NIS2 compliance Microsoft 365
NIS2 gives you 24 hours to report. Default logs keep 90 days.
The directive sets statutory clocks - an early warning within 24 hours, a notification with indicators of compromise within 72, a final report within a month - and holds management personally accountable for the measures behind them. 1Security measures NIS2 readiness from the Microsoft 365 tenant itself: each Article 21 measure as a requirement with a live status, up to three years of forensic history behind the reporting clock, and a dated evidence pack you can hand to the authority or the board.
The scenario
Counsel says you are in scope. The first ask is proof.
NIS2 (EU 2022/2555) covers essential and important entities across 18 sectors, and it arrives with teeth: fines up to 10 million euro or 2% of worldwide turnover for essential entities, 7 million or 1.4% for important ones, and management bodies that must approve the measures and can be held personally liable. The first thing anyone asks after the scoping call is not for a new firewall. It is for evidence that the measures exist and work.
Here is the part the questionnaire industry does not tell you: the frameworks overlap. Across eleven regulations - NIS2 among them, next to GDPR, DORA, ISO/IEC 27001 and the EU AI Act - the obligations collapse into 15 shared requirements, and 11 of those are measurable directly from tenant data. Only four are documents a human has to write. If you run your tenant well, you are further along than the spreadsheet suggests, and 1Security measures exactly how far before you change a single setting.
What does not wait is the clock. Article 23 wants an early warning in 24 hours, a notification with severity, impact and indicators of compromise in 72, and a final report with root cause inside a month. The evidence those reports rest on normally lives in 90-day logs and disconnected admin centers, which is why forensic readiness under NIS2 is a standing requirement, not something you stand up on incident day.
The walkthrough
From scoping letter to evidence pack, on screens.
Each beat is a screen with a filter and an artifact at the end, not a workshop.
- 01
Open the NIS2 framework view
The Compliance screen scores the tenant against NIS2 article by article, each article citing the shared requirements that satisfy it - measured statuses for things like log retention, access control and dormant accounts, attested statuses for the four documents. Not evaluated is never counted as a pass, and the worklist orders every open requirement by how many articles it unlocks.
- 02
Answer the supply-chain article
Article 21(2)(d) asks who has a foothold in you and who you hand data to. The Apps screen lists every OAuth app and integration with publisher, access channel and the admin who consented it. The Domains screen lists every external organisation seen in guests, shared files and mail, with its configured standing next to its observed activity and drift flagged.
- 03
Drill the 72-hour question before it is real
Pick one account on the Activity Logs screen and produce its full attributed timeline - actor, resource, app, device, location - then everything it can still reach and how much of that carries regulated data. With up to three years of retained history on standard licenses, the drill takes a sitting, and the real 72-hour notification stops being frightening.
- 04
Export the dated evidence
The whole status document is captured automatically every Monday and on demand, so what was our status on this date has a real answer. The per-framework evidence pack exports as a dated document and is served over the read-only REST API - the same artifact for the authority, the auditor and the board.
What makes it work
Three parts of the platform behind the NIS2 answer.
The same 15 requirements score GDPR, DORA, ISO/IEC 27001 and the EU AI Act in the same pass - one fix moves every framework that cites it.
Compliance monitoring
Eleven frameworks measured continuously from tenant data, with snapshots, a worklist and a per-framework evidence pack.
Explore the feature →Audit and evidence
Up to three years of unified activity history with per-actor attribution - the record the 24, 72-hour and one-month reports rest on.
Explore the feature →App governance
Every third-party app and consent with publisher, reach and the person who let it in - the software half of the supply-chain article.
Explore the feature →
FAQ
Common questions.
Are we even in scope for NIS2?
Scope covers essential and important entities across 18 sectors, generally from 50 employees or 10 million euro turnover, with national transpositions deciding the edges. That call belongs to your counsel. The practical point: the measures NIS2 asks for are the ones a well-run tenant needs anyway, so measuring readiness costs you nothing even if the scoping answer turns out to be no.
Does this replace a lawyer or an auditor?
No. Whether an incident is significant, which national authority receives the report and how your sector transposition applies are calls for compliance counsel. What 1Security replaces is the weeks of evidence-gathering before those calls: counsel works from a measured, dated record instead of a questionnaire.
Do we need E5 licenses for this?
No. The readiness measurement, the retained history and the evidence pack run on the standard read-only connection and the licenses you already own. Where a specific remediation does need a premium Microsoft SKU, the product says so on the action itself instead of letting you find out mid-fix.
What about systems outside Microsoft 365?
We measure the Microsoft 365 side: identities, files, mail, apps, agents and the audit trail around them. For most office-work organisations that is where the majority of NIS2-relevant evidence lives, but OT networks and on-premises systems need their own evidence sources. The evidence pack is honest about what it covers.
How fast do we get the first readiness picture?
The same day the tenant is connected read-only. Readiness is computed from data the platform collects on its own, with deliberately conservative statuses - not evaluated never counts as a pass - so the first picture is one you can already show internally, and weekly snapshots start accumulating from there.
Walk into NIS2 scope with the answers already measured.
Connect read-only and the NIS2 requirement statuses, the worklist and the first evidence pack land the same day - before you have remediated anything at all.
Or keep answering NIS2 questionnaires from a binder.