NIS2 · Directive (EU) 2022/2555
NIS2 compliance for essential and important entities
NIS2 widens who's in scope and sets firmer duties for risk management, incident reporting and management accountability. ResiliencePilot turns those duties into controls and evidence your management body can stand behind.

What NIS2 requires, and how we deliver it
Every duty maps to a workflow
Risk-management measures, staged incident reporting, supply-chain security: each NIS2 duty runs through the platform with a full audit trail.
Risk-management measures
Implement and evidence the NIS2 cybersecurity risk-management measures (policies, controls, business continuity and supply-chain security) in one register.
Staged incident reporting
Capture incidents and draft the early warning, notification and final report, with rAIley shaping the regulatory narrative against the timelines.
Supply-chain security
Run third-party risk management across your supply chain: tier vendors by criticality, run due-diligence questionnaires, and link supplier risk to your incident and continuity records.
Management accountability
Give your management body the oversight dashboards and a documented sign-off trail, with 4-eyes approvals on key decisions.
Article 21(2)(c): Business continuity & crisis management
Backup management, disaster recovery and crisis management, evidenced through BIA, recovery strategies and a tested exercise programme, all held in the same system as the rest of your continuity work.
Cross-framework reuse
Pull in controls you already run for ISO 27001 or DORA and map them straight to NIS2.
Where rAIley helps with NIS2
rAIley drafts the staged incident notifications NIS2 calls for and proposes risk-management measures and controls from your own descriptions, each grounded in your data, citation-backed and audit-logged. Your team keeps the final say and signs off before anything is filed.
Frequently asked questions
- Yes. You capture the incident once and draft the early warning, the notification and the final report; rAIley helps shape each against the NIS2 reporting timelines. Your team reviews and submits.
- That depends on your sector and size under NIS2. ResiliencePilot supports both; the obligations differ in supervision, not in the platform you use.
- Yes. Overlapping controls are mapped once and reused across every framework you run.
- In the EU, on Microsoft Azure (Sweden Central). If you have specific residency requirements, talk to us.
Does ResiliencePilot handle NIS2 incident reporting timelines?
Are we an essential or important entity?
Can we reuse our ISO 27001 controls for NIS2?
Where is our data hosted?
Meet NIS2 with ResiliencePilot
See it on your own data and frameworks, with your security and data-residency questions answered.