> ## Documentation Index
> Fetch the complete documentation index at: https://docs.msportal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Add NIS2 playbooks

> Review a client against the EU NIS2 directive by article, then import the playbooks you need.

<Note>
  Branch preview. The NIS2 playbooks ship with the next MSPortal release. Screenshots are added after the production check.
</Note>

**Audience:** MSP staff with Playbooks management permission and active billing. Read access lets you inspect the catalog; import permission is separate.

NIS2 is Directive (EU) 2022/2555. It applies to essential and important entities in the sectors listed in its annexes, and it reaches their suppliers through contract terms. Each EU Member State applies it through national law, so confirm the national rules for each client.

## Find the NIS2 playbooks

Open **Settings > Compliance > Playbooks > Security Frameworks > NIS2**. The page groups ten playbooks by article.

| Section                                         | Playbooks                                                     |
| ----------------------------------------------- | ------------------------------------------------------------- |
| **Scope and governance (Articles 2, 3 and 20)** | NIS2 Scope, Registration & Management Accountability          |
| **Risk-management measures (Article 21)**       | NIS2 Risk Analysis, Security Policies & Effectiveness         |
|                                                 | NIS2 Incident Handling                                        |
|                                                 | NIS2 Business Continuity, Backup & Crisis Management          |
|                                                 | NIS2 Supply Chain Security                                    |
|                                                 | NIS2 Secure Acquisition, Development & Vulnerability Handling |
|                                                 | NIS2 Cyber Hygiene & Training                                 |
|                                                 | NIS2 Cryptography, MFA & Secure Communications                |
|                                                 | NIS2 HR Security, Access Control & Asset Management           |
| **Incident reporting (Article 23)**             | NIS2 Incident Reporting                                       |

Start with the scope and governance playbook. It records whether the client is an essential entity, an important entity, or a supplier to one, and that answer decides how the other playbooks apply.

## Review the checks

Open a playbook title to read its check list. Every check title starts with its article reference, such as **Art. 21(2)(c)** or **Art. 23(4)(a)**. Each check includes how to check, why it matters, remediation, expected evidence and cross-references to the implementing regulation, ISO/IEC 27001, CIS Controls and NIST CSF where they apply.

Close details after review. The details **Copy** action performs an immediate copy; use **Add** on the card if you need the import-mapping dialog.

## Import with the correct mapping

1. Click **Add** for one playbook, or select several and choose **Add to Tenant** in the header.
2. Review every **Folder** destination in **Add Playbooks to Tenant**. The default is a **NIS2** folder with one subfolder per playbook.
3. Choose a **Status list** for each selected playbook.
4. Review the duplicate warning if a playbook is already imported. Importing again creates another copy.
5. Click **Add to Tenant**, then inspect the destination folder under **Settings > Compliance > Checks** and the new group under **Groups**.

NIS2 checks are company-level checks, so the dialog suggests no device types.

## Prepare an assessment

Tailor the imported checks to the client's Member State. Replace the generic references to the national authority and CSIRT with the client's actual bodies and portal, and adjust thresholds where national law sets them. Then configure groups, runs and company scope through [Compliance settings](/user-guides/settings/compliance).

The playbooks structure a review. They do not determine a client's legal status, replace legal advice or certify compliance.

## FAQs

<AccordionGroup>
  <Accordion title="Do the playbooks cover national transposition laws?">
    No. They follow the directive text. Add or adjust checks for national requirements after import.
  </Accordion>

  <Accordion title="Can I use them for a client that is out of scope?">
    Yes. The scope playbook includes a check for suppliers to NIS2 entities, and the Article 21 playbooks work as a general security review.
  </Accordion>

  <Accordion title="Is NIS2 the same as NIST CSF 2.0?">
    No. NIS2 is EU law. NIST CSF 2.0 is a voluntary US framework. Many NIS2 checks cross-reference NIST CSF 2.0 categories.
  </Accordion>

  <Accordion title="Can I import an Imported playbook again to update it?">
    A repeated import creates another group and check copies. Review existing content before importing again.
  </Accordion>
</AccordionGroup>

## Related guides

* [Use playbooks to prepare compliance reviews](/user-guides/playbooks/index)
* [Add CIS benchmarks](/user-guides/compliance/adding-cis-benchmarks)
* [Compliance settings](/user-guides/settings/compliance)
