1 of 29

“Act Now: From SRA to ISO/IEC 27001, A Smarter Path to NIS 2 Compliance”

Daniella Vendramini

Cyber Risk & Compliance Consultancy Services Team Lead

ISO/IEC 27001:2022 Lead Auditor

2 of 29

🡪 Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (December 14, 2022)

Directive (EU) 2016/1148 concerning measures for a high common level of security of network and information security across the Union” (“NIS”)

🡪 NIS 2 replaces the old NIS and came into effect on October 18, 2024

The NIS 2 Directive could become for cybersecurity what the EU GDPR has become for privacy: a worldwide standard that other countries use as a best practice for their own legislation.

What is the old NIS, and how is NIS 2 different?

NIS 1:

Cybersecurity for critical infrastructure

NIS 2:

Same level of cybersecurity across all Member States

A wider and deep pool of entities

Better cooperation between the Member States

New timelines for reporting incidents

More focus on supply chains

The responsibility on the top management of entities

Stricter penalties

Why is NIS 2 important?

It sets very strict cybersecurity requirements for many companies in European Union.

+ 100,000 companies in the EU will have to become NIS 2 compliant!

You can find the official text here: https://eur-lex.europa.eu/eli/dir/2022/2555

NIS 2 Directive: The New Reality

3 of 29

Annex I: Sectors of high criticality

Annex II: Other critical sectors

Drinking water

Wastewater

Space

ICT service management

Public administration

Digital infrastructures (including ISP and cloud)

Energy

Transport

Financial market institutions

Banking

Health

Waste management

Food production & distribution

Postal & courier services

Manufacture, production and distribution of chemicals

Digital providers

Manufacturing

Research

“Essential entities” are as follows:

    • Companies that have more than 250 employees or 50 million euro of revenue and that are in one of the Annex I: Sectors of high criticality
    • DNS service providers
    • Trust service providers
    • Public administration entities
    • Other entities specified by Member States
    • Public electronic communication networks
    • Any critical entity according to CER (EU) 2022/2557

“Essential entities”

“Important entities”

NEW SECTORS

DORA PRIORITY

NIS 1 SECTORS

NIS2 makes provision to impose administrative fines for infringements

A maximum of at least 10,000,000 EUR or up to 2% of the total worldwide annual turnover of the undertaking to which the ESSENTIAL ENTITY belongs in the preceding financial year, whichever is higher.

A maximum of at least 7,000,000 EUR or 1,4% of the total worldwide annual turnover of the undertaking to which the IMPORTANT ENTITY belongs in the preceding financial year, whichever is higher.

NIS 2 Directive Overview

*For financial market infrastructures, the Digital Operational Resilience Act (DORA) will take priority.

4 of 29

Annex I: Sectors of high criticality

Annex II: Other critical sectors

Drinking water

Wastewater

Space

ICT service management

Public administration

Digital infrastructures (including ISP and cloud)

Energy

Transport

Financial market institutions

Banking

Health

Waste management

Food production & distribution

Postal & courier services

Manufacture, production and distribution of chemicals

Digital providers

Manufacturing

Research

“Essential entities” are as follows:

    • Companies that have more than 250 employees or 50 million euro of revenue and that are in one of the Annex I: Sectors of high criticality
    • DNS service providers
    • Trust service providers
    • Public administration entities
    • Other entities specified by Member States
    • Public electronic communication networks
    • Any critical entity according to CER (EU) 2022/2557

“Essential entities”

“Important entities”

NEW SECTORS

DORA PRIORITY

NIS 1 SECTORS

NIS2 makes provision to impose administrative fines for infringements

A maximum of at least 10,000,000 EUR or up to 2% of the total worldwide annual turnover of the undertaking to which the ESSENTIAL ENTITY belongs in the preceding financial year, whichever is higher.

A maximum of at least 7,000,000 EUR or 1,4% of the total worldwide annual turnover of the undertaking to which the IMPORTANT ENTITY belongs in the preceding financial year, whichever is higher.

NIS 2 Directive Overview

*For financial market infrastructures, the Digital Operational Resilience Act (DORA) will take priority.

