CROSSWALKS

GAISSF to NIS2 Crosswalk

Public crosswalk publication mapping GAISSF v1.0 to NIS2, with scope, method, limitations and traceability.

1. Executive Summary

CRO-029 maps all 59 GAISSF v1.0 controls to material provisions of Directive (EU) 2022/2555. The analysis contains 115 forward mapping records and a reverse register for all 46 articles.

The strongest operational alignment is with Article 20 governance, Article 21 cybersecurity risk-management measures, Article 22 supply-chain risk assessment and Article 23 reporting obligations. GAISSF supplies control and evidence structures; it does not determine legal scope, entity classification, jurisdiction, reporting deadlines or national supervisory requirements.

2. Purpose and Intended Use

  • Support NIS2 readiness and gap analysis.

  • Reuse GAISSF control evidence in national NIS2 programmes.

  • Identify legal, procedural and country-specific work beyond GAISSF.

  • Support internal assurance without asserting regulatory compliance.

4. Scope

The crosswalk covers all GAISSF controls and all NIS2 articles. Entity-facing technical and governance provisions receive substantive mappings. Member State cooperation, institutional, enforcement and final provisions are retained in the reverse register and classified as outside GAISSF scope where appropriate.

5. Mapping Methodology

Each mapping compares intended outcome, actor, lifecycle scope, evidence expectation and normative character. Similar terminology is insufficient. Relationship strength and confidence are assigned independently. Composite support is recorded where several GAISSF controls jointly support one article.

6. Key Findings

Governance

D6 and selected D8 controls support management oversight, approval, auditability and accountability under Article 20.

Risk management

D1–D7 and D9 controls provide extensive technical and operational support for Article 21, particularly incident handling, continuity, supply-chain security, access control, integrity and monitoring.

Reporting

GAISSF incident controls support detection and evidence, but Article 23 notification thresholds, 24-hour early warning, 72-hour incident notification, final reporting and national channels require separate procedures.

Supervision

GAISSF evidence may support audits and inspections, but regulator powers, fines and liability are not framework outcomes.

7. NIS2 Article Coverage Register

Article Title Chapter Mapped controls Coverage Residual gap
1 Subject matter Chapter I — General provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
2 Scope Chapter I — General provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
3 Essential and important entities Chapter I — General provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
4 Sector-specific Union legal acts Chapter I — General provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
5 Minimum harmonisation Chapter I — General provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
6 Definitions Chapter I — General provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
7 National cybersecurity strategy Chapter II — Coordinated cybersecurity frameworks 2 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
8 Competent authorities and single points of contact Chapter II — Coordinated cybersecurity frameworks 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
9 National cyber crisis management frameworks Chapter II — Coordinated cybersecurity frameworks 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
10 Computer security incident response teams (CSIRTs) Chapter II — Coordinated cybersecurity frameworks 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
11 Requirements, technical capabilities and tasks of CSIRTs Chapter II — Coordinated cybersecurity frameworks 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
12 Cooperation at national level Chapter II — Coordinated cybersecurity frameworks 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
13 Cooperation Group Chapter III — Cooperation 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
14 CSIRTs network Chapter III — Cooperation 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
15 European cyber crisis liaison organisation network (EU-CyCLONe) Chapter III — Cooperation 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
16 Report on the state of cybersecurity in the Union Chapter III — Cooperation 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
17 Peer reviews Chapter III — Cooperation 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
18 Mutual assistance Chapter III — Cooperation 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
19 Union-level coordinated security risk assessments of critical supply chains Chapter III — Cooperation 3 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
20 Governance Chapter IV — Risk management and reporting 10 Substantially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
21 Cybersecurity risk-management measures Chapter IV — Risk management and reporting 47 Substantially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
22 Coordinated security risk assessments of critical supply chains Chapter IV — Risk management and reporting 7 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
23 Reporting obligations Chapter IV — Risk management and reporting 5 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
24 Use of European cybersecurity certification schemes Chapter IV — Risk management and reporting 6 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
25 Standardisation Chapter IV — Risk management and reporting 6 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
26 Jurisdiction and territoriality Chapter IV — Risk management and reporting 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
27 Registry of entities Chapter IV — Risk management and reporting 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
28 Domain name registration data Chapter IV — Risk management and reporting 0 Not Addressed This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
29 Cybersecurity information-sharing arrangements Chapter IV — Risk management and reporting 5 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
30 Voluntary notification of relevant information Chapter IV — Risk management and reporting 4 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
31 General aspects concerning supervision and enforcement Chapter VII — Supervision and enforcement 9 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
32 Supervisory and enforcement measures in relation to essential entities Chapter VII — Supervision and enforcement 7 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
33 Supervisory and enforcement measures in relation to important entities Chapter VII — Supervision and enforcement 4 Partially Addressed GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance.
34 General conditions for imposing administrative fines Chapter VII — Supervision and enforcement 0 Not Addressed This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
35 Infringements entailing a personal data breach Chapter VII — Supervision and enforcement 0 Not Addressed This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
36 Penalties Chapter VII — Supervision and enforcement 0 Not Addressed This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
37 Delegation of power Chapter VII — Supervision and enforcement 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
38 Exercise of the delegation Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
39 Committee procedure Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
40 Review Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
41 Transposition Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
42 Amendment of Regulation (EU) No 910/2014 Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
43 Amendment of Directive (EU) 2018/1972 Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
44 Repeal Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
45 Entry into force Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.
46 Addressees Chapter VIII — Delegated, implementing and final provisions 0 Outside Scope This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls.

