Skip to main content
Branch preview. The NIS2 playbooks ship with the next MSPortal release. Screenshots are added after the production check.
Audience: MSP staff with Playbooks management permission and active billing. Read access lets you inspect the catalog; import permission is separate. NIS2 is Directive (EU) 2022/2555. It applies to essential and important entities in the sectors listed in its annexes, and it reaches their suppliers through contract terms. Each EU Member State applies it through national law, so confirm the national rules for each client.

Find the NIS2 playbooks

Open Settings > Compliance > Playbooks > Security Frameworks > NIS2. The page groups ten playbooks by article. Start with the scope and governance playbook. It records whether the client is an essential entity, an important entity, or a supplier to one, and that answer decides how the other playbooks apply.

Review the checks

Open a playbook title to read its check list. Every check title starts with its article reference, such as Art. 21(2)(c) or Art. 23(4)(a). Each check includes how to check, why it matters, remediation, expected evidence and cross-references to the implementing regulation, ISO/IEC 27001, CIS Controls and NIST CSF where they apply. Close details after review. The details Copy action performs an immediate copy; use Add on the card if you need the import-mapping dialog.

Import with the correct mapping

  1. Click Add for one playbook, or select several and choose Add to Tenant in the header.
  2. Review every Folder destination in Add Playbooks to Tenant. The default is a NIS2 folder with one subfolder per playbook.
  3. Choose a Status list for each selected playbook.
  4. Review the duplicate warning if a playbook is already imported. Importing again creates another copy.
  5. Click Add to Tenant, then inspect the destination folder under Settings > Compliance > Checks and the new group under Groups.
NIS2 checks are company-level checks, so the dialog suggests no device types.

Prepare an assessment

Tailor the imported checks to the client’s Member State. Replace the generic references to the national authority and CSIRT with the client’s actual bodies and portal, and adjust thresholds where national law sets them. Then configure groups, runs and company scope through Compliance settings. The playbooks structure a review. They do not determine a client’s legal status, replace legal advice or certify compliance.

FAQs

No. They follow the directive text. Add or adjust checks for national requirements after import.
Yes. The scope playbook includes a check for suppliers to NIS2 entities, and the Article 21 playbooks work as a general security review.
No. NIS2 is EU law. NIST CSF 2.0 is a voluntary US framework. Many NIS2 checks cross-reference NIST CSF 2.0 categories.
A repeated import creates another group and check copies. Review existing content before importing again.