NEWVenvera speaks your language: the full platform, in English, German, Spanish, Bulgarian and Arabic.See what’s new
NIS2 compliance software

Under NIS2, your management is personally liable.

Venvera is NIS2 compliance software that turns the ten Article 21 measures, 24-hour incident early warning and supply-chain risk into operational workflows, not checkboxes, so you can prove it to your national authority the day they ask and keep the liability off your board’s shoulders.

Risk & policiesIncident handlingBusiness continuitySupply-chain securityCyber hygieneAccess control & MFA

How much of NIS2 do you already have?

Pick the framework you already run. Every control domain that appears in both is listed with the requirement reference on each side, so you can see the reusable part of your existing programme before you scope any new work.

You already run
You have been asked to add
30 of the 43 domains in this crosswalk appear in both NIST SP 800-53 and NIS2.
DomainNIST SP 800-53NIS2
Encryption
SC-13Cryptographic Protection
SC-28Protection of Information at Rest
SC-8Transmission Confidentiality and Integrity
Art. 21(2)(h)Are policies and procedures in place governing the use of cryptography, including encryption standards for data at rest and in transit?
Key Management
SC-12Cryptographic Key Establishment and Management
Art. 21(2)(h)Are cryptographic key management procedures documented, covering key generation, distribution, storage, rotation, and destruction?
Access Control
AC-3Access Enforcement
AC-6Least Privilege
Art. 21(2)(i)Is there a formal access control policy enforcing least privilege principle, with documented procedures for access provisioning and de-provisioning?
Identity Management
AC-2Account Management
IA-4Identifier Management
Art. 21(2)(i)Is there a formal access control policy enforcing least privilege principle, with documented procedures for access provisioning and de-provisioning?
Authentication & MFA
IA-2Identification and Authentication (Organizational Users)
IA-5Authenticator Management
Art. 21(2)(j)Is multi-factor authentication or continuous authentication deployed for access to critical systems, remote access, and privileged accounts?
Access Rights Review
AC-2Account Management
Art. 21(2)(i)Are access rights reviewed regularly (at least annually) and recertified, with privileged access subject to enhanced controls and monitoring?
Privileged Access Management
AC-6Least Privilege
AC-5Separation of Duties
Art. 21(2)(i)Are access rights reviewed regularly (at least annually) and recertified, with privileged access subject to enhanced controls and monitoring?
Network Security
SC-7Boundary Protection
AC-17Remote Access
Art. 21(2)(g)Are basic cyber hygiene practices established and enforced, including patching, password policies, device management, and network segmentation?
Vulnerability Management
RA-5Vulnerability Monitoring and Scanning
SI-2Flaw Remediation
Art. 21(2)(e)Is there a vulnerability handling and disclosure process that ensures timely identification, assessment, and remediation of vulnerabilities?
Logging & Monitoring
AU-2Event Logging
AU-6Audit Record Review, Analysis, and Reporting
AU-12Audit Record Generation
SI-4System Monitoring
Art. 21(2)(f)Are security metrics and KPIs defined, tracked, and reported to management to measure the effectiveness of cybersecurity controls?
Incident Management
IR-4Incident Handling
Art. 21(2)(b)Is there a documented incident handling procedure covering detection, analysis, containment, eradication, and recovery phases?
Incident Classification
IR-5Incident Monitoring
Art. 23(3)Are incident classification criteria documented, distinguishing significant incidents based on impact on service provision, affected users, duration, and geographic scope?
Incident Reporting
IR-6Incident Reporting
Art. 23(4)(a)–(b)Can your organisation submit an early warning to the CSIRT within 24 hours and an incident notification within 72 hours of becoming aware of a significant incident?
Incident Response Team
IR-8Incident Response Plan
Art. 21(2)(b)Is there a documented incident handling procedure covering detection, analysis, containment, eradication, and recovery phases?
Post-Incident Review
IR-4Incident Handling
Art. 21(2)(b)Do you perform post-incident reviews for significant incidents, with root cause analysis and lessons learned fed into risk management improvements?
Business Continuity
CP-2Contingency Plan
Art. 21(2)(c)Are business continuity and disaster recovery plans documented, covering all critical services, with defined RTO/RPO targets and tested at least annually?
Backup & Restoration
CP-9System Backup
CP-10System Recovery and Reconstitution
Art. 21(2)(c)Are backup procedures implemented with defined scope, frequency, and secure off-site storage, with regular restoration testing?
Crisis Management
CP-4Contingency Plan Testing
Art. 21(2)(c)Is there a crisis management framework with defined escalation procedures, communication plans, and designated crisis management team?
Third-Party Risk Management
SR-2Supply Chain Risk Management Plan
Art. 21(2)(d)Is there a documented supply chain security policy covering ICT product and service procurement, with security requirements for suppliers?
Supplier Due Diligence
SR-6Supplier Assessments and Reviews
SA-4Acquisition Process
Art. 21(2)(d)Do you assess the cybersecurity posture and practices of direct suppliers and service providers before entering into agreements?
Supplier Contracts
SR-5Acquisition Strategies, Tools, and Methods
PS-7External Personnel Security
Art. 21(2)(d)Do supplier contracts include cybersecurity requirements, incident notification obligations, and audit/assessment rights?
Supplier Monitoring
SR-3Supply Chain Controls and Processes
SR-6Supplier Assessments and Reviews
Art. 21(2)(d)Are supply chain risks and supplier cybersecurity performance monitored on an ongoing basis, with periodic re-assessment?
Risk Assessment
RA-3Risk Assessment
PM-9Risk Management Strategy
Art. 21(2)(a)Is there a formal, documented risk analysis methodology that identifies and assesses cybersecurity risks to network and information systems?
Information Security Policy
AC-1Policy and Procedures
PL-2System Security and Privacy Plans
Art. 21(2)(a)Has the management body approved a comprehensive information security policy covering all network and information systems, reviewed at least annually?
Security Awareness Training
AT-2Literacy Training and Awareness
AT-3Role-Based Training
Art. 20(2), Art. 21(2)(g)Is there a cybersecurity awareness and training programme for all staff, including management body members, with regular refresher sessions?
Change Management
CM-3Configuration Change Control
Art. 21(2)(e)Is there a formal change management process for network and information systems that includes security impact assessment and testing?
Secure Development
SA-3System Development Life Cycle
SA-8Security and Privacy Engineering Principles
Art. 21(2)(e)Are secure development practices (secure coding guidelines, code review, security testing) applied to in-house and custom-developed software?
Security Testing
SA-11Developer Testing and Evaluation
CA-2Control Assessments
Art. 21(2)(f)Are there defined policies and procedures to assess the effectiveness of cybersecurity risk-management measures, including regular security testing?
Penetration Testing
CA-8Penetration Testing
Art. 21(2)(f)Are there defined policies and procedures to assess the effectiveness of cybersecurity risk-management measures, including regular security testing?
Breach Notification
IR-6Incident Reporting
SR-8Notification Agreements
Art. 23(4)(a)–(b)Can your organisation submit an early warning to the CSIRT within 24 hours and an incident notification within 72 hours of becoming aware of a significant incident?

