Skip to content

NIS2 Directive

21 rules checking EU NIS2 Directive (2022/2555) compliance for essential and important entities. NIS2 requires organizations to implement appropriate and proportionate technical measures for network and information system security.

Rule IDSeverityNIS2 ReferenceCategorySummary
NIS2-NET-001HIGHArt. 21(2)(h)Insecure ProtocolsUnencrypted protocol detected
NIS2-NET-002CRITICALArt. 21(2)(g)Deprecated ProtocolsDeprecated or broken protocol detected
NIS2-NET-003HIGHArt. 21(2)(h,i)Insecure AuthenticationInsecure authentication protocol detected
NIS2-NET-010CRITICALArt. 21(2)(a)Overly PermissiveAny-to-any unrestricted traffic
NIS2-NET-011CRITICALArt. 21(2)(i)Overly PermissiveOverly broad source address
NIS2-NET-012CRITICALArt. 21(2)(i)Overly PermissiveOverly broad destination address
NIS2-NET-013CRITICALArt. 21(2)(a)Overly PermissiveAll ports or wide port range allowed
NIS2-NET-014HIGHArt. 21(2)(a)Overly PermissiveAll protocols (ANY) allowed
NIS2-NET-020CRITICALArt. 21(2)(a)Network SegmentationDirect internet-to-internal access
NIS2-NET-021CRITICALArt. 21(2)(a,i)Database ExposureDatabase ports exposed from broad source
NIS2-NET-030CRITICALArt. 21(2)(i,j)Remote AccessRemote admin from external without VPN
NIS2-NET-031HIGHArt. 21(2)(i,j)Administrative AccessAdmin protocols from broad sources
NIS2-NET-032CRITICALArt. 21(2)(a)ICS/SCADA IsolationICS/SCADA protocols crossing zone boundaries
NIS2-NET-033HIGHArt. 21(2)(d)Supply Chain SecurityUnrestricted outbound to internet
NIS2-NET-034CRITICALArt. 21(2)(a,i)Container ExposureContainer/orchestration APIs exposed
NIS2-NET-035CRITICALArt. 21(2)(a,i)Out-of-Band ManagementIPMI/BMC hardware control exposed
NIS2-NET-036MEDIUMArt. 21(2)(a)DNS and Covert ChannelsDNS as covert channel from internal segment
NIS2-NET-037CRITICALArt. 21(2)(a,i)Risky Service ExposureHigh-risk service from broad source
NIS2-NET-038HIGHArt. 21(2)(i)Administrative AccessManagement traffic crossing untrusted segments
NIS2-NET-039MEDIUMArt. 21(2)(f)Rule DocumentationNo application name or business justification