EU Directive 2022/2555

DDactic for NIS2 Compliance

NIS2 Article 21 requires essential and important entities to implement availability measures, business continuity testing, and technical resilience controls. DDactic validates DDoS resilience and produces OPI-scored evidence artifacts for auditors.

What NIS2 Requires

The Network and Information Security Directive 2 (EU Directive 2022/2555) required transposition into national law by October 17, 2024. It applies to essential and important entities across 18 sectors and introduces proportionate but binding cybersecurity obligations, including availability resilience measures.

"Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services."

NIS2 Article 21(1)

"The measures referred to in paragraph 1 shall include at least the following: ... (e) business continuity, such as backup management and disaster recovery, and crisis management; (f) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure."

NIS2 Article 21(2)(e) and (f)

NIS2 does not prescribe specific test types in the way DORA does, but national competent authorities and the EU Agency for Cybersecurity (ENISA) guidance make clear that "availability incidents" means DDoS must be tested. The directive requires entities to demonstrate, not merely assert, that resilience controls work.

How DDactic Satisfies NIS2 Requirements

NIS2's availability and resilience requirements map directly to what DDactic tests. The OPI Validated score serves as a quantified, repeatable measure of compliance with Article 21.

NIS2 Requirement Article DDactic Coverage
Manage risks to availability of network and information systems Art. 21(1) DDactic identifies attack surface gaps attackers exploit: unprotected origin IPs, rate-limit bypass paths, WAF coverage holes, and protocol-layer vulnerabilities
Business continuity testing Art. 21(2)(e) Active DDoS simulation validates whether services remain available under L3/L4/L7 attack load; OPI Operational Resilience component measures availability degradation and latency under sustained attack
Disaster recovery and crisis management Art. 21(2)(e) Post-simulation hardening steps serve as the crisis response playbook: vendor-specific configurations to activate when an attack is detected
Vulnerability handling and disclosure Art. 21(2)(f) DDactic discovers and documents DDoS-relevant vulnerabilities: origin IP exposure, missing rate limiting, WAF rule gaps, QUIC/HTTP2 attack vectors
Network and information systems security Art. 21(2)(f) Passive recon covers CDN detection, WAF vendor fingerprinting (25+ vendors), TLS configuration, open port enumeration, and subdomain mapping
Proportionate technical measures Art. 21(1) OPI Passive tier (free) satisfies basic gap identification for smaller entities; OPI Validated satisfies full active testing requirements for essential entities
Incident impact minimisation Art. 21(1) Identifies which attack paths would be most effective before an actual incident; allows teams to close gaps proactively rather than responding reactively

Who Must Comply with NIS2

NIS2 applies to entities in 18 sectors. "Essential" entities face stricter ex-ante supervision; "important" entities face lighter ex-post supervision. Both must comply with Article 21.

Annex I - Essential Entities

  • Energy (electricity, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructure
  • Health (hospitals, labs, pharma R&D)
  • Drinking water and wastewater
  • Digital infrastructure (IXPs, DNS, TLD, cloud, CDN)
  • ICT service management (MSPs, MSSPs)
  • Public administration (central government)
  • Space

Annex II - Important Entities

  • Postal and courier services
  • Waste management
  • Chemical manufacturing and distribution
  • Food production and distribution
  • Manufacturing (medical, computers, vehicles)
  • Digital providers (search, social, marketplaces)
  • Research organisations

Size thresholds apply: entities with 50+ employees or EUR 10M+ annual turnover generally fall in scope. Member states may extend NIS2 to smaller entities in critical sectors.

Evidence DDactic Produces for NIS2

NIS2 Article 23 requires incident reporting, and competent authorities expect entities to demonstrate they had tested resilience before an incident occurred. DDactic produces the artifacts that support this.

  • 📋Attack Surface ReportFull inventory of discovered subdomains, origin IPs, CDN coverage, WAF presence, and identified vulnerabilities before testing
  • 📄OPI Validated AssessmentScored 0-100 across 6 components with methodology, test scope, and results per attack vector - timestamped and referenceable
  • 🛠Hardening RecommendationsVendor-specific configuration steps for Cloudflare, Akamai, Imperva, AWS Shield - the remediation action plan
  • 📅Before/After DeltaRerun after implementing hardening steps to document improvement - the continuous compliance record NIS2 supervisors expect

DDoS Is Specifically an NIS2 Risk

Availability Is Explicitly Covered

NIS2 defines "incident" as any event that compromises availability. DDoS attacks are the primary availability threat for most essential entities. A resilience programme without DDoS testing is incomplete by definition.

ENISA Threat Landscape

ENISA's annual threat landscape consistently lists DDoS as a top threat to EU essential services. Competent authorities reference this when assessing whether entities' measures are "appropriate and proportionate."

CDN Bypass Is the Hidden Risk

Most NIS2 entities assume their CDN absorbs DDoS attacks. DDactic finds the origin IPs that are exposed behind those CDNs - the bypass path that makes CDN protection irrelevant. This gap is not visible without active discovery.

Get NIS2-Ready Evidence in 48 Hours

Start with a free passive scan of your attack surface. Upgrade to OPI Validated for a full report suitable for NIS2 Article 21 compliance documentation.

Run Free Scan

Other compliance frameworks: DORA · PCI DSS 4.0 · ISO 27001 · SOC 2 · All standards