Not enough time…

5 of 29

NIS 2 Framework – Article 1

Responsibilities of the Member States

Cybersecurity Strategies (Government) Reporting Obligations

Competent Authorities for Crisis Management, Contact Points for Communication and for CSIRTs Role

Exchange of Cybersecurity Information

Supervisory and Enforcement Obligations

Responsibilities of the Entities

Management Commitment

Managing Cyber Security Risks

Reporting Obligations

6 of 29

The Most Important NIS 2 Requirements for Entities

Chapter I — General provisions

Chapter II — Coordinated cybersecurity frameworks

Chapter III — Cooperation at union and international level

Chapter IV — Cybersecurity risk-management measures and reporting obligations

Article 20 - Governance

Article 21 - Cybersecurity risk-management measures

Article 22 - Union level coordinated security risk assessments of critical supply chains

Article 23 - Reporting obligations

Article 24 - Use of European cybersecurity certification schemes

Article 25 - Standardisation

Chapter V — Jurisdiction and registration

Chapter VI — Information sharing

Chapter VII — Supervision and enforcement

Chapter VIII — Delegated and implementing acts

Chapter IX — Final provisions

Annex I — Sectors of high criticality

Annex II — Other critical sectors

Annex III — Correlation table between NIS 2 and NIS

7 of 29

NIS 2 Cybersecurity & Reporting Obligations

🡪 Articles 20, 21, 23: Governance, Cybersecurity risk-management measures, Reporting obligations

Reporting Obligations

Cybersecurity Obligations

Member States can add extra local rules on top of NIS 2 through national legislative transposition

01

08

02

07

03

06

04

05

02. Importance of Training

According to Article 20, top management must complete and approve regular cybersecurity training covering risks and security practices.

01. Responsibilities of Senior Management

According to Article 20, senior management must approve and oversee cybersecurity measures and can be held liable if they are not properly implemented.

0.4 Cybersecurity Measures

According to Article 21, companies must apply technical, operational, and organizational measures to manage risks and reduce impacts.

03. Risk-Based Approach to Cybersecurity

According to Article 21, cybersecurity measures must match the level of risk, considering factors such as expousure, company size, incident likelihood and severity and economic impact.

07. Using Certified IT Products and Services

The NIS 2 directive does not require certification but allows authorities to demand the use of certified IT products and services, which may become mandatory in the future.

08. Fines

According to Article 34, non-compliance may lead to fines up to €10 million or 2% of turnover for essential entities, and €7 million or 1.4% for important ones.

0.5 Supply Chain Security

According to Article 21, companies must manage supply chain risks by addressing supplier vulnerabilities, ensuring product quality, and securing development processes.

06. Reporting of Significant Incidents

According to Article 23, companies must report significant incidents to CSIRTs through early warnings, incident notifications, and follow-up reports. A final report is due within one month, plus updates if needed.

Most Important Cybersecurity & Reporting Requirements in NIS 2

8 of 29

06. Reporting of Significant Incidents

🡪 NIS 2 Chapter IV, Article 23 – Reporting obligations

(6) ‘incident’ means an event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems;

(a) it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned;

(b) it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

To report only ‘significant’ incidents to the CSIRT or competent authority and to affected recipients through:

EARLY WARNING

Is it a suspected malicious act with potential cross-border impacts?

OFFICIAL INCIDENT NOTIFICATION

Assessment of the incident, severity and impact, plus indicators of compromise.

INTERMEDIATE STATUS REPORT

At the resquest of CSIRT or relevant competent authority.

FINAL REPORT

Or if incident ongoing at time of final report a progress report and final report 1 month after end.

9 of 29

Once you implement all cybersecurity measures required by NIS2, you will significantly lower the chances of an incident, especially for significant incidents.

Hope for the best; prepare for the worst.

Once you implement all cybersecurity measures required by NIS 2, you will significantly lower the chances of an incident, especially for significant incidents.

10 of 29

If your institution is asked to comply with NIS 2, where do you start?

11 of 29

I don’t like the sound of all that…

Am I in Scope of the Directive?

12 of 29

13 of 29

NIS 2 Transposition Tracker

Last update: 15 October 2025

November 2025 – NIS 2 not yet in national law (NCSB still legislative process); EU infringement procedure ongoing; NCSC provide draft guidance + FAQs; NIS 1 still apply until NCSB pass

14 of 29

The Irish Approach: NCSC RMM & CyFun*

Draft law

National Cyber Security Act 2025?

