ISMS Copilot
NIS 2

NIS 2 Copilot

Specialist AI guidance for EU NIS2 Directive compliance

NIS 2 transposition laws are in force across most of the EU. Map your obligations and draft your risk measures now.

What the NIS 2 Copilot Can Do

NIS2 scope assessment and applicability determination

Cybersecurity risk management guidance

Incident reporting procedures and templates

Supply chain security assessment

Board-level accountability framework

Cross-mapping to ISO 27001 controls

About NIS 2 Copilot

NIS2 Copilot provides specialist AI guidance to align with the EU's NIS2 Directive requirements for cybersecurity risk management and incident reporting.

Cross-framework mappings

Working across NIS 2 and another standard? ISMS Mappings is a free public directory of control maps (ISO 27001, SOC 2, NIST, GDPR, and more). A Better ISMS tool, separate from the chat assistant.

Browse free mappings

Frequently Asked Questions

What is the NIS 2 Directive?

NIS 2 is the EU's updated directive on Network and Information Security, expanding cybersecurity requirements to more sectors and introducing stricter obligations.

Who needs to comply with NIS 2?

Essential and important entities across sectors like energy, transport, health, digital infrastructure, and public administration in the EU.

How does NIS 2 relate to ISO 27001?

ISO 27001 provides a strong foundation for NIS 2 compliance. The Copilot helps map controls between both frameworks.

Has my country transposed NIS 2 into national law yet?

It depends on the Member State: NIS 2 is a directive, so obligations bite through each country's own transposition law, and several states missed the 17 October 2024 deadline. Our free NIS 2 transposition tracker at /learn/nis-2-transposition-tracker shows the last-verified status for all 27 EU Member States with a dated source per country, and the free NIS 2 Applicability Checker at /resources/nis-2-applicability-checker tells you whether you are in scope at all.

Ready to do compliance work faster?

Built for speed, accuracy, and audit-ready output.