Framework overlap

Does NIS2 Directive cover NIST SP 