The libraryEU

NIS2, the cyber law and its national transpositions

EU · effective 2024-10-17 · generated from the corpus

incident reporting within 24 hours, a named accountable person, supply chain accountability

What this opens

20 openings, strongest first. Nothing is hidden. Each one says how far the evidence actually goes, so you can decide which are worth your time. 4 are backed by a specific recorded outcome.

01

Supply‑Chain Vulnerability Dashboard

81/100

tooling infrastructure

The dashboard aggregates supplier‑declared cyber posture, flags uncertified vendors, and allows firms to issue provisional compliance certificates pending formal certification. It bridges the gap identified in pat-cert-capacity-lag by providing a trusted, auditable record of supply‑chain risk.

Backed by recorded evidenceOutcome 5, 6 and 7 show certified‑body shortages and missing top‑level certification, matching the dashboard’s purpose.
What would kill it

If firms continue to rely on uncertified suppliers without any provisional certification dashboard, the mechanism fails.

02

Supply‑Chain Compliance Data Integration Platform

80/100

tooling infrastructure

The brokerage issues digital provisional certificates; a software layer fetches the IDs, verifies them against a central registry, and feeds the compliance status into procurement and risk management workflows, enabling continuous monitoring.

Backed by recorded evidenceOutcomes 1‑4 document a central registry of registered entities, supporting a platform that pulls IDs from that registry.
What would kill it

If the central registry contains no provisional certificate IDs after six months, the platform cannot function.

03

NIS2 Incident Reporting Knowledge Training Platform

79/100

information gap

The regulator focuses on education in the first cycle, requiring firms to internalize the reporting protocols before the audit phase. This creates a knowledge gap that can only be closed by dedicated training programs.

Backed by recorded evidenceOutcome 9 confirms the regulator’s education‑first approach, creating a reporting knowledge gap.
What would kill it

If firms meet the 24‑hour reporting requirement without using external training, demand for the platform disappears.

04

Rapid Cyber Certification Brokerage

76/100

supply gap

Because certified supply runs out before demand, firms use the dashboard to find uncertified suppliers. A brokerage can vet and fast‑track these suppliers for certification and issue provisional compliance certificates, filling the shortfall until formal certification is available.

Backed by recorded evidenceOutcomes 5‑7 show certification bodies lagged, confirming a certified‑supply gap.
What would kill it

If by 31 Dec 2026 there are at least three accredited bodies able to certify at the highest level covering all essential entities, the certification brokerage would be unnecessary.

05

AI‑Driven Incident Reporting Simulation Platform

72/100

tooling infrastructure

The regulator’s first‑cycle education requires firms to demonstrate reporting procedures. A cloud platform offers simulated incidents, auto‑grading, and real‑time feedback, letting firms internalize protocols before the audit phase.

Supported by a pattern, not a specific outcomeEducation‑first approach (pat‑first‑cycle‑education, outcome 9) creates demand for simulated reporting drills.
What would kill it

If the regulator mandates live incident drills instead of simulated ones by 31 Mar 2025, the simulation platform loses its relevance.

06

Automated Incident Reporting Platform

70/100

tooling infrastructure

The platform automatically captures security event logs, applies the 24‑hour NIS2 deadline, and routes a concise report to the designated accountable person and the national authority. It also stores evidence for the audit that will occur a year later, aligning with the phased audit schedule from pat-audit-comes-last.

Supported by a pattern, not a specific outcomeSupported by pat-cert-capacity-lag and the long‑lead audit timeline; no direct outcome mentions automation.
What would kill it

If no organization adopts the automated reporting tool and all reports remain manual, the value proposition collapses.

07

24‑hour incident reporting readiness consulting

69/100

service demand

Consultants perform a gap analysis, design incident reporting workflows, and train staff, ensuring the 24‑hour reporting requirement is met before any incident occurs.

Supported by a pattern, not a specific outcomeEarly education focus and lack of sanctions suggest operators will seek consulting to meet 24‑hour reporting, though no outcome directly proves demand.
What would kill it

An organization that used the consulting service still fails to submit a 24‑hour incident report after an incident.

08

NIS2 Role and Incident Reporting Training Suite

68/100

information gap

The law introduces new roles and strict timelines. A training and knowledge service can create role definitions, reporting templates, and internal SOPs, ensuring firms are ready before the law takes effect.

