Guide

How to prepare for NIS2 in Microsoft 365

How to align a Microsoft 365 estate with the NIS2 Directive by treating readiness as an evidence problem: map requirements to controls, baseline access and configuration, and capture durable records an auditor can follow.

Published For Compliance & Legal, CISO
Definition

NIS2 readiness in Microsoft 365 is the work of aligning access, configuration, and evidence with the NIS2 Directive's requirements for essential and important entities. Like DORA, its gaps in Microsoft 365 tend to sit in the evidence trail rather than the technology, so readiness means capturing who has access, what changed, and how incidents were handled as durable records an auditor can follow from requirement to proof.

NIS2 widens both the set of organizations in scope and the expectation that they can demonstrate control, not just assert it. In Microsoft 365 that shifts the work from configuring the right settings to proving, over time, that access, change, and incidents were handled the way the directive requires.

The approach mirrors any evidence-driven regulation. Map the obligations to concrete M365 controls, baseline them, capture the trail continuously, and review it on a cadence. The steps below build that evidence so an NIS2 audit becomes a handover rather than a reconstruction under pressure.

Steps

  1. Map NIS2 requirements to M365 controls

    Translate the relevant NIS2 obligations into the concrete Microsoft 365 controls and configurations that satisfy them, so every requirement has an owner and a control it maps to.

  2. Baseline access and configuration

    Record the baseline access and configuration of the controls that matter, so you can demonstrate what good looked like and detect drift away from it.

  3. Capture change and incident evidence

    Ensure permission changes, sharing events, administrative actions, and incident handling are captured and retained, because under NIS2 the audit trail is the evidence.

  4. Review on a cadence

    Review the collected evidence on a schedule, not just before an audit, so gaps are found and closed while they are cheap to fix.

  5. Package for audit

    Assemble the mapped controls, baselines, and logs into a package an auditor can follow from obligation to proof, turning the audit into a handover.

Related connectors

Trusted by

MAPALBAMVille de LuxembourgWACKERGRUNDFOSAMGENOsramLufthansaThyssenKruppSunrisePattern