NIS2, Directive (EU) 2022/2555
NIS2 logging and incident detection support for Windows estates.
You cannot handle an incident you cannot see. DPLens collects Windows security telemetry and file changes, delivers them to your SIEM through outages, and comes with a software supply chain you can verify.
- Article 21
- Incident handling
- Business continuity
- Supply-chain security
In short
DPLens supports NIS2 logging and incident detection on Windows. NIS2 Article 21 requires essential and important entities to take appropriate cybersecurity risk-management measures, including incident handling, business continuity, supply-chain security and the use of cryptography. DPLens supports these by collecting and reliably delivering the logs and file-change events your detection depends on, over TLS, with a tamper-evident record of changes to the agent. Detection, response, reporting and governance stay with you.
This page relates DPLens features to NIS2 and the UK NIS Regulations as we read them. It is not legal advice. National transpositions differ; your counsel and competent authority decide what applies to you. DPLens Ltd holds no certification, and using DPLens does not confer one.
The directive
What NIS2 asks for
Article 21 lists the measures entities must cover, as a minimum, in proportion to their risk. The items most relevant to logging are paraphrased below.
Art. 21(2)(b)
Incident handling
Being able to detect, analyse and respond to incidents. In practice that rests on collecting the right logs and keeping them intact.
Art. 21(2)(c)
Business continuity
Backup management, disaster recovery and crisis management, so security functions keep working through disruption.
Art. 21(2)(d) and (e)
Supply chain and secure acquisition
Security in your relationships with suppliers, and in acquiring and maintaining systems, including vulnerability handling and disclosure.
Art. 21(2)(h)
Cryptography
Policies and procedures on the use of cryptography and, where appropriate, encryption.
Article 23 sets incident reporting stages to the CSIRT or competent authority, starting with an early warning within 24 hours of becoming aware of a significant incident. For certain digital-infrastructure and digital-service entities, Commission Implementing Regulation (EU) 2024/2690 adds more detailed technical requirements, including on monitoring and logging.
Control map
NIS2 mapping
| Requirement | How DPLens supports it | What you do |
|---|---|---|
| Art. 21(2)(b) Incident handling | Collects any Windows Event Log channel, log files, inbound syslog and NetFlow/IPFIX, and file-integrity changes, and delivers them to your SIEM; collection coverage shows sources producing nothing | Detection content, triage and response in your SIEM and SOC |
| Art. 21(2)(c) Business continuity | Per-destination disk cache, failover with failback, fan-out to a second destination; events counted, never dropped silently | Continuity plans and recovery testing for your logging platform |
| Art. 21(2)(d) Supply-chain security | Authenticode-signed releases, SHA-256 checksums, CycloneDX and SPDX SBOMs; no telemetry, no call-home and no vendor control plane | Supplier assessment and verifying each download before you deploy it |
| Art. 21(2)(e) Vulnerability handling and disclosure | Secure engineering, signed releases and a published vulnerability reporting address | Patch management: rolling out each fix, with DPLens Manager or your own tools |
| Art. 21(2)(h) Cryptography | TLS with certificate validation on by default; mutual TLS where the receiver requires it; secrets protected on the machine | Choosing TLS for each destination and managing the certificates |
| Art. 21(2)(i) Access control | Console reachable from the machine itself by default; remote access limited to the addresses you allow; sign-ins and failures recorded in the audit trail | Who holds the console password and administrator rights on hosts |
| Art. 23 Reporting | Delivers the host evidence an investigation and report draw on | Classifying and reporting incidents within the deadlines |
United Kingdom
The UK position
NIS2 is an EU directive and does not apply in the UK. UK organisations are covered by the NIS Regulations 2018, which apply to operators of essential services and relevant digital service providers. Many UK competent authorities assess against the National Cyber Security Centre's Cyber Assessment Framework, which includes security monitoring. The government has brought forward a Cyber Security and Resilience Bill to update the UK regime; check its current status. UK organisations with EU operations may also be in scope of NIS2 through those operations.
The DPLens capabilities on this page are the same in either regime: Windows Event Log collection, reliable delivery, file integrity monitoring and a verifiable supply chain, described in the Trust Centre.
How to do it
In the documentation
FAQ
Questions entities ask
Does NIS2 set a log retention period?
The directive itself does not set one general retention period for logs. National law, implementing acts for particular sectors and your own risk assessment may. You set retention in your SIEM or archive.
How does DPLens help with the 24-hour early warning?
Reporting starts with knowing an incident has happened, which depends on detection in your SIEM. DPLens delivers Windows events and file changes promptly and counts every drop, so any gap in visibility shows up straight away.
Can we verify DPLens as a supplier?
Each release is published with SHA-256 checksums, Authenticode signatures and SBOMs in CycloneDX and SPDX, and the agent checks its own signature at start-up and records the result in its audit trail.
See it on your own logs
Try DPLens on one Windows server before you talk to anyone.
Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.