A row means the two requirements cover the same ground, so one implementation and one set of evidence can usually serve both. It does not mean satisfying one certifies the other: each framework keeps its own scope, wording and assessment, and some requirements have no counterpart at all. Treat this as a starting map for planning, then confirm each row against the requirement text.

NIS2 compliance software for the Article 21 measures and the clocks

Venvera is NIS2 compliance software for essential and important entities under Directive (EU) 2022/2555, as transposed by your member state. It carries 14 tracked controls covering the ten risk-management measures in Article 21, from risk analysis and incident handling to supply-chain security, cryptography and multi-factor authentication. Each control names the evidence your national competent authority will look for and records who owns it. Incident reporting runs on the 24-hour early warning and 72-hour notification deadlines, and the Article 20 management-body approval is evidenced alongside the measures.

What is NIS2, and why is it your board’s problem?

NIS2 (Directive (EU) 2022/2555) is EU cybersecurity law that each member state transposes into national law, binding essential and important entities across 18 sectors - energy, transport, banking, health, digital infrastructure and more. It is enforced by your national competent authority, which can inspect, audit and sanction. And under Article 20 the accountability is personal: your management body must approve and oversee the cybersecurity measures, so infringements carry fines up to 10 million euros or 2% of global annual turnover for essential entities, with authorities empowered to suspend management from their roles until they comply. Miss the measures and the exposure lands on named individuals, not just the company.

 app.venvera.com
/ NIS2 · ten Article 21 measures, one audit-ready screen
/ NIS2 · ten Article 21 measures, one audit-ready screen
10
Article 21 measures, all covered
24h
Early warning deadline, auto-tracked
72h
Incident notification deadline tracked
Art. 20
Management liability, evidenced
Article 21(2)(a)

All ten Article 21 measures, in one live register.

NIS2 Article 21 opens with risk analysis and information system security policies - and a competent authority reads that as your whole risk posture. Venvera gives you a structured register where every risk is scored on a 5x5 likelihood-by-impact matrix, classified, owned and tracked through treatment, with security policies under version control and approval workflows. The gap assessment maps what you have against all ten Article 21 measures and shows exactly where coverage is missing - before an inspector finds it.

  • Centralised risk register with automated 5x5 scoring
  • Policy library with version control and approval workflows
  • Gap assessment against all 10 NIS2 Article 21 measures
  • Cross-framework mapping to DORA, ISO 27001 and GDPR
  • Evidence export for competent authority requests
 app.venvera.com
/ RISK REGISTER · 5x5 scoring, all ten measures mapped
/ RISK REGISTER · 5x5 scoring, all ten measures mapped
Article 23

A 24-hour incident clock that starts itself.

