⚡ Quick Summary
Published by the European Union Agency for Cybersecurity (ENISA), this technical implementation guidance supports Commission Implementing Regulation (EU) 2024/2690, which sets technical and methodological requirements for cybersecurity risk-management measures under the NIS2 Directive. It addresses relevant entities in specified digital-infrastructure and ICT-service-management subsectors, including DNS providers and registries, cloud, data-centre and content-delivery providers, managed service and security service providers, certain online platforms, and trust service providers.
The guidance covers 13 requirement areas, from overarching network and information-system security policy and risk management through incident handling, continuity, supply chains, secure acquisition and development, assessment of measures, training, cryptography, personnel, access, assets, and physical security. For each requirement, it presents indicative, actionable guidance, examples of evidence, and, in some cases, additional tips. It also maps requirements to ISO/IEC 27001:2022, ISO/IEC 27002:2022, NIST Cybersecurity Framework 2.0, ETSI EN 319 401 V3.1.1, CEN/TS 18026:2024 and national frameworks. The document stresses that these elements are non-exhaustive and do not themselves establish compliance or conformity.
🧩 What’s Covered
The supplied extract presents the following major parts, in document order:
- Regulatory context and structure: Explains the relationship to Article 21(2) of the NIS2 Directive and the Regulation’s Annex. It identifies the in-scope entity types, defines the guidance’s advisory purpose, and explains the three recurring components: guidance, examples of evidence and tips. It also describes mappings to selected international, European and national frameworks.
- Security policy and accountability: Sets out the required content of a high-level network and information-system security policy, including security objectives, resourcing, documentation, management-body approval, monitoring indicators and topic-specific policies. It addresses assigned security roles, direct reporting to management, competence, segregation of conflicting duties, and periodic review.
- Risk management and assurance: Describes a documented risk-management framework, an all-hazards assessment process, risk appetite, tolerance and criteria, treatment plans, residual-risk acceptance and annual review. It then covers compliance monitoring, reporting to management bodies, and independent reviews that must preserve reviewer impartiality and lead to corrective action or documented risk acceptance.
- Incident handling: Covers incident policy, monitoring and logging, event reporting, assessment and classification, containment, eradication, recovery and post-incident review. Examples include incident categorisation, communication plans, SIEM, EDR and XDR tools, log-retention safeguards, playbooks, testing, root-cause analysis and feedback into risk treatment.
- Business continuity and crisis management: Provides guidance on business continuity and disaster-recovery plans, business-impact analysis and recovery objectives including RTOs, RPOs, SDOs and maximum acceptable outage. It also addresses backups, redundancy, integrity checks, restoration testing, crisis escalation criteria, communications and use of information from CSIRTs or competent authorities.
- Supply chain security: Covers a policy for direct suppliers and service providers; selection criteria; security provisions in contracts and service-level agreements; lifecycle monitoring; and a current registry of suppliers, contact points and provided ICT products, services and processes. It includes detailed considerations for free and open-source software dependencies.
- Secure acquisition and early development lifecycle: The available text covers risk-based acquisition processes for critical ICT products and services, including lifecycle support, component information, secure configuration, validation and review. It begins the secure development lifecycle section, requiring rules spanning specification, design, development, implementation and testing.
💡 Why it matters?
The guidance translates Regulation requirements into operational governance, implementation and audit material. It helps affected entities organise policy ownership, risk acceptance, reporting lines, testing schedules and evidence collection rather than treating compliance as a purely technical exercise. The examples of evidence can assist national competent authorities in developing supervisory approaches, while entities can use them to structure documentation and demonstrate that controls exist.
It also makes connections between incident response, continuity planning, supplier oversight, asset management and risk treatment. Its standards mappings are intended to help entities integrate existing frameworks, reduce duplication and streamline audits, without treating the mapped standards as equivalent to the Regulation.
❓ What’s Missing
The document expressly does not determine whether an entity must hold all, some or alternative examples of evidence, nor does it determine whether measures or evidence are appropriate. It is advisory, not legally binding, and does not replace Member State frameworks, guidance or supervisory approaches. The mappings do not assess full coverage or equivalence between standards and frameworks; the mapping table itself is referenced as an Excel file on the ENISA website rather than reproduced in the supplied text. This review also cannot assess the detailed treatment of chapters after the opening of secure development, because the supplied extraction ends on PDF page 80 while the document continues to page 170.
👥 Best For
It is best suited to security and compliance leads at entities covered by the Regulation, as well as risk managers, internal auditors, incident-response teams, procurement staff and continuity planners. It is particularly useful for teams developing policies, risk-treatment records, supplier clauses, monitoring procedures and evidence packs for national supervisory engagement.
📄 Source Details
Technical Implementation Guidance: On Commission Implementing Regulation (EU) 2024/2690 of 17 October 2024 is an English-language ENISA publication dated June 2025, version 1.0. It names Konstantinos Moulinos and Marianthi Theocharidou as authors and gives the imprint “Luxembourg: Publications Office of the European Union, 2025.” Only the extracted text for PDF pages 1–80 of the 170-page file was available, through the opening of section 6.2.