The NIS2 Directive affects tens of thousands of organisations across the EU and requires demonstrable management of risks, incidents, business continuity and supply-chain dependencies. For IT teams, this represents a complex operational obligation; for management, it is often a misunderstood regulation.
Tazilla bridges these two worlds – providing precise data for IT and clear decision-making insights for leadership. This article explains where Tazilla supports NIS2 compliance and where responsibility remains with organisational processes, people and other technologies.
1. Cybersecurity Risk Management (Article 21 NIS2)
NIS2 builds on one key pillar – an organisation must know its assets, threats and impacts, assign appropriate security controls and continuously monitor their effectiveness. This is a systematic process – not a one-off spreadsheet exercise.
What tazilla covers
The Risk Analysis module together with the Organisation, Assets, Threat Intelligence, Vulnerability Scanning and Compliance modules provides a comprehensive framework for risk management across the entire organisation.
It enables:
- precise asset inventory (hardware, software, data, processes, locations) and classification,
- use of predefined catalogues of threats, impacts and security controls,
- using the AI Risk Analysis Wizard to prepare risk assessments and propose assets, threats, impacts and security controls (Human in the Loop),
- automatic linking of risks to incidents, third parties or business continuity plans (BCP),
- using information from Vulnerability Scanning, Threat Intelligence and Honeypot to continuously update risk assessments,
- clear analytical dashboards and management reports that simplify decision-making and demonstration of compliance.
The result is an auditable proof that the organisation truly manages risks as required by Article 21 NIS2 and applicable national legislation.
What tazilla does not cover
Tazilla does not design security architecture (firewalls, EDR, SIEM) nor does it physically implement encryption, patching or network segmentation. However, it enables organisations to record these controls, link them to identified risks and document their implementation. The implementation of technical security controls therefore remains with the organisation and its suppliers.
2. Management Responsibility and Approvals (Article 20)
NIS2 shifts cybersecurity from “just IT” to an enterprise-wide responsibility. Management must understand risks, approve controls and demonstrably maintain security-related competence.
What tazilla covers
The platform helps organisations meet this obligation clearly and transparently by allowing them to:
- generate management risk reports summarising key risks, planned controls and related costs,
- record approvals, management decisions and remarks, creating a complete audit trail,
- record evidence of compliance with legislative requirements and monitor the organisation’s compliance level through the Compliance module,
- plan and track mandatory training for management and employees through the Tazilla Training module.
This helps management make informed decisions and demonstrate compliance with legislative requirements.
What tazilla does not cover
Tazilla cannot make decisions on behalf of management or ensure that recommendations are approved or implemented. Approving budgets, accepting risks, assigning internal responsibilities and making strategic decisions remain exclusively the responsibility of management.
3. Incidents and Mandatory Reporting (Article 23)
NIS2 requires organisations to report significant cybersecurity incidents to national authorities (e.g., CSIRT, NBÚ in Slovakia) within strict deadlines – an initial notification within 24 hours, updates within 72 hours, and a final report within one month. For many organisations, this is one of the most challenging obligations: incidents often arise unexpectedly and under pressure, and the team must ensure accurate and complete reporting while resolving the issue.
What tazilla covers
The Registers – Cybersecurity Events module enables:
- recording incidents, vulnerabilities and critical threats,
- assigning incidents to specific assets, services, employees or suppliers,
- recording response measures, incident timelines, management decisions and detailed descriptions,
- categorisation according to NBÚ rules,
- linking incidents to risk assessments, business continuity plans (BCP/DRP) and corrective actions,
- storing documentation (logs, evidence, analyses, correspondence).
This provides the organisation with the necessary information to quickly understand: What happened? What was affected? What are the impacts? Who handled the incident? Were all obligations met? Practically, this means that the CISO or responsible person can prepare required reports from already available data.
What tazilla does not cover
Tazilla does not automatically submit incident reports, as reporting to the relevant national authorities remains the organisation’s responsibility. The organisation is also responsible for determining whether an event qualifies as a significant cybersecurity incident and for submitting notifications within the deadlines required by law.
4. Business Continuity, Backup and Recovery
One of NIS2’s key requirements is ensuring continued operations even during disruptions – whether due to cyberattacks, technical failures or human error. Regulations therefore emphasise documented and tested Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP), including clear recovery parameters and responsibilities.
What tazilla covers
The Business Continuity Management module allows organisations to create, maintain and audit their preparedness documentation. It supports:
• creation and maintenance of BCP/DRP plans and their links to assets, services and responsible persons,
• setting RTO and RPO parameters, defining Recovery Strategy and linking them to individual assets and services,
• recording backup strategies including responsible persons and restoration tests,
• documenting and evaluating plan tests – often the weakest area during audits.
Tazilla helps organisations create and continuously maintain business continuity documentation and prepare evidence for internal and external audits.
