Compliance Node Overview
Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 lays down rules for the application of NIS2 Directive (EU) 2022/2555 as regards technical and methodological requirements of cybersecurity risk-management measures and the cases in which an incident is considered significant. It applies to the relevant entities listed in NIS2 Annex II point 8: DNS service providers; TLD name registries; cloud computing service providers; data centre service providers; content delivery network (CDN) providers; managed service providers (MSPs); managed security service providers (MSSPs); online marketplaces; online search engines; social networking services platforms; and trust service providers. Article 1 sets scope; Article 2 incorporates the Annex's technical and methodological requirements implementing NIS2 Article 21(2)(a)-(j); Article 3 specifies significant-incident criteria including (a) direct financial loss exceeding EUR 500,000 or 5% of preceding-year turnover (whichever lower), (b) trade secret exfiltration, (c) death of a natural person, (d) considerable health damage, plus entity-type specific criteria in Articles 4-15. Article 16 sets entry into force on the twentieth day after publication in the OJEU. The Annex draws on ISO/IEC 27001, ISO/IEC 27002, ETSI EN 319401 and CEN/TS 18026:2024.
Pillar: Cybersecurity · Authority: EUR-Lex - Commission Implementing Regulation (EU) 2024/2690 (17 October 2024) · Version: 1.0.1 · Last updated:
Primary source: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R2690
SHA-256 integrity: 7b3401ff5a12a36bd9645cf8e1951a949e410f8f03059c793c3279176e22c394
Primary Citations — 20 traced to source
- Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024
- Article 1 - Subject matter and scope (eleven categories of relevant entities)
+ 18 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.