---
title: NIS2
description: Meet NIS2's 24-hour and 72-hour incident reporting deadlines with three years of forensic history, live risk visibility, and evidence for every Article 21 measure - on standard Microsoft 365 licenses.
icon: Scale
---

# NIS2 Readiness

NIS2 turns incident response into a race against statutory clocks: an **early warning within 24 hours** of becoming aware of a significant incident, an **incident notification with an initial assessment within 72 hours**, and a **final report within a month**. Most organizations cannot answer the underlying questions - _what happened, who was affected, is it still happening_ - in that window, because the evidence lives in 90-day logs and disconnected admin centers. 1Security's job is to make the deadline the easy part.

## What NIS2 Actually Requires

The directive (EU 2022/2555, transposed into national law since October 2024) applies to _essential_ and _important_ entities across 18 sectors, and it is not a checkbox exercise:

- **Article 21** mandates risk-management measures: incident handling, logging and detection, access control and asset management, supply-chain security, cyber hygiene, and - critically - _policies to assess the effectiveness_ of those measures.
- **Article 23** sets the reporting clock: 24-hour early warning (including whether malicious action is suspected), 72-hour notification with severity, impact, and indicators of compromise, and a one-month final report covering root cause and mitigation.
- **Management is personally accountable.** Boards must approve and oversee the measures, and can be held liable for violations - with fines up to €10M or 2% of worldwide turnover for essential entities (€7M / 1.4% for important ones).

## Beating the Reporting Clock

| Deadline                   | What the regulator needs                              | Where you get it                                                                                                                                                                                                                                                                                          |
| -------------------------- | ----------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **24 h** - early warning   | Is it real? Is it malicious? Is it cross-border?      | [Activity Logs](/en/docs/screens/activity-logs): the account's full timeline with every action attributed to actor, resource, app, device, and location. [Location Intelligence](/en/docs/location) separates a genuine foreign sign-in from Microsoft backend noise in one glance.                       |
| **72 h** - notification    | Severity, impact assessment, indicators of compromise | Blast radius on demand: everything the account touched, [every file it can still reach](/en/docs/screens/files), whether [sensitive or regulated data](/en/docs/screens/sensitive-info) was in scope, and which [device](/en/docs/screens/devices) - managed, personal, or shadow - carried the activity. |
| **1 month** - final report | Root cause, full chronology, mitigation applied       | Up to **three years of retained history** reconstructs the entire attack path - including entry points months old - and the remediation trail (revoked links, stripped permissions) documents your response.                                                                                              |

## Evidence for the Article 21 Measures

NIS2 doesn't just ask you to have controls - it asks you to _demonstrate they work_. That's the hard part, and it's where continuous visibility replaces the annual PDF:

- **Incident handling & detection** - [Trends](/en/docs/screens/trends) run 50+ prebuilt and unlimited custom detections over the permission graph: mass downloads, insider-risk patterns, sensitive data exposed to AI. Alerts arrive in minutes, not at the next audit.
- **Logging & forensic readiness** - three years of unified, searchable audit history on standard licenses, instead of a log-storage bill that punishes you for being prepared.
- **Access control policy** - the [permission graph](/en/docs/permission-graph) shows effective access (nested groups and inheritance resolved), so least-privilege is something you _measure_, and access reviews audit reality instead of intentions.
- **Asset management** - live inventories of [devices](/en/docs/screens/devices) (including shadow devices that never registered), [sites](/en/docs/screens/sites), and [connected apps](/en/docs/screens/apps) - the assets you can't protect are the ones you don't know about.
- **Supply-chain security** - every third-party app and [AI agent](/en/docs/screens/agents) with a foothold in your tenant, its publisher verification, its access channel, and who let it in.
- **Effectiveness assessment** - [sensitivity-label coverage](/en/docs/screens/sensitivity-labels) measured against actual [sensitive-data locations](/en/docs/sensitivity): the difference between "we have a data classification policy" and "here is its coverage, as a number, trending quarterly."

## The 72-Hour Drill

<Callout type="info">
  Run this as an exercise before you run it as an incident: pick a user account,
  and within one sitting produce (1) their complete 90-day activity timeline
  with devices and locations, (2) every file, site, and mailbox item they can
  currently reach, (3) how much of it carries regulated data, and (4) one
  revoked permission as remediation evidence. If you can do it in a drill, the
  72-hour notification stops being frightening.
</Callout>

## Scope, Honestly

1Security provides the forensic record, the live risk visibility, and the remediation trail that NIS2 obligations rest on. Whether a given incident is "significant," which national authority receives your report, and how your sector's transposition applies - those are calls for your compliance counsel. Bring them the evidence; 1Security makes sure you have it.