Supported by a pattern, not a specific outcomePattern pat‑first‑cycle‑education and outcome 9 show the regulator focuses on education first.
What would kill it

If the regulator issues its first sanction before 30 Jun 2025, the premise that education dominates the first cycle is disproved.

09

Compliance Workflow Design Consulting

63/100

service demand

Because the law names a single accountable person, firms must create formal reporting workflows. A consulting service audits current practices, maps incident flows, and installs custom templates, ensuring compliance before the audit.

Supported by a pattern, not a specific outcomeThe need for a single accountable person (outcome 9, pat‑first‑cycle‑education) drives demand for workflow consulting.
What would kill it

If the regulator publishes a mandatory, one‑size‑fit‑all incident‑reporting template by 1 Feb 2025, custom workflow consulting would no longer be needed.

10

Scenario Customization Consulting for Supply Chain Reporting

59/100

service demand

Consultants audit a firm’s supply‑chain map, design custom incident scenarios that mirror real‑world threats, integrate those scenarios into the AI platform, and train staff on interpreting simulation results.

Supported by a pattern, not a specific outcomePatterns pat-scope-multiplies and pat-audit-comes-last highlight expanding scope and delayed audits, suggesting demand for early scenario‑customisation consulting.
What would kill it

If after one year fewer than 5% of regulated firms have integrated the AI platform for supply‑chain incident reporting, the premise is falsified.

11

NIS2 Incident Reporting Implementation Consulting

57/100

information gap

The NIS2 duties phase in over years; registration and implementation precede the audit. Firms must therefore engage consultants early to build compliant reporting systems before the audit triggers.

Supported by a pattern, not a specific outcomePat‑audit‑comes‑last shows implementation precedes audit, creating early consulting demand.
What would kill it

If firms do not engage consultants before the audit phase, the early‑implementation consulting market does not materialise.

12

Provisional Compliance Audit Services

56/100

service demand

The 24‑hour reporting rule forces firms to confirm supplier compliance immediately; audit firms can rapidly test and certify suppliers using the brokerage’s provisional certificates, meeting the deadline.

Supported by a pattern, not a specific outcomePattern pat-cert-capacity-lag shows certified capacity lags demand, and outcome 8 shows firms buying security‑officer services, supporting a market for provisional audit services.
What would kill it

If no firms request provisional audit services within six months of the law taking effect, the hypothesis is falsified.

13

Pre‑sale of compliance management platforms

52/100

timing arbitrage

Software vendors can offer a limited‑time discount to capture early adopters; after the deadline, demand spikes and prices increase, allowing early buyers to amortize cost over a higher post‑law valuation.

Supported by a pattern, not a specific outcomePat‑first‑cycle‑education, pat‑audit‑comes‑last and pat‑cert‑capacity‑lag suggest a pre‑sale price gap.
What would kill it

If early‑sale prices are not higher than later prices after the law, pre‑sale contracts provide no advantage.

14

Early-bird compliance consulting contracts

50/100

timing arbitrage

Compliance providers can price early bookings lower; after the law, the surge in demand drives up rates, so early buyers gain a cost advantage.

Supported by a pattern, not a specific outcomePat‑first‑cycle‑education, pat‑audit‑comes‑last and pat‑scope‑multiplies point to a price surge after the law.
What would kill it

If early‑bird consulting contracts do not lock in lower rates than contracts signed after the law, the arbitrage does not exist.

15

Adaptive Incident Reporting Guidance Plug‑in

47/100

information gap

The plug‑in analyzes logs from the AI simulation platform, maps each event to the required NIS2 fields, and presents a template editor that auto‑fills missing data. It also stores best‑practice examples for future reference.

Supported by a pattern, not a specific outcomePattern pat-first-cycle-education indicates the regulator prioritises education over punishment, creating a need for guidance tools.
What would kill it

If the regulator publishes a mandatory reporting template that supersedes any plugin suggestions within three months, the premise is falsified.

16

Supply‑chain accountability audit and certification service

44/100

service demand

Audit firms evaluate supplier controls, document accountable persons, and issue certification, filling the certification gap identified in the new regime.

