What Directive (EU) 2022/2555 of the European Parliament and of the Council of 16 November 2022 on measures for a high common level of cybersecurity across the Union, amending and repealing Directive (EU) 2016/1148 (NIS2 Directive) requires
The NIS2 Directive imposes mandatory risk management and incident reporting obligations on Cloud Service Providers (CSPs) classified as Essential or Important Entities under Articles 21 and 23. These entities must implement 10 minimum security measures (Article 21), report significant incidents within 24 hours (early warning) and 72 hours (formal notification) per Article 24, ensure supply chain security (Article 22), and cooperate with national authorities and ENISA.
Pillar: Cloud & SaaS · Authority: European Parliament and Council of the European Union · Version: 1.0.1 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555
SHA-256 integrity: 2f67baa7847a934694db76142f4bad7c492c585d8eebcfa8640478decd36fcac
Primary Citations — 5 traced to source
- NIS2 Directive, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, Article 21, 2022
- NIS2 Directive, https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32022L2555, Article 22, 2022
+ 3 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/eu-nis2-cloud-essential-services-2022-2555.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/eu-nis2-cloud-essential-services-2022-2555.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/eu-nis2-cloud-essential-services-2022-2555
- Back to registry: Browse all 10,085 compliance nodes