GAISSF to NIS2 Crosswalk
Public crosswalk publication mapping GAISSF v1.0 to NIS2, with scope, method, limitations and traceability.
1. Executive Summary
CRO-029 maps all 59 GAISSF v1.0 controls to material provisions of Directive (EU) 2022/2555. The analysis contains 115 forward mapping records and a reverse register for all 46 articles.
The strongest operational alignment is with Article 20 governance, Article 21 cybersecurity risk-management measures, Article 22 supply-chain risk assessment and Article 23 reporting obligations. GAISSF supplies control and evidence structures; it does not determine legal scope, entity classification, jurisdiction, reporting deadlines or national supervisory requirements.
2. Purpose and Intended Use
Support NIS2 readiness and gap analysis.
Reuse GAISSF control evidence in national NIS2 programmes.
Identify legal, procedural and country-specific work beyond GAISSF.
Support internal assurance without asserting regulatory compliance.
3. Legal and Source Baseline
Primary legal source: Directive (EU) 2022/2555, adopted 14 December 2022 and published in OJ L 333 on 27 December 2022. The transposition deadline was 17 October 2024. National transposition measures remain the operative source for entity-level legal obligations.
Commission Implementing Regulation (EU) 2024/2690 is a separate, directly applicable implementation layer for specified digital infrastructure, ICT service-management, digital provider and trust-service entities. It is not silently merged into the base article mapping.
4. Scope
The crosswalk covers all GAISSF controls and all NIS2 articles. Entity-facing technical and governance provisions receive substantive mappings. Member State cooperation, institutional, enforcement and final provisions are retained in the reverse register and classified as outside GAISSF scope where appropriate.
5. Mapping Methodology
Each mapping compares intended outcome, actor, lifecycle scope, evidence expectation and normative character. Similar terminology is insufficient. Relationship strength and confidence are assigned independently. Composite support is recorded where several GAISSF controls jointly support one article.
6. Key Findings
Governance
D6 and selected D8 controls support management oversight, approval, auditability and accountability under Article 20.
Risk management
D1–D7 and D9 controls provide extensive technical and operational support for Article 21, particularly incident handling, continuity, supply-chain security, access control, integrity and monitoring.
Reporting
GAISSF incident controls support detection and evidence, but Article 23 notification thresholds, 24-hour early warning, 72-hour incident notification, final reporting and national channels require separate procedures.
Supervision
GAISSF evidence may support audits and inspections, but regulator powers, fines and liability are not framework outcomes.
7. NIS2 Article Coverage Register
| Article | Title | Chapter | Mapped controls | Coverage | Residual gap |
|---|---|---|---|---|---|
| 1 | Subject matter | Chapter I — General provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 2 | Scope | Chapter I — General provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 3 | Essential and important entities | Chapter I — General provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 4 | Sector-specific Union legal acts | Chapter I — General provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 5 | Minimum harmonisation | Chapter I — General provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 6 | Definitions | Chapter I — General provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 7 | National cybersecurity strategy | Chapter II — Coordinated cybersecurity frameworks | 2 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 8 | Competent authorities and single points of contact | Chapter II — Coordinated cybersecurity frameworks | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 9 | National cyber crisis management frameworks | Chapter II — Coordinated cybersecurity frameworks | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 10 | Computer security incident response teams (CSIRTs) | Chapter II — Coordinated cybersecurity frameworks | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 11 | Requirements, technical capabilities and tasks of CSIRTs | Chapter II — Coordinated cybersecurity frameworks | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 12 | Cooperation at national level | Chapter II — Coordinated cybersecurity frameworks | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 13 | Cooperation Group | Chapter III — Cooperation | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 14 | CSIRTs network | Chapter III — Cooperation | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 15 | European cyber crisis liaison organisation network (EU-CyCLONe) | Chapter III — Cooperation | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 16 | Report on the state of cybersecurity in the Union | Chapter III — Cooperation | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 17 | Peer reviews | Chapter III — Cooperation | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 18 | Mutual assistance | Chapter III — Cooperation | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 19 | Union-level coordinated security risk assessments of critical supply chains | Chapter III — Cooperation | 3 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 20 | Governance | Chapter IV — Risk management and reporting | 10 | Substantially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 21 | Cybersecurity risk-management measures | Chapter IV — Risk management and reporting | 47 | Substantially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 22 | Coordinated security risk assessments of critical supply chains | Chapter IV — Risk management and reporting | 7 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 