Article 21 measures. Article 23 timelines. One workspace.
STORM GRC gives CISOs, Heads of Compliance and DPOs at essential and important entities a single workspace for the cybersecurity risk-management measures, incident reporting workflow, supply-chain controls and management-body governance evidence NIS 2 requires.
NIS 2 raises the bar for cyber governance: faster reporting, named accountability, and more organisations under supervision.
The Directive applies across the EU since the 17 October 2024 transposition deadline. Most operators discover they’re in scope, that personal accountability is real, and that incident timelines start in hours — not weeks.
Scope expansion
NIS 2 covers far more sectors than NIS 1 and pulls in medium-sized entities, not just large ones. Many organisations are now Essential or Important entities without realising it.
Article 21 measures
Ten categories of cybersecurity risk-management measures — from risk analysis to MFA, supply-chain controls and cyber hygiene — all evidenced and maintained on a continuous basis.
Article 23 timelines
Early warning to the CSIRT within 24 hours. Incident notification within 72 hours. Final report within one month. The reporting timeline begins as soon as the organisation becomes aware of a potentially significant incident.
Management liability
The management body must approve cybersecurity measures, oversee implementation and is personally liable for non-compliance. Cybersecurity training for the board is mandatory.
Essential or important — same obligations, different supervision.
Both categories carry the same Article 21 and Article 23 obligations. What differs is how the competent authority supervises you, and the maximum administrative fine.
Essential entities
Sectors of high criticality — energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space.
- Proactive supervisioncompetent authority can inspect at any time
- Higher finesup to €10M or 2% of global turnover
- On-site auditssecurity scans and document requests
- Mandatory cybersecurity training for the management body
- Same Article 21 measures as Important entities
Important entities
Other critical sectors — postal & courier, waste management, chemicals, food, manufacturing, digital providers, research organisations. NIS 2’s “important” category is still meaningful: you’re regulated, just supervised differently.
- Ex-post supervision — triggered after incidents or evidence of non-compliance
- Maximum fines up to €7M or 1.4% of global turnover
- Same Article 21 measures, same Article 23 reporting
- Same supply-chain obligations for downstream suppliers
- Same management-body accountability rules
Ten cybersecurity risk-management measures. All mapped.
STORM’s NIS 2 configuration is pre-mapped to the ten Article 21 categories and the supporting governance and reporting requirements. STORM translates generic ISO 27001 controls into NIS 2 language so you don’t have to.
Three deadlines. One workflow.
From the moment your team becomes aware of a significant incident, the clock starts. STORM builds Article 23 into the incident module — so the early warning, the notification and the final report are produced from the same record without re-keying.
Notify the CSIRT
An early warning to the CSIRT or competent authority indicating whether the incident is suspected to be caused by unlawful or malicious acts, and whether it could have a cross-border impact.
Full incident notification
An incident notification updating the early warning with an initial assessment of severity and impact, with indicators of compromise where available.
Final report
A detailed description of the incident, its severity and impact, the type of threat or root cause, applied and ongoing mitigation measures, and (if applicable) the cross-border impact.
What your CISO actually opens on Monday.
The same STORM platform, configured for NIS 2 — Article 21 measures cross-mapped to ISO 27001 you already have, Article 23 reporting wired into your incident module, supplier register linked to BitSight and FortiRecon.
Scope & entity check
A short configurator walks you through Annex I and Annex II to confirm whether you are Essential, Important, or out of scope — and which competent authority applies.
Article 21 gap analysis
Each of the ten Article 21 categories scored on the 5-level maturity scale, with drill-down to controls, evidence and remediation tasks assigned with deadlines.
24h / 72h / 1m timeline
Article 23 reporting wired into the incident workflow — the early warning, the notification and the final report all generated from the same record, with role-based approval and CSIRT-ready export.
Audit-ready NIS 2 posture in 90 days.
A typical mid-size operator (essential or important entity, 200–1500 staff) hits NIS 2 audit-ready posture within one quarter. Larger operators with multiple subsidiaries plan a longer programme — but the first 30 days look the same.
Scope & baseline
- Entity classification confirmed (Essential / Important)
- Competent authority and CSIRT contact established
- Article 21 gap analysis complete
- Existing ISO 27001 controls mapped to Article 21
Measures & supply chain
- Article 21 risk-management measures evidenced
- Supplier register live with BitSight ratings
- Incident response plan aligned to Article 23
- Management body cybersecurity training delivered
Audit-ready
- Internal audit completed and reported
- Management body approval recorded
- 24h / 72h / 1m reporting workflow tested
- Competent authority documentation pack ready
From scattered controls to a management-ready NIS 2 evidence pack.
STORM gives essential and important entities one place to map Article 21 measures, supplier controls, incident-reporting workflows and management-body accountability. The result is a structured view of what is covered, what needs remediation and what can be shown to auditors or competent authorities.
Operation snapshot
Questions CISOs and Heads of Compliance actually ask.
If your question isn’t here, the answer is a 30-minute call — usually faster than email.
Are we essential, important, or out of scope?
We already have ISO 27001. Does that cover NIS 2?
How does the 24-hour early warning actually work?
How do we handle suppliers under Article 21.2.d?
Does the management body really need cybersecurity training?
Can we deploy on-premise?
How is STORM priced for a NIS 2 programme?
See STORM GRC supporting your NIS 2 obligations — in 30 minutes.
A focused demo with someone who knows the Directive. We walk through how STORM GRC supports Article 21 measures, Article 23 reporting, supply-chain controls and management-body governance evidence — and show you exactly how it fits your organisation, with no commitment required.
EU-based team. No sales pressure.


