
This article was authored by Hristian Daskalov, Security Compliance Director at Evrotrust. Dr. Daskalov is a cybersecurity and digital policy expert with extensive experience in regulatory compliance, digital transformation, and EU technology policy. In addition to his role at Evrotrust, he is involved in several European innovation and cybersecurity initiatives and regularly works on bridging regulatory frameworks with practical technology implementation.
NIS2 (Directive (EU) 2022/2555) is rapidly moving from an upcoming regulatory framework to an operational reality across Europe. As of March 2026, the ECSO NIS2 Directive Transposition Tracker reports that 21 out of 27 EU Member States have successfully transposed NIS2 into national law, while the remaining countries are in advanced legislative and implementation stages.
A concrete example among the most recent transpositions is Bulgaria, where amendments to the Cybersecurity Act implementing NIS2 were promulgated on 13 February 2026, entering into force shortly thereafter.
Although NIS2 is an EU directive, regulatory alignment is extending beyond the EU itself. Neighboring non-EU jurisdictions, including countries in the Western Balkans, are increasingly aligning their cybersecurity frameworks with EU legislation and standards. This reflects the realities of interconnected supply chains, digital service ecosystems, and cross-border infrastructure.
For organizations operating across multiple jurisdictions, NIS2 therefore represents more than a compliance exercise; it is a shift toward consistent cybersecurity governance across Europe’s digital economy.
What Is NIS2?
The NIS2 Directive (Directive (EU) 2022/2555) is the EU’s updated framework for strengthening cybersecurity across critical and important sectors. It replaces the original NIS Directive (2016/1148) and significantly expands both the scope and enforcement mechanisms.
Its objectives include:
- Improving cybersecurity risk management across essential sectors
- Strengthening incident reporting obligations
- Increasing cooperation between Member States
- Enhancing supervisory and enforcement powers
- Ensuring accountability of management bodies
NIS2 also introduces stronger governance obligations, including requirements for organizations to implement appropriate technical, operational, and organizational cybersecurity measures.
These measures typically cover areas such as:
- Risk analysis and information security policies
- Incident handling procedures
- Business continuity and crisis management
- Supply chain security
- Access control and authentication mechanisms
- Monitoring, logging, and evidence preservation
While these requirements focus heavily on security controls, they also implicitly require organizations to maintain traceable and verifiable records demonstrating that these controls are implemented and functioning effectively.
Who Does NIS2 Apply To?
NIS2 significantly expands the scope of organizations covered compared to the original directive.
It introduces two main categories:
Essential entities
These include organizations operating in sectors considered critical for society and the economy, such as:
- Energy
- Transport
- Banking
- Financial market infrastructure
- Health
- Drinking water and wastewater
- Digital infrastructure
- Public administration
- Space
Essential entities are subject to stricter supervisory regimes and proactive oversight by national authorities.
Important entities
NIS2 also covers a broader group of important entities, including sectors such as:
- Digital providers
- Postal and courier services
- Waste management
- Chemicals
- Food production and processing
- Manufacturing of critical products
- Research organizations
Many medium and large organizations in these sectors may fall within scope if they meet certain size and activity thresholds.
This expansion means that thousands of additional organizations across Europe must now implement formal cybersecurity governance frameworks and be able to demonstrate compliance.
Beyond Incident Response: The Evidence Layer of NIS2

Many organizations initially approach NIS2 from the perspective of risk controls and incident reporting. While these areas are central, NIS2 also reinforces another critical dimension that is sometimes overlooked:
The ability to prove that security-critical actions were executed properly and under accountable decision-making.
In practice, organizations must be able to demonstrate:
- who approved a critical change
- when a security decision was taken
- how access to sensitive systems was granted
- whether incident response actions were properly recorded
For organizations operating across multiple jurisdictions, this becomes particularly important because supervisory practices, sector classifications, and enforcement approaches may differ across Member States.
The result is a growing need for high-integrity digital evidence and traceable governance processes.
Where Qualified Trust Services Add Practical Value
Qualified trust services under eIDAS can play an important role in strengthening this “evidence layer” of cybersecurity governance.
They help organizations secure and evidence key digital processes that sit at the intersection of cybersecurity, compliance, and operational governance, particularly where strong assurance and non-repudiation are required.
Typical high-impact use cases include:
Strong electronic identification and authentication
Secure identification of staff, administrators, and third parties accessing sensitive systems or approving security-relevant actions.
Qualified electronic signatures and seals
Legally robust signing of security-related documents such as:
- policies and procedures
- change approvals
- supplier onboarding documentation
- incident response decisions
- internal approvals and governance records
Qualified electronic timestamps
Anchoring logs, incident timelines, change windows, and evidence packages with tamper-resistant proof of time.
Tamper-evident archiving
Preserving evidence and documentation for:
- audits
- internal investigations
- supervisory authority reviews
- regulatory reporting
These mechanisms do not replace cybersecurity risk management measures. Instead, they strengthen the process integrity and evidentiary layer, helping organizations demonstrate that controls are not only documented, but executed and verifiable.
Reflecting this importance, NIS2 explicitly encourages Member States to promote the use of qualified trust services by essential and important entities.
Practical Next Steps for Essential and Important Entities
For organizations preparing for NIS2 compliance, a pragmatic starting point is to identify the digital processes where traceability and provability matter most.
Key areas to review for NIS2 compliance
1. Critical workflows requiring strong assurance
- approval chains
- privileged access management
- supplier onboarding
- incident response procedures
2. Security-relevant document governance
- policy approvals
- exception management
- change management documentation
- contractual security obligations
3. Logging and evidence integrity
- timestamping security logs
- maintaining tamper-evident records
- preserving investigation evidence
4. Governance and oversight
- internal control processes
- board-level approvals
- risk management documentation
Addressing these areas early helps organizations create audit-ready processes aligned with NIS2 governance expectations.
How Evrotrust Supports Organizations Across Markets
Evrotrust supports organizations across the EU, its neighboring countries, and beyond with qualified trust services that enable secure, traceable, and auditable electronic processes.
These services help organizations strengthen governance and operational resilience in multi-jurisdiction environments, where cybersecurity compliance must be demonstrable across different regulatory frameworks.
Evrotrust has recently confirmed compliance of its flagship qualified trust services through a surveillance audit performed by an accredited conformity assessment body against ETSI EN 319 401 v3.2.1.
From both a technical and legal perspective, ETSI EN 319 401 serves as the baseline policy and security standard for trust service providers. Its latest version explicitly supports NIS2-aligned security management and cybersecurity expectations, translating governance, risk management, incident handling, and continuity requirements into operational controls that are auditable within the QTSP environment.
Final Thoughts
As organizations across Europe adapt their cybersecurity governance to the NIS2 framework, the focus is shifting from policy documentation toward demonstrable operational resilience.
Qualified trust services can play a critical role in this transition by strengthening the integrity, traceability, and evidentiary value of key digital processes.
If your organization is updating its cybersecurity governance and core workflows in the context of NIS2, Evrotrust can help – reach out to our experts to assist you in identifying which qualified trust services best support your risk profile and operational needs.
With independently assessed operational maturity aligned to NIS2-relevant expectations, Evrotrust can support rapid operational rollout across jurisdictions, providing credible, audit-ready assurance that critical digital identity and transaction workflows are secure, traceable, and consistently controlled.
Frequently Asked Questions
Is NIS2 directly applicable in all EU countries?
No. NIS2 is a directive, meaning each EU Member State must transpose it into national law. While the core requirements are harmonized, the implementation and supervisory frameworks can vary between countries.
Does NIS2 only apply to large companies?
Not necessarily. While size thresholds are used in many cases, organizations may still fall within scope depending on sector classification, criticality, or national implementation rules.
What are the main obligations under NIS2?
Key obligations typically include:
- implementing cybersecurity risk management measures
- reporting significant incidents to authorities
- maintaining business continuity capabilities
- securing supply chains
- ensuring management accountability for cybersecurity
How do trust services relate to NIS2 compliance?
Trust services do not replace cybersecurity controls, but they can help organizations demonstrate compliance and accountability, particularly for approvals, logs, documentation, and audit trails.
Why is evidence and traceability becoming more important?
Regulators increasingly expect organizations to show how cybersecurity decisions were made and executed, not just that policies exist. Reliable digital evidence strengthens both internal governance and regulatory interactions.





