Rule-set entry · nis2-001

MFA / backup / incident contact baseline

Baseline security: multi-factor authentication on admin accounts, tested backups, and a documented incident-response contact.

Module
nis2 light
Scope
SMEs adopting NIS2-Light baseline; direct NIS2 scope for essential / important entities.
Effective since
2024-10-17
Next deadline
Rule version
1.0
Last reviewed
2026-01-10
Reviewed by
KonformPass Team
Rule set
EUReady Rules v1.0

Source

NIS2-Umsetzungsgesetz (Entwurf) / BSI-Empfehlungen

Open source

What KonformPass checks

This rule is evaluated in the readiness check via the following questions:

  • nis2_mfa
  • nis2_backup
  • nis2_incident_contact

Scoring impact

Reduces NIS2-Light score by up to 35 pts

Weight in module: 35

Not a binding legal statement

This entry is a structured, manually reviewed orientation. It does not replace legal, tax, IT security, accessibility or certification advice. Binding statements follow from the underlying regulation itself.