Concrete implementation advice
Every requirement of the Regulation is translated into traceable implementation steps — with explanations of what matters in practice and the pitfalls to avoid.
The ENISA guidance breaks every requirement of Commission Implementing Regulation (EU) 2024/2690 down into concrete implementation advice, evidence examples and standard mappings — the practical blueprint for making the NIS2 risk-management measures under Article 21(2) audit-ready.
With Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024, the European Commission set out the technical and methodological requirements for the cybersecurity risk-management measures under Article 21(2) of NIS2. The Regulation formally applies first to certain types of digital providers — from DNS services and cloud and data-centre operators to Managed (Security) Service Providers and trust service providers.
The ENISA Technical Implementation Guidance is the non-binding companion to it: for each requirement it explains how to meet it in practice, what evidence auditors expect and how the measure maps to established standards. That makes the guidance a practical blueprint — including for all other NIS2 entities to which the Regulation does not (yet) directly apply.
Six core building blocks that turn the ENISA guidance from a list of rules into an actionable handbook.
Every requirement of the Regulation is translated into traceable implementation steps — with explanations of what matters in practice and the pitfalls to avoid.
For each measure the guidance names example evidence — policies, logs, configurations, test reports — you can use to document effectiveness to auditors and authorities.
Each requirement is mapped to European and international standards, including ISO/IEC 27001/27002, the NIST Cybersecurity Framework (CSF) and IEC 62443 — so existing certifications count.
The structure follows the Annex of the Regulation: from security policy, risk management and incident handling through business continuity and supply-chain security to cryptography, access control and multi-factor authentication (MFA).
The guidance makes clear which provider types the Regulation applies to directly — and explains why the advice is valuable as a blueprint for other essential and important entities too.
It places the technical requirements in the legal framework: the Regulation specifies the binding obligation under Article 21(2) of NIS2, while the ENISA guidance explains how to meet it — and is itself not binding.
The ENISA guidance does not stand alone — it interlocks with law, standards and existing management systems.
The Regulation specifies Article 21(2) of NIS2; national transposition (in Germany the NIS2 Implementation Act) remains the binding frame. The guidance helps you meet those duties technically.
The standard mappings make an existing ISO/IEC 27001 ISMS an accelerator: existing controls and evidence can be mapped precisely to the Regulation's requirements and gaps made visible.
For financial entities, DORA complements the NIS2 logic with sector-specific requirements. Where both apply, a shared control and evidence framework avoids duplicate work.
In Germany, IT-Grundschutz provides concrete modules and requirements that combine well with the ENISA implementation advice — from risk analysis to evidence management.
Four steps from baseline assessment to robust evidence.
We compare your current state with CIR (EU) 2024/2690 and the ENISA guidance — requirement by requirement across all 13 measure areas, with clear prioritisation of the gaps.
We close the gaps with concrete technical and organisational measures — from policies and processes through hardening and cryptography to MFA and access control.
For each measure we build the evidence ENISA recommends — documented, versioned and centrally findable, so effectiveness is provable.
We embed effectiveness assessment, reviews and updates into operations so your evidence stays current — for audits, authorities and customers.
1
2
3
4
This self-check is no substitute for a formal assessment; it is a first orientation.
Primary sources for verification and matching VamiSec services.
Answers on the ENISA guidance and how to apply it.
No. The guidance is explicitly non-binding. What is binding is the NIS2 Directive (or its national transposition) and — for the provider types concerned — Commission Implementing Regulation (EU) 2024/2690. The guidance explains how to meet those requirements in practice.
Initially to certain types of digital providers: DNS services, TLD registries, cloud computing, data centres, CDN, Managed (Security) Service Providers, online marketplaces, online search engines, social networks and trust service providers. For other NIS2 entities it is a valuable blueprint.
The roughly 13 areas of the Regulation's Annex: security policy, risk management, incident handling, business continuity and crisis management, supply-chain security, security in acquisition/development/maintenance, effectiveness assessment, cyber hygiene and training, cryptography, human-resources security/access control/asset management, plus MFA and secured communications.
For each measure the guidance names example evidence — such as approved policies, a risk register, incident logs, hardening and configuration records, test and audit reports, and training records. What matters is that they are current, versioned and findable.
Often yes. Via the guidance's standard mappings, existing controls and evidence from an ISMS can be mapped precisely to the Regulation's requirements. That reduces duplicate work and quickly reveals the remaining gaps.
We take you from a gap analysis against the ENISA guidance to audit-ready evidence — pragmatic and requirement-precise.