Skip to content

NIS2NIST 800-171 crosswalk

A control-by-control mapping between NIS2 Directive (EU 2022/2555) and NIST SP 800-171 Rev. 2. 5 mappings.

NIS2NIST 800-171RelationshipNotes
Art. 21(2)(a)
Risk analysis and information system security policies
3.11.1
Periodically assess risk
RelatedCurated
Risk assessment & management
Art. 21(2)(b)
Incident handling
3.6.1
Establish an incident-handling capability
PartialCurated
Incident response & breach notification
Art. 21(2)(h)
Cryptography and encryption
3.13.11
Employ FIPS-validated cryptography
EquivalentCurated
Cryptography & data protection
Art. 21(2)(i)
Access control and asset management
3.1.1
Limit system access to authorized users
PartialCurated
Access control & identity
Art. 23
Reporting obligations
3.6.1
Establish an incident-handling capability
PartialCurated
Incident response & breach notification

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.