NIS2 Directive → NIST CSF 2.0
Many multinational operators run their control library on NIST CSF while facing NIS2 obligations in Europe. This crosswalk maps NIS2 Article 21 to CSF 2.0 functions so the same evidence satisfies both.
Scope: Operator-level. Excludes device-side controls.
| Category | NIS2 Directive | NIST CSF 2.0 | Notes |
|---|---|---|---|
| Govern | NIS2 Art.20 (management liability) | CSF GV.RR / GV.OC | Board-level responsibility explicit in both. |
| Identify | NIS2 Art.21(2)(a) | CSF ID.RA | Risk assessment scope must include signalling exposure. |
| Protect | NIS2 Art.21(2)(e,h,j) | CSF PR.AA / PR.DS / PR.PS | Access, data-in-transit, platform security. |
| Detect | NIS2 Art.21(2)(b) | CSF DE.CM | Continuous monitoring — signalling firewall telemetry. |
| Respond | NIS2 Art.23 (24h early warning) | CSF RS.MA | CSF RS.MA-04 covers regulator notification. |
| Recover | NIS2 Art.21(2)(c) | CSF RC.RP | Business continuity and recovery planning. |
Gaps
- NIS2 explicitly requires supply-chain security clauses in contracts — CSF references but does not mandate.
- CSF Tiers do not map directly to NIS2 essential/important entity classification.
Key takeaways
- CSF 2.0 Govern function aligns cleanly with NIS2 management-liability clauses.
- One well-scoped CSF profile can satisfy NIS2 evidence needs for a multinational operator.
- National transpositions (Germany, France) add local nuances not in either framework.