NIS2 Compliance

Meet the NIS2 requirements
for certificate management

NIS2 Article 21 requires technical security measures — including control over TLS certificates and PKI. CertControl gives your organisation the register, monitoring, and reporting that supervisory authorities expect.

14-day free trial  ·  Dedicated instance  ·  EU hosted

NIS2 Article 21 — requirement coverage
Asset inventory
Automatically maintained register of all certificates
Risk assessment
TLS risk score and expiry risk per endpoint
Incident response
Alerts and audit log for 24/72h reporting
Supply chain security
Monitoring of supplier certificates
Audit documentation
Executive reports ready for supervisory authorities
What NIS2 requires

Article 21 and TLS certificates

TLS certificates sit at the centre of three of NIS2's eight Article 21 requirement areas. Here is exactly what each one demands — and where CertControl covers it.

Article 21(2)(a)

Risk analysis and information system security

Organisations must document risks associated with their information systems — including the risk of certificate expiry, weak TLS configuration, and compromised keys. A certificate asset register is the foundation for this analysis.

Article 21(2)(h)

Cryptography and encryption policies

Organisations must have documented policies for the use of cryptography and encryption. For TLS this means: strong cipher suites, valid certificates, correct key sizes, and SHA-256 or stronger signatures — all verifiable and traceable.

Article 21(2)(d)

Supply chain security

The security of suppliers' and service providers' systems is part of the organisation's overall security posture. Monitoring key supplier TLS certificates provides early warning of third-party risks before they become incidents.

Incident reporting

NIS2 incident reporting: 24 hours. 72 hours. One month.

NIS2 introduces strict deadlines for reporting significant incidents to national authorities. A certificate expiry causing service unavailability can qualify as a significant incident — and starts the clock.

24h
Early warning
Notification to authority that an incident has occurred
72h
Incident notification
Update with initial assessment of severity and scope
1 mo
Final report
Complete analysis of incident, root cause, impact, and remediation

Without a complete certificate register, it can take hours just to establish whether a certificate expiry is the root cause of an outage — time you do not have under NIS2's reporting requirements. CertControl maintains a continuous audit log of all certificate events, changes, and alerts.

How CertControl covers NIS2

Six features that cover the Article 21 requirements

📋

Complete asset register

Automatically updated register of all certificates across monitored endpoints — internal and external. Expiry dates, ownership, environment, and associated systems documented and searchable.

🔍

TLS risk assessment

Automatic scanning of TLS configuration for weak cipher suites, protocol versions, and certificate issues. Risk score per endpoint with prioritised remediation recommendations.

🔔

Proactive alerting

Configurable alerts up to 90 days before expiry. Email, webhook, and Slack notifications ensure the right people are notified in time — not when the incident has already started.

📊

Audit-ready reporting

Executive and operational reports with certificate status, expiry forecasts, and compliance score — ready to download and present to supervisory authorities and management.

🌐

Supplier monitoring

Monitoring of key supplier TLS certificates extends your security register to the supply chain — without manual processes that cannot scale with the number of suppliers.

🕵️

Discovery of unknown certificates

Certificate Transparency monitoring and external scanning discover certificates issued for your domains that IT has not registered — shadow IT certificates that create compliance gaps.

app.certcontrol.pro — NIS2 Compliance Report
NIS2 compliance report in CertControl showing certificate status and audit documentation

NIS2 compliance report — certificate status, expiry forecast, and audit documentation in one view.

Questions & answers

NIS2 and certificates — frequently asked questions

Does NIS2 apply to certificates and TLS?

Yes. NIS2 Article 21(2)(h) requires documented policies for the use of cryptography and encryption — which directly covers TLS certificates, cipher suite configuration, and key management. Article 21(2)(e) further requires secure acquisition and maintenance of information systems, including vulnerability handling. Expired or misconfigured certificates represent a failure under both sub-articles. Supervisory authorities are expected to request documentation of certificate management processes during inspections.

When does a certificate expiry become a NIS2 incident?

A certificate expiry causing service unavailability, inaccessibility of critical systems, or a data breach can qualify as a significant incident under NIS2. The assessment depends on the criticality of the system and the scope of impact. The definition of "significant incident" is broadly worded — and uncertainty should always lead to reporting.

Which organisations are in scope for NIS2?

NIS2 covers essential and important entities across 18 sectors including energy, transport, banking, healthcare, digital infrastructure, and public administration. Generally, organisations with 50 or more employees or annual revenue exceeding €10 million operating in a covered sector are in scope. Member states may apply the directive more broadly to certain categories.

What are the penalties for NIS2 non-compliance?

Important entities can be fined up to €7 million or 1.4% of global annual turnover. Essential entities can be fined up to €10 million or 2% of global annual turnover. In addition, senior management can be held personally liable for failures to implement adequate security measures.

Can CertControl generate documentation for NIS2 supervisory inspections?

Yes. CertControl generates executive and operational reports with complete certificate status, expiry forecasts, compliance scores, and historical incident records. The reports are designed to be presented directly to supervisory authorities or management — downloadable in one click without manual assembly.

Get started

Ready to document NIS2 compliance?

Book a walkthrough with our team — we'll show you exactly which NIS2 requirements CertControl covers and what else you need to have in place.

14-day free trial  ·  EU hosted  ·  GDPR aligned

Related resources

Guides and checklists for NIS2 compliance

Guide

NIS2 and Certificate Management: What Security Teams Need to Know

A complete walkthrough of NIS2 requirements for TLS and PKI — from asset inventory to incident reporting.

Read the guide →
Guide

Supplier Certificate Risk: The Supply Chain Blind Spot

How third-party certificate failures cascade into your own NIS2 obligations — and how to get visibility before incidents occur.

Read the guide →
Guide

NIS2 Audit Inspections: Documentation Your CISO Must Have Ready

What supervisory authorities specifically ask for during NIS2 inspections — and how to prepare your technical documentation.

Read the guide →
Financial sector

DORA and NIS2 Certificate Requirements in Financial Services

Banks and insurers must comply with both DORA and NIS2. Here is what each regulation requires — and where they overlap.

Read the guide →
Checklist

NIS2 Checklist: 20 Requirements Under Article 21

Go through the requirements point by point — which ones does CertControl cover automatically, and which require manual action?

See the checklist →
Scope guide

Is Your Organisation Subject to NIS2?

Sector overview and a two-question test: find out whether your organisation qualifies as an essential or important entity under NIS2.

Check your scope →