8. Control-to-Article Mapping Register

Controlled Publication. The table below shows a representative sample (6 of 115 total records). The complete control-by-control mapping register — full requirement-level traceability, evidence guidance and machine-readable export — is a Controlled Publication. Contact ODA3 Institute for access.
Record GAISSF control NIS2 article Relationship Confidence Rationale Residual gap
CRO-029-MAP-0001 D1-CTL-01 — Dataset Provenance & Poisoning Prevention Art. 21 — Cybersecurity risk-management measures SP High Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification.
CRO-029-MAP-0002 D1-CTL-01 — Dataset Provenance & Poisoning Prevention Art. 24 — Use of European cybersecurity certification schemes S Medium May support use of certification, standards and technical specifications contemplated by NIS2. NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification.
CRO-029-MAP-0003 D1-CTL-01 — Dataset Provenance & Poisoning Prevention Art. 25 — Standardisation S Medium May support use of certification, standards and technical specifications contemplated by NIS2. NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification.
CRO-029-MAP-0004 D1-CTL-02 — Model Extraction Resistance Art. 21 — Cybersecurity risk-management measures SP High Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification.
CRO-029-MAP-0005 D1-CTL-03 — Behavioral Drift Detection Art. 21 — Cybersecurity risk-management measures SP High Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification.
CRO-029-MAP-0006 D1-CTL-04 — Federated Learning Poisoning Prevention Art. 21 — Cybersecurity risk-management measures SP High Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification.

9. Limitations

  • This crosswalk is not legal advice.

  • NIS2 is a directive implemented through national law.

  • Scope depends on sector, size, entity type and Member State rules.

  • Mapping does not prove control implementation or operating effectiveness.

  • National authorities may impose additional procedures, evidence and deadlines.

  • The implementing regulation and future guidance require separate change control.

10. Notably Absent

  • No automatic NIS2 compliance claim

  • No determination that an organisation is an essential or important entity

  • No country-specific transposition analysis

  • No regulator endorsement

  • No proof of operating effectiveness

  • No automatic satisfaction of incident notification deadlines

11. Sources

Directive (EU) 2022/2555 — https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng

Commission Implementing Regulation (EU) 2024/2690 — https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj/eng

European Commission NIS2 transposition status — https://digital-strategy.ec.europa.eu/en/policies/nis-transposition

GAISSF-NOR-001 and GAISSF-NOR-004 v1.0.

© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute.