Compliance/NIS2/Cybersecurity

NIS2 compliance for Cybersecurity

Cybersecurity is the regulated function. Essential + important entities must implement risk-management measures (Art. 21) including supply-chain security (Art. 21(2)(d)) + report incidents (Art. 23) within 24h / 72h / 1 month.

Updated 15 May 2026·Primary application·Primary source ↗

What applies

Articles + provisions of Directive (EU) 2022/2555 — Network and Information Security Directive 2 most directly engaged by Cybersecurity deployments:

  • Art. 21
  • Art. 23

What this looks like in Cybersecurity

Cybersecurity is the regulated function. Essential + important entities must implement risk-management measures (Art. 21) including supply-chain security (Art. 21(2)(d)) + report incidents (Art. 23) within 24h / 72h / 1 month.

Flagship exampleCustomer NIS2 audit: cybersecurity vendor provides per-tenant audit bundle covering the customer's deployment.

Where Promethean's evidence layer fits

The substrate emits specific evidence kinds that map to NIS2 obligations. Most directly relevant for Cybersecurity:

For the full sector view including LLM-feature catalogue, tier recommendation, and reviewer-gate examples, see the Cybersecurity sector page.

Adjacent cells

Other regulations for Cybersecurity