NIS2 Compliance

NIS2 and
certificate management

NIS2 Article 21 requires technical security measures — including control over TLS certificates and PKI. CertControl gives your organisation the register, monitoring, and reporting that supervisory authorities expect.

14-day free trial  ·  Dedicated instance  ·  EU hosted

NIS2 Article 21 — requirement coverage
Asset inventory
Automatically maintained register of all certificates
Risk assessment
TLS risk score and expiry risk per endpoint
Incident response
Alerts and audit log for 24/72h reporting
Supply chain security
Monitoring of supplier certificates
Audit documentation
Executive reports ready for supervisory authorities
What NIS2 requires

Article 21 and TLS certificates

The NIS2 Directive obliges essential and important entities to implement appropriate and proportionate technical security measures. TLS certificates are central to three of the eight requirement areas.

Article 21(2)(a)

Risk analysis and information system security

Organisations must document risks associated with their information systems — including the risk of certificate expiry, weak TLS configuration, and compromised keys. A certificate asset register is the foundation for this analysis.

Article 21(2)(h)

Security in acquisition and maintenance of systems

Systems must be configured and maintained securely throughout their lifecycle. For TLS this means: current certificates, strong cipher suites, correct certificate chains, and timely renewal — all documented and traceable.

Article 21(2)(f)

Supply chain security

The security of suppliers' and service providers' systems is part of the organisation's overall security posture. Monitoring key supplier TLS certificates provides early warning of third-party risks before they become incidents.

Incident reporting

24 hours. 72 hours. One month.

NIS2 introduces strict deadlines for reporting significant incidents to national authorities. A certificate expiry causing service unavailability can qualify as a significant incident — and starts the clock.

24h
Early warning
Notification to authority that an incident has occurred
72h
Incident notification
Update with initial assessment of severity and scope
1 mo
Final report
Complete analysis of incident, root cause, impact, and remediation

Without a complete certificate register, it can take hours just to establish whether a certificate expiry is the root cause of an outage — time you do not have under NIS2's reporting requirements. CertControl maintains a continuous audit log of all certificate events, changes, and alerts.

How CertControl covers NIS2

NIS2-ready certificate management

📋

Complete asset register

Automatically updated register of all certificates across monitored endpoints — internal and external. Expiry dates, ownership, environment, and associated systems documented and searchable.

🔍

TLS risk assessment

Automatic scanning of TLS configuration for weak cipher suites, protocol versions, and certificate issues. Risk score per endpoint with prioritised remediation recommendations.

🔔

Proactive alerting

Configurable alerts up to 90 days before expiry. Email, webhook, and Slack notifications ensure the right people are notified in time — not when the incident has already started.

📊

Audit-ready reporting

Executive and operational reports with certificate status, expiry forecasts, and compliance score — ready to download and present to supervisory authorities and management.

🌐

Supplier monitoring

Monitoring of key supplier TLS certificates extends your security register to the supply chain — without manual processes that cannot scale with the number of suppliers.

🕵️

Discovery of unknown certificates

Certificate Transparency monitoring and external scanning discover certificates issued for your domains that IT has not registered — shadow IT certificates that create compliance gaps.

app.certcontrol.pro — NIS2 Compliance Report
NIS2 compliance report in CertControl showing certificate status and audit documentation

NIS2 compliance report — certificate status, expiry forecast, and audit documentation in one view.

Questions & answers

NIS2 and certificates — frequently asked questions

Does NIS2 apply to certificates and TLS?

Yes. NIS2 Article 21(2)(h) requires securing the acquisition, development, and maintenance of information systems — including TLS/PKI. Expired or misconfigured certificates count as a technical security weakness under the directive. Supervisory authorities are expected to request documentation of certificate management processes during inspections.

When does a certificate expiry become a NIS2 incident?

A certificate expiry causing service unavailability, inaccessibility of critical systems, or a data breach can qualify as a significant incident under NIS2. The assessment depends on the criticality of the system and the scope of impact. The definition of "significant incident" is broadly worded — and uncertainty should always lead to reporting.

Which organisations are in scope for NIS2?

NIS2 covers essential and important entities across 18 sectors including energy, transport, banking, healthcare, digital infrastructure, and public administration. Generally, organisations with 50 or more employees or annual revenue exceeding €10 million operating in a covered sector are in scope. Member states may apply the directive more broadly to certain categories.

What are the penalties for NIS2 non-compliance?

Important entities can be fined up to €7 million or 1.4% of global annual turnover. Essential entities can be fined up to €10 million or 2% of global annual turnover. In addition, senior management can be held personally liable for failures to implement adequate security measures.

Can CertControl generate documentation for NIS2 supervisory inspections?

Yes. CertControl generates executive and operational reports with complete certificate status, expiry forecasts, compliance scores, and historical incident records. The reports are designed to be presented directly to supervisory authorities or management — downloadable in one click without manual assembly.

Get started

Ready to document NIS2 compliance?

Book a walkthrough with our team — we'll show you exactly which NIS2 requirements CertControl covers and what else you need to have in place.

14-day free trial  ·  EU hosted  ·  GDPR aligned

Related resources

Dive deeper into NIS2 and certificates

Guide

NIS2 and Certificate Management: What Security Teams Need to Know

A complete walkthrough of NIS2 requirements for TLS and PKI — from asset inventory to incident reporting.

Read the guide →
Guide

Supplier Certificate Risk: The Supply Chain Blind Spot

How third-party certificate failures cascade into your own NIS2 obligations — and how to get visibility before incidents occur.

Read the guide →
Use case

Audit Readiness

Keep certificate documentation organised and stay ready for supervisory inspections at any time — not just when the request arrives.

See the use case →