DDactic for NIS2 Compliance
NIS2 Article 21 requires essential and important entities to implement availability measures, business continuity testing, and technical resilience controls. DDactic validates DDoS resilience and produces OPI-scored evidence artifacts for auditors.
What NIS2 Requires
The Network and Information Security Directive 2 (EU Directive 2022/2555) required transposition into national law by October 17, 2024. It applies to essential and important entities across 18 sectors and introduces proportionate but binding cybersecurity obligations, including availability resilience measures.
"Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services, and to prevent or minimise the impact of incidents on recipients of their services and on other services."
NIS2 Article 21(1)"The measures referred to in paragraph 1 shall include at least the following: ... (e) business continuity, such as backup management and disaster recovery, and crisis management; (f) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure."
NIS2 Article 21(2)(e) and (f)NIS2 does not prescribe specific test types in the way DORA does, but national competent authorities and the EU Agency for Cybersecurity (ENISA) guidance make clear that "availability incidents" means DDoS must be tested. The directive requires entities to demonstrate, not merely assert, that resilience controls work.
How DDactic Satisfies NIS2 Requirements
NIS2's availability and resilience requirements map directly to what DDactic tests. The OPI Validated score serves as a quantified, repeatable measure of compliance with Article 21.
| NIS2 Requirement | Article | DDactic Coverage |
|---|---|---|
| Manage risks to availability of network and information systems | Art. 21(1) | DDactic identifies attack surface gaps attackers exploit: unprotected origin IPs, rate-limit bypass paths, WAF coverage holes, and protocol-layer vulnerabilities |
| Business continuity testing | Art. 21(2)(e) | Active DDoS simulation validates whether services remain available under L3/L4/L7 attack load; OPI Operational Resilience component measures availability degradation and latency under sustained attack |
| Disaster recovery and crisis management | Art. 21(2)(e) | Post-simulation hardening steps serve as the crisis response playbook: vendor-specific configurations to activate when an attack is detected |
| Vulnerability handling and disclosure | Art. 21(2)(f) | DDactic discovers and documents DDoS-relevant vulnerabilities: origin IP exposure, missing rate limiting, WAF rule gaps, QUIC/HTTP2 attack vectors |
| Network and information systems security | Art. 21(2)(f) | Passive recon covers CDN detection, WAF vendor fingerprinting (25+ vendors), TLS configuration, open port enumeration, and subdomain mapping |
| Proportionate technical measures | Art. 21(1) | OPI Passive tier (free) satisfies basic gap identification for smaller entities; OPI Validated satisfies full active testing requirements for essential entities |
| Incident impact minimisation | Art. 21(1) | Identifies which attack paths would be most effective before an actual incident; allows teams to close gaps proactively rather than responding reactively |
Who Must Comply with NIS2
NIS2 applies to entities in 18 sectors. "Essential" entities face stricter ex-ante supervision; "important" entities face lighter ex-post supervision. Both must comply with Article 21.
Annex I - Essential Entities
- Energy (electricity, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking and financial market infrastructure
- Health (hospitals, labs, pharma R&D)
- Drinking water and wastewater
- Digital infrastructure (IXPs, DNS, TLD, cloud, CDN)
- ICT service management (MSPs, MSSPs)
- Public administration (central government)
- Space
Annex II - Important Entities
- Postal and courier services
- Waste management
- Chemical manufacturing and distribution
- Food production and distribution
- Manufacturing (medical, computers, vehicles)
- Digital providers (search, social, marketplaces)
- Research organisations
Size thresholds apply: entities with 50+ employees or EUR 10M+ annual turnover generally fall in scope. Member states may extend NIS2 to smaller entities in critical sectors.
Evidence DDactic Produces for NIS2
NIS2 Article 23 requires incident reporting, and competent authorities expect entities to demonstrate they had tested resilience before an incident occurred. DDactic produces the artifacts that support this.
- 📋Attack Surface ReportFull inventory of discovered subdomains, origin IPs, CDN coverage, WAF presence, and identified vulnerabilities before testing
- 📄OPI Validated AssessmentScored 0-100 across 6 components with methodology, test scope, and results per attack vector - timestamped and referenceable
- 🛠Hardening RecommendationsVendor-specific configuration steps for Cloudflare, Akamai, Imperva, AWS Shield - the remediation action plan
- 📅Before/After DeltaRerun after implementing hardening steps to document improvement - the continuous compliance record NIS2 supervisors expect
DDoS Is Specifically an NIS2 Risk
Availability Is Explicitly Covered
NIS2 defines "incident" as any event that compromises availability. DDoS attacks are the primary availability threat for most essential entities. A resilience programme without DDoS testing is incomplete by definition.
ENISA Threat Landscape
ENISA's annual threat landscape consistently lists DDoS as a top threat to EU essential services. Competent authorities reference this when assessing whether entities' measures are "appropriate and proportionate."
CDN Bypass Is the Hidden Risk
Most NIS2 entities assume their CDN absorbs DDoS attacks. DDactic finds the origin IPs that are exposed behind those CDNs - the bypass path that makes CDN protection irrelevant. This gap is not visible without active discovery.
Other compliance frameworks: DORA · PCI DSS 4.0 · ISO 27001 · SOC 2 · All standards