ISMS Copilot
NIS 2 Implementing Regulation

NIS 2 Implementing Regulation Copilot

Navigate the technical and methodological requirements of Implementing Regulation (EU) 2024/2690 with confidence

What the NIS 2 Implementing Regulation Copilot Can Do

Check whether your entity type is in scope under Art. 1 and how qualified Annex requirements apply to you

Identify whether an incident meets the significance criteria in Arts. 3–14

Map your existing controls to the 13 Annex requirement areas

Interpret the 'where appropriate', 'where applicable' and 'to the extent feasible' qualifiers covered by Art. 2(2)

Check recurring incidents against all three Art. 4 conditions: at least twice in six months, same apparent root cause, and together meeting Art. 3(1)(a)

Draft documented reasoning when a qualified Annex requirement is not applied

About NIS 2 Implementing Regulation Copilot

Implementing Regulation (EU) 2024/2690 sets binding technical and methodological cybersecurity requirements for specific entity types under NIS 2, and defines when an incident is considered significant. ISMS Copilot helps you work through the Annex requirements and significant-incident criteria relevant to your organisation.

Cross-framework mappings

Working across NIS 2 Implementing Regulation and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

What is Implementing Regulation (EU) 2024/2690?

It is a European Commission implementing regulation that lays down binding technical and methodological cybersecurity risk-management requirements for specific entity types (including DNS service providers, cloud computing providers, managed service providers and trust service providers) and specifies the cases in which an incident is considered significant for the purposes of NIS 2 Art. 23(3).

How does the NIS 2 Implementing Regulation Copilot help?

The Copilot helps you interpret the 13 Annex requirement areas (covering topics from incident handling and access control to supply chain security and cryptography), understand the entity-specific significant-incident thresholds in Arts. 5–14, and identify where your organisation needs to document its reasoning under Art. 2(2).

Does the regulation apply to all NIS 2 entities?

No. Art. 1 limits direct applicability to a defined set of 'relevant entities', including DNS service providers, TLD name registries, cloud computing, data centre and content delivery network providers, managed and managed security service providers, online marketplaces, online search engines, social networking services platforms, and trust service providers; for other NIS 2 entities it may serve as a reference model alongside NIS 2 Art. 21 and applicable national law.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.