Directive 2022/2555: risk-management and incident duties have applied since 18 October 2024. The Commission's first review is due by 17 October 2027 — the 24-hour clock is already running.
A directive can require risk management. It cannot produce the inventory, the evidence or the incident trail on the day they are needed.
Directive (EU) 2022/2555 — NIS2 — sets a higher common level of cybersecurity across the Union. Member States were due to transpose it by 17 October 2024. National implementation remains uneven, but the obligations for essential and important entities are no longer a future project.
Covered organisations sit in critical and important sectors under Annexes I and II — energy, transport, banking, health, digital infrastructure, manufacturing, food and others — generally once they meet size thresholds, with some digital and trust services in scope regardless of size. Essential entities face more intensive supervision; important entities are still in scope for the same core duties.
The incident clock is the operating test
Management bodies must approve cybersecurity risk-management measures, oversee them, and can be held liable for infringements. Article 21 requires appropriate and proportionate technical, operational and organisational measures on an all-hazards basis: risk analysis, incident handling, business continuity, supply-chain security, vulnerability handling, cryptography, human-resource security and authentication among them.
Supply-chain security is explicit. Entities must take account of vulnerabilities in direct suppliers and service providers, and of the quality of those suppliers’ cybersecurity practices — including secure development. A control framework that stops at the organisation’s own perimeter is incomplete.
Significant incidents have a clock. An early warning is due within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month. Recipients of the service may also need to be informed. Those timelines only work if assets, contacts, evidence and decision rights already exist.
The risk is not only a fine. It is discovering, under a 24-hour clock, that nobody can say which systems matter, which supplier is in the path, which control is in place, or who is allowed to notify.
Where readiness breaks
- Inventory: which assets, services and controls are in scope, and which suppliers sit on the critical path.
- Evidence: policies, tests, exceptions and supplier assessments that can be shown to a supervisor — not documents that exist only as intent.
- Incident: who detects, who decides, who notifies the CSIRT or competent authority, and how the trail from early warning to final report is kept.
These are connected decisions. Treating risk management, vendor management and incident response as separate workstreams leaves the organisation to reconcile them when an incident, or an inspection, arrives.
What Ontzi builds
Ontzi turns the obligation into a supervisable operating model. We connect asset and control inventory to evidence collection, bring supplier risk into the same picture as internal measures, and give policies and incidents a path that can produce an audit package without a scramble.
The immediate output is the ability to manage and report. The durable value is a repeatable capability: the organisation knows what it runs, what it relies on, who owns each control and how to act when something breaks.
The directive is the duty. The operating model is what makes it defensible.
Primary text
This field note is general information, not legal advice. Whether an organisation is essential or important, and how national supervisors apply the rules, should be checked in the law applicable to each entity.