23 | Reporting obligations | Chapter IV — Risk management and reporting | 5 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 24 | Use of European cybersecurity certification schemes | Chapter IV — Risk management and reporting | 6 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 25 | Standardisation | Chapter IV — Risk management and reporting | 6 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 26 | Jurisdiction and territoriality | Chapter IV — Risk management and reporting | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 27 | Registry of entities | Chapter IV — Risk management and reporting | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 28 | Domain name registration data | Chapter IV — Risk management and reporting | 0 | Not Addressed | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 29 | Cybersecurity information-sharing arrangements | Chapter IV — Risk management and reporting | 5 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 30 | Voluntary notification of relevant information | Chapter IV — Risk management and reporting | 4 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 31 | General aspects concerning supervision and enforcement | Chapter VII — Supervision and enforcement | 9 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 32 | Supervisory and enforcement measures in relation to essential entities | Chapter VII — Supervision and enforcement | 7 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 33 | Supervisory and enforcement measures in relation to important entities | Chapter VII — Supervision and enforcement | 4 | Partially Addressed | GAISSF provides implementation controls, but legal applicability, national transposition details and regulator-facing procedures remain outside framework conformance. |
| 34 | General conditions for imposing administrative fines | Chapter VII — Supervision and enforcement | 0 | Not Addressed | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 35 | Infringements entailing a personal data breach | Chapter VII — Supervision and enforcement | 0 | Not Addressed | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 36 | Penalties | Chapter VII — Supervision and enforcement | 0 | Not Addressed | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 37 | Delegation of power | Chapter VII — Supervision and enforcement | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 38 | Exercise of the delegation | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 39 | Committee procedure | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 40 | Review | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 41 | Transposition | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 42 | Amendment of Regulation (EU) No 910/2014 | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 43 | Amendment of Directive (EU) 2018/1972 | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 44 | Repeal | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 45 | Entry into force | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
| 46 | Addressees | Chapter VIII — Delegated, implementing and final provisions | 0 | Outside Scope | This provision primarily concerns Member States, EU cooperation, jurisdiction, supervision, enforcement or legal procedure and is not established by GAISSF controls. |
8. Control-to-Article Mapping Register
| Record | GAISSF control | NIS2 article | Relationship | Confidence | Rationale | Residual gap |
|---|---|---|---|---|---|---|
| CRO-029-MAP-0001 | D1-CTL-01 — Dataset Provenance & Poisoning Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification. |
| CRO-029-MAP-0002 | D1-CTL-01 — Dataset Provenance & Poisoning Prevention | Art. 24 — Use of European cybersecurity certification schemes | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification. |
| CRO-029-MAP-0003 | D1-CTL-01 — Dataset Provenance & Poisoning Prevention | Art. 25 — Standardisation | S | Medium | May support use of certification, standards and technical specifications contemplated by NIS2. | NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification. |
| CRO-029-MAP-0004 | D1-CTL-02 — Model Extraction Resistance | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification. |
| CRO-029-MAP-0005 | D1-CTL-03 — Behavioral Drift Detection | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification. |
| CRO-029-MAP-0006 | D1-CTL-04 — Federated Learning Poisoning Prevention | Art. 21 — Cybersecurity risk-management measures | SP | High | Provides a technical, operational or organisational safeguard relevant to NIS2 risk-management measures. | NIS2 applicability, essential/important entity classification, national transposition, proportionality, reporting deadlines, competent-authority procedures and evidence of operating effectiveness require separate verification. |
9. Limitations
This crosswalk is not legal advice.
NIS2 is a directive implemented through national law.
Scope depends on sector, size, entity type and Member State rules.
Mapping does not prove control implementation or operating effectiveness.
National authorities may impose additional procedures, evidence and deadlines.
The implementing regulation and future guidance require separate change control.
10. Notably Absent
No automatic NIS2 compliance claim
No determination that an organisation is an essential or important entity
No country-specific transposition analysis
No regulator endorsement
No proof of operating effectiveness
No automatic satisfaction of incident notification deadlines
11. Sources
Directive (EU) 2022/2555 — https://eur-lex.europa.eu/eli/dir/2022/2555/oj/eng
Commission Implementing Regulation (EU) 2024/2690 — https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj/eng
European Commission NIS2 transposition status — https://digital-strategy.ec.europa.eu/en/policies/nis-transposition
GAISSF-NOR-001 and GAISSF-NOR-004 v1.0.
© 2026 ODA3 Pvt Ltd. Published by ODA3 Institute.