Compliance/NIS2/Cybersecurity
NIS2 compliance for Cybersecurity
Cybersecurity is the regulated function. Essential + important entities must implement risk-management measures (Art. 21) including supply-chain security (Art. 21(2)(d)) + report incidents (Art. 23) within 24h / 72h / 1 month.
What applies
Articles + provisions of Directive (EU) 2022/2555 — Network and Information Security Directive 2 most directly engaged by Cybersecurity deployments:
- Art. 21
- Art. 23
What this looks like in Cybersecurity
Cybersecurity is the regulated function. Essential + important entities must implement risk-management measures (Art. 21) including supply-chain security (Art. 21(2)(d)) + report incidents (Art. 23) within 24h / 72h / 1 month.
Flagship exampleCustomer NIS2 audit: cybersecurity vendor provides per-tenant audit bundle covering the customer's deployment.
Where Promethean's evidence layer fits
The substrate emits specific evidence kinds that map to NIS2 obligations. Most directly relevant for Cybersecurity:
For the full sector view including LLM-feature catalogue, tier recommendation, and reviewer-gate examples, see the Cybersecurity sector page.
Adjacent cells
Same regulation, other sectors
Other regulations for Cybersecurity