NIS2 gives you a three-stage clock for every significant incident, and Venvera enforces all of it: a 24-hour early warning to the CSIRT, a 72-hour notification with initial assessment, and a one-month final report with root-cause analysis. Built-in criteria decide whether an incident is significant, pre-formatted templates carry every required field, and the countdown starts the moment the incident does - so a reporting deadline is never something someone had to remember under pressure.

  • Automatic significance classification against NIS2 criteria
  • Countdown timers for the 24h, 72h and 1-month deadlines
  • Pre-formatted templates for early warning, notification and final report
  • Cross-border impact flagging for multi-jurisdiction incidents
  • Complete incident timeline for supervisory review
 app.venvera.com
/ INCIDENTS · 24h / 72h / 1mo, tracked to the minute
/ INCIDENTS · 24h / 72h / 1mo, tracked to the minute
Article 21(2)(d)

Find the supplier that takes you down - first.

Article 21(2)(d) makes you own the security of your direct suppliers and service providers - and their subcontractors. Venvera scores each supplier across five weighted dimensions, maps the subcontracting chain to n-th party, and flags concentration risk at provider and country level before it becomes an incident. Contractual security requirements, SLA compliance and periodic reassessment all live in one place, documented and ready for review.

  • Five-dimension automated supplier risk scoring
  • Subcontracting chain mapping with n-th party visibility
  • Contractual security requirements tracking per supplier
  • Concentration risk alerts at provider and geographic level
  • Periodic reassessment scheduling with overdue alerting
 app.venvera.com
/ THIRD-PARTY RISK · concentration surfaced, chains mapped
/ THIRD-PARTY RISK · concentration surfaced, chains mapped
Article 21(2)(c)

Prove you can keep running when it breaks.

Article 21(2)(c) wants proof you can keep running through a disruption - backups, disaster recovery and crisis management that actually work. Venvera tracks RTO and RPO targets per critical asset, links each asset to the business function it supports so you can see cascade effects, and holds your continuity plans under version control with test schedules and post-test findings. When the authority asks whether you tested it, the answer is already documented.

  • RTO and RPO target tracking per critical asset
  • Asset-to-function dependency mapping for impact analysis
  • Business continuity plan versioning with approval workflows
  • Testing schedule management with post-test findings
  • Crisis management procedures with escalation chains
 app.venvera.com
/ CONTINUITY · plans, RTO/RPO and test evidence
/ CONTINUITY · plans, RTO/RPO and test evidence
Article 21(2)(g)

Cyber hygiene and training, evidenced for the audit.

Article 21(2)(g) requires basic cyber hygiene and cybersecurity training for everyone - and evidence that it happened. Venvera tracks training completion by department and role, documents your hygiene policies and baseline controls, and flags overdue certifications before they lapse. Every completion and policy sign-off is captured as an evidence package your competent authority can review on request.

  • Training completion tracking by department and role
  • Cyber hygiene policy management with annual review cycles
  • Baseline control implementation monitoring
  • Overdue training and certification alerting
  • Evidence packages for competent authority audits
 app.venvera.com
/ EVIDENCE · training and hygiene, packaged for audit
/ EVIDENCE · training and hygiene, packaged for audit
Article 20

The evidence that keeps liability off your board.

Article 20 makes your management body personally liable: they must approve the cybersecurity measures, oversee implementation and complete training - and infringements can cost them their roles. Venvera logs every element of that oversight: policy approvals with digital sign-off, risk-report reviews, training completion and meeting attendance, exportable as a personal accountability package per management member. It is the evidence that proves the board governed - and keeps the liability where it belongs.

  • Policy approval tracking with digital sign-off records
  • Management training completion records and reminders
  • Risk report review log with acknowledgement tracking
  • Meeting attendance and cybersecurity agenda item logging
  • Personal accountability evidence export per management member
 app.venvera.com
/ BOARD · Article 20 oversight, evidenced per member
/ BOARD · Article 20 oversight, evidenced per member
Why switch

The spreadsheet or Venvera.

Spreadsheets
Venvera
Risk analysis
Ad-hoc assessments, no structured methodology
Automated 5x5 scoring with Article 21 gap mapping
Incident notification
Manual deadline tracking, email-based process
24h/72h/1mo countdown timers with auto-escalation
Supply-chain security
Vendor list without risk scoring
5-dimension supplier scoring with concentration alerts
Business continuity
Static document, updated once a year
Living plans with RTO/RPO tracking and test scheduling
Training records
Spreadsheet tracking, no reminders
Automated tracking by department with overdue alerts
Management oversight
No evidence trail for Article 20
Digital sign-offs, training records, meeting logs

NIS2, answered.

NIS2 guides

Know where you stand on NIS2 before the regulator asks.

Start with a free gap report across the Article 21 measures - 10 minutes, no email to start.

Every paid plan: audit-ready in 90 days, or your money back*

10 minutes · no email to start · no credit card · yours to keep