Skip to content

NIS2 / Full version

NIS2

NIS2 is Directive (EU) 2022/2555. Article 21 is the risk-management duty. Article 23 is the incident report. Neither article names SPF, DKIM, or DMARC.

Short answer

The two obligations

Article 21 is the risk-management duty for essential and important entities. Article 23 is how a significant incident is reported, and on what clocks.

Neither article names an email authentication record. A page on this site that treats DMARC as a NIS2 requirement would be adding a sentence the directive does not contain.

Where DNS shows up

DNS shows up in scope and in the implementing-act list, not as a mail record. Article 2 and Article 3 name DNS service providers. Article 21(5) names them again, with TLD name registries and a longer list of provider types, as subjects of Commission implementing acts.

The short pages on scope and on Article 21 quote those provisions. This page is only the map.