Supported by a pattern, not a specific outcomePattern shows certification capacity lag and audits come last, indicating a market for private audit and certification services, but no direct outcome confirms it.
What would kill it

Regulator explicitly forbids non‑accredited audit firms from issuing supply‑chain accountability certifications.

17

Training Incident Response Teams for 24h Reporting

/100

supply gap

The law requires incidents to be reported within 24 hours, so firms need dedicated teams that can investigate and file reports quickly. Current staff levels are too low to cover all potential incidents.

Not scored
18

Supply Chain Audit Consulting

/100

adjacent market

NIS2 requires firms to monitor suppliers for cyber risk, so consulting firms can sell assessment, certification, and remediation services.

Not scored
19

Cyber Incident Response Staffing Shortage

/100

adjacent market

The law names an accountable person and forces immediate reporting, so firms must hire or outsource certified responders, a role that is currently in short supply.

Not scored
20

Supply Chain Certification Gap

/100

supply gap

NIS2 demands supply chain accountability and certification for suppliers. Certification bodies have limited capacity, so the number of certified suppliers falls short of the new demand. Companies must rely on uncertified or self‑declared suppliers.

Not scored

The same event, in one country

Everything above is the version that is true everywhere. Picking a country does not filter it. It loads a different analysis, with that country's own dates, its own competition and its own count of who is affected. Pick one to see where that country stands.

What history says

Drawn from the 5 precedents the corpus held when this derivation ran. How often each pattern was actually seen is on the card, because one sighting is not a rule.

The regulator spends the first cycle on education rather than punishment. One wrote a two year fine moratorium into the statute itself. Early fines are a bad predictor of whether a regime has teeth.

Seen in 3 of the countries we studied · be-nis2-2024, de-nis2-2025, pl-nis2-2026

Duties phase in over years and the audit is always last. Registration comes first, implementation next, and verification a year or two after that.

Seen twice. Not yet a rule. · be-nis2-2024, pl-nis2-2026

Where a duty requires something certified, the certified supply runs out before the demand does. What fills the gap is uncertified: a self-declaration, or a counterfeit carrying a standard number one digit out from the real one.

Seen twice. Not yet a rule. · be-nis2-2024, us-eclipse-2024

The supervised population multiplies several times over when the new regime replaces the old one, so the regulator inherits far more entities than it has ever overseen.

Seen once. This is an instance, not a pattern. · nl-nis2-2026

Official visitor forecasts miss by an order of magnitude in both directions. Planning to the published forecast is the main way operators lose money on a dated event.

Seen once. This is an instance, not a pattern. · us-eclipse-2024

Accommodation inside the affected corridor multiplies several times over and fills weeks ahead, so the constraint on visitors becomes beds rather than interest.

Seen once. This is an instance, not a pattern. · us-eclipse-2024

When a regulator offers a choice between a light national framework and a heavier international standard, most firms take the lighter one.

Seen once. This is an instance, not a pattern. · be-nis2-2024

For an event whose value depends on conditions on the day, demand lands where the conditions turn out good, not where they were predicted good. Fixed capacity in one location carries the whole risk.

Seen once. This is an instance, not a pattern. · us-eclipse-2024

Certification at the top tier lags the lower tiers, so the entities under the strictest duty are the last able to discharge it.

Seen once. This is an instance, not a pattern. · be-nis2-2024

Most of the population misses the registration deadline. Well under half had registered when the date passed, and the regulator moved to notices rather than penalties.

Seen once. This is an instance, not a pattern. · de-nis2-2025

What we measured, and what we could not

QuestionAnswer
How many are affectedA source exists and we have not read it yet. Named in the registry, so you can check that we go back.
Is anyone already doing thisA source exists and we have not read it yet. Named in the registry, so you can check that we go back.
What it sold forA source exists and we have not read it yet. Named in the registry, so you can check that we go back.

The precedents underneath

WhereWhenOutcomes recordedUsable
BE202490
US2024110
DE202560
NL202620
PL202630

Recorded but not verified

Nothing on this page is derived from these. Each one is here because removing it quietly would be worse, and each says which of two different things happened: the page was not there, or the site would not let us look.

31 recorded outcomes answer an older question about market movements rather than about businesses created. They are kept, they are visible in the counts above, and nothing on this page learns from them.