Entities in scope should prepare by ensuring they have appropriate governance controls & readiness measures in place.

Source: NCSC: NIS2, DECC

  • The Draft RMM represent the minimum baseline of compliance and the ‘what’ organisations need to do.
  • There are 16 Risk Management Measures covering NIS 2 Articles, which is broken up into:
    • ‘Foundational Actions’: the minimum required to meet the legislative NIS 2 obligations
    • ‘Supporting Actions’: further controls that may be required, depending on specific risks

Organisations can use various frameworks, like ISO 27001, COBIT, NIST or their own Information Security Management System to meet these requirements.

15 of 29

Certification or self-assessment under CyFun is optional

“CyFun is one recognised way to organise and evidence your controls, not a statutory presumption of compliance”

The Role of CyFun in Ireland’s Compliance Framework:

“Perform a Risk Assessment” to Select your Assurance Level (CyFun Selection)

Complete your Self-Assessment, and Implement Corrective Actions/ Measures

Submit your responses to an authorised CAB for a Conformity Assessment

Request your label on the national website/ portal of

your country

*The Cybersecurity Fundamentals Framework

16 of 29

NIS 2 in Ireland - Key Takeaways

CyFun® for NIS 2 in

Ireland

CyFun® for NIS 2 in

Belgium

Ireland

  • Ireland continues the NIS 2 transposition, which is overdue as of 17 October 2024
  • NIS 1 remains in full effect and covers the most critical operators within the State
  • NCSC Ireland will be the National Competent Authority (NCA) Coordinator
  • NCSC published the Draft Risk Management Measures (RMM) in June ’25
  • Ireland has joined the CyFun® as a co-owner (announced in June ‘25)
  • NCSC will develop specific resources/ guides for CyFun® in Ireland
  • In Ireland, certification through CyFun® will be optional
  • A National Certification System will take 18-24 months
  • There is no Conformity Assessment Bodies (CAB)
  • Entities are encouraged to use CyFun® internally

Belgium

  • CyFun® is originally developed by Centre for Cybersecurity Belgium (CCB)
  • CyFun 2025® has been launched covering the new version of NIST CSF (2.0)
  • In Belgium, Presumpsion of Conformity to NIS 2 can be obtained through:
      • CyFun verification (assurance levels BASIC and IMPORTANT)
      • CyFun certification (assurance level ESSENTIAL) or
      • ISO/IEC 27001 certification

17 of 29

18 of 29

15 Implementation Steps for NIS 2 Cyber Risk Measures

01. Obtain Senior Management Support

02. Set up Project Management

03. Perform Initial Training

04. Write a Top-Level Policy on Information System Security

05. Define the Risk Management Methodology

06. Perform Risk Assessment and Treatment

07. Write and Approve the Risk Treatment Plan

08. Implement Cybersecurity Measures

09. Set up Supply Chain Security

10. Set up the Assessment of Cybersecurity Effectiveness

11. Set up Incident Reporting

12. Set up Continual Cybersecurity Training

13. Conduct Periodic Internal Audits

14. Conduct Periodic Management Review

15. Execute Corrective Actions

“All these best practices are applicable for both essential and important entities”

19 of 29

15 Implementation Steps for NIS 2 Cyber Risk Measures

01. Obtain Senior Management Support

02. Set up Project Management

03. Perform Initial Training

04. Write a Top-Level Policy on Information System Security

05. Define the Risk Management Methodology

06. Perform Risk Assessment and Treatment

07. Write and Approve the Risk Treatment Plan

08. Implement Cybersecurity Measures

09. Set up Supply Chain Security

10. Set up the Assessment of Cybersecurity Effectiveness

11. Set up Incident Reporting

12. Set up Continual Cybersecurity Training

13. Conduct Periodic Internal Audits

14. Conduct Periodic Management Review

15. Execute Corrective Actions

12 of 15 steps can be implemented using ISO 27001.

