Scope
SecOps ForcesNIS2: what actually changes
Compliance
NIS2 does not askfor an annual report.It asks for evidence.
The directive expects risk management over time, not a snapshot taken once a year. That shift is what surprises most: a dated audit does not demonstrate an ongoing process, and the process is what you will be asked to prove.
Information page · No offer on this page · Updated August 2026
What changes in practice
Four shifts
that affect everyone.
We will not walk through the text article by article — others do that better, and your legal counsel is better placed for it. Here is what we observe, on the technical side, at organizations preparing for it.
Supply chain
Your customers now audit you
Leadership
Accountability moves up
Continuity
Evidence must be continuous
What we cover
Our part of the subject, clearly bounded.
Email security
Microsoft 365 configuration
Timestamped evidence
Where to start
Measure before you declare.
The first question on any questionnaire is about your actual state. It is better to know it before answering.
Microsoft 365 audit
Frequently asked
Common questions about NIS2.
Are we in scope?
Is an annual audit enough?
Can you make us compliant?
What do insurers ask on top?
Where do you stand today?
Thirty minutes to look at your situation. If your deadline is regulatory, we will tell you frankly what falls to us and what does not.