with the relevant information.