20 of 29

Processes

Output

Stakeholders’ Expectations and Wishes

Contracts

Goals, Mission, Vision and Values of the Organisation

Managed Information Security According to Objectives

Input

Plan

Do

Check

Act

Managed Information Security According to Objectives

Confidentiality

Integrity

Availability

ISO Information Security Management System s)

21 of 29

Processes

Output

Stakeholders’ Expectations and Wishes

Contracts

Goals, Mission, Vision and Values of the Organisation

Managed Information Security According to Objectives

Input

Plan

Do

Check

Act

Managed Information Security According to Objectives

Confidentiality

Integrity

Availability

ACTIVITIES THAT ARE CONTINUOUSLY ASSESSED AND IMPROVED

Controls

ISO Information Security Management System s)

22 of 29

Mapping ISO 27001 with NIS 2 Relevant Articles

Article 20

Management Commitment

Article 21

Cybersecurity Measures

Article 23

Incident Reporting

Completely map ISO 27001 Clauses/ Controls

One exception about Crisis Management

Since NIS 2 Article 23 “Reporting obligations” mandates very specific reporting requirements, the fact is that they cannot be addressed using ISO 27001.

🡪 Relevant Articles for companies that need to become compliant

Out of 26 cybersecurity requirements specified by NIS 2, ISO 27001 can address 25 of them; only Crisis Management is not really covered by the standard.

23 of 29

Request the complete version from us: ictsecurityservices@heanet.ie

24 of 29

Request the complete version from us: ictsecurityservices@heanet.ie

25 of 29

Request the complete version from us: ictsecurityservices@heanet.ie

Cybersecurity Risk Management Policy

Cybersecurity Governance and Oversight Policy

Security Awareness and Training Policy

Information Security Policy

Incident Management Policy

Business Continuity Policy

Backup Policy

Supplier Risk Management Policy

Change Management Policy

Secure Development Lifecycle (SDLC) Policy

Cyber Hygiene Guidelines

Cryptography Policy

NDAs and Confidentiality Agreements

Access Control Policy

Asset Management Policy

Authentication Policy

Information Transfer Policy

Communication Security Policy

Policy Review and Development (ictsecurityservices@heanet.ie)

26 of 29

If your company is compliant with ISO 27001, then the best thing is really to do a gap analysis and see what documents you are missing. You must also slightly adapt these existing documents so that they have references to NIS 2. And basically, this would be it.

If you are not compliant with ISO 27001, keep in mind that this standard is not a legal requirement of NIS 2. However, adopting ISO 27001 can simplify and accelerate compliance, since many controls align directly with NIS 2. It also brings extra benefits like stronger security, better governance and more trust.

“To be or not to be… ISO Certified”

27 of 29

Key Benefits of ISO/IEC 27001

1. Demonstrates external validation of your security practices; building credibility and trust

2. Aligns all departments under a single framework, ensuring shared responsibility.

3. Provides a structured way to identify and address the most significant security risks.

4. Turns policies into action; closing gaps and enabling proactive risk management.

5. Demonstrates governance, reducing organisational risk and insurance costs.

5 Reasons IT Managers Say “Yes” to ISO 27001

1. Accountability & Trust

2. One Security Standard

3. Clear IT Security Risk Focus

4. Stronger Policies and Actions

5. Lower Cyber Insurance Premiums

Confidentiality Assurance

Secure data Exchange

Regulatory Compliance

Data Protection

Competitive Advantage

Enhanced Trust

Consistent Delivery

Risk Reduction

Security Culture

Organisational Protection

Strong Internal Processes

Continual Improvement

Global Compliance

Lower Costs

Vulnerability Detection

28 of 29

Build Security. Inspire Trust – Together for the Future

🡪 Supporting education and research through practical security and compliance services.

NIS 2 Readiness Self-Assessment

🡪 Scan to access our excusive NIS 2 Self Assessment tool

Get a high-level view of your institution’s compliance NIS 2 Directive through a quick self-assessment form.

Security & Risk Assessment

🡪 Schedule your SRA with us (Security Consultancy Services)

Receive a clear snapshot of your security posture based on best practices, including ISO 27001 and NIS 2.

Policy Review & Development

🡪 Request the creation, review, or adoption of policies

Ensure your policies are aligned with your needs, NIS 2 requirements, and industry best practices.

Schedule with us: ictsecurityservices@heanet.ie

29 of 29

THANK YOU

Daniella Vendramini