What tazilla does not cover
Tazilla does not perform backups or data recovery, manage storage systems or replication, or provide crisis communication. It also does not decide when BCP or DRP plans should be activated. These activities remain the responsibility of the organisation and its IT teams. Tazilla records them, links them to risks and related information, and helps maintain a clear overview of the organisation’s preparedness.
5. Supplier Management and Supply Chain Risks
According to NIS2, suppliers pose one of the largest sources of risk – yet organisations frequently underestimate them. A supplier incident can have the same impact as one occurring directly in your infrastructure. NIS2 requires organisations to know, assess and continuously manage third-party risks.
What tazilla covers
The Third Parties and Contracts modules provide a unified environment for managing the supply chain and enable organisations to:
• maintain and categorise all suppliers, including their criticality,
• link suppliers to services, assets and responsible persons,
• perform third-party risk assessments, including the use of security questionnaires,
• store auditable SLA, contract and security requirement data,
• link supplier assessment results with the organisation’s risk analysis.
What tazilla does not cover
Tazilla does not enforce SLAs, verify suppliers’ technical security controls or perform security audits at supplier premises. These activities remain the responsibility of the organisation. Tazilla provides the tools to record, assess and demonstrate supply chain risk management.
6. Documentation, Policies and Audit Trail
NIS2 requires demonstrability – it is not enough to claim that processes exist. Organisations must present evidence that they are performed and regularly updated. Documentation and audit trails determine whether an organisation passes audits, inspections or incident investigations.
What tazilla covers
The Documentation and Compliance modules provide a structured and controlled environment for managing security documentation and evidence of compliance with legislative requirements:
• centralising directives, policies, records, audit logs and decisions,
• ensuring versioning and linkage to services, assets, risks and security controls,
• recording evidence of compliance with individual requirements and corrective actions and generating questionnaires and audit materials.
This enables faster preparation of evidence for auditors and regulators, with all relevant documents and supporting evidence connected and stored in a single system.
What tazilla does not cover
Tazilla does not ensure the quality or accuracy of internal policies, does not create them automatically, and does not replace legal experts or internal approval processes. It provides tools for documenting, managing and demonstrating compliance, while the creation, approval and maintenance of documentation remain the organisation’s responsibility.
7. Training, Cyber Hygiene and Awareness
NIS2 stresses that technology alone is insufficient. Organisations must demonstrate that their people know how to work securely and respond to incidents. Continuous awareness, training and security culture are key.
What tazilla covers
Tazilla provides a multi-layered approach to training and prevention:
- the Training module with eLearning courses in text or video format, final tests and AI-narrated content,
- management of the training catalogue, employee acknowledgements and records of completed training,
- dashboards and auditable records of completed training,
- Threat Intelligence, Vulnerability Scanning and Honeypot modules, which provide up-to-date information about cyber threats and support continuous security awareness.
These functionalities support better cyber hygiene and help organisations demonstrate compliance with employee training requirements.
What tazilla does not cover
Tazilla cannot build an organisation’s security culture on its own or guarantee that employees will apply the knowledge gained in practice. Training planning, internal communication and building security awareness remain the responsibility of the organisation.
8. Technical Security Controls (Critical but Outside Tazilla’s Scope)
NIS2 includes numerous requirements classified as “hard security” – technical controls implemented within IT infrastructure. These are essential and cannot be replaced by any GRC platform.
Tazilla does not cover hard security
Tazilla does not implement:
• firewalling, IDS/IPS, EDR/XDR, SIEM monitoring,
• email security (anti-spam, anti-phishing),
• DDoS protection, WAF,
• patch management,
• real-time operational and log monitoring,
• PKI, certificates, encryption or key management,
• physical security (access control, CCTV).
Tazilla can, however, record these controls, their implementation status, responsible persons and links to risks.
What Tazilla provides in this area (management perspective)
While not operating these technologies, Tazilla can:
• include them in the catalogue of security controls,
• record their implementation and status,
• assign responsible persons and budgets,
• link them to risks, impacts and assets,
• record evidence of their implementation and monitor their fulfilment through the Compliance module.
In practice, Tazilla provides management-level, auditable oversight of implemented security controls, while their design, implementation and operation remain the responsibility of the organisation.
Conclusion: Tazilla Makes NIS2 Achievable – But Not Automatic
The most common NIS2 failures remain the same:
organisations do not know whether they fall under NIS2, do not manage risks, ignore monitoring, lack continuity plans, and have no system for recording incidents or suppliers.
Tazilla addresses these issues in a single platform – clearly, comprehensively, auditably and in a way understood by both IT and management. It supports fulfilment of a substantial part of NIS2 requirements and creates a framework for long-term security management, rather than mere “checkbox compliance”.
