Skip to content

NIS2NIST 800-171 crosswalk

A control-by-control mapping between NIS2 Directive (EU 2022/2555) and NIST SP 800-171 Rev. 2. 5 mappings.

NIS2NIST 800-171RelationshipNotes
Art. 21(2)(a)
Risk analysis and information system security policies
3.11.1
Periodically assess risk
RelatedCurated
Évaluation et gestion des risques
Art. 21(2)(b)
Incident handling
3.6.1
Establish an incident-handling capability
PartialCurated
Réponse aux incidents et notification des violations
Art. 21(2)(h)
Cryptography and encryption
3.13.11
Employ FIPS-validated cryptography
EquivalentCurated
Cryptographie et protection des données
Art. 21(2)(i)
Access control and asset management
3.1.1
Limit system access to authorized users
PartialCurated
Contrôle d'accès et identité
Art. 23
Reporting obligations
3.6.1
Establish an incident-handling capability
PartialCurated
Réponse aux incidents et notification des violations

Mappings marked “Official” derive from standards-body informative references; “Curated” mappings are authored by Cyber Compliance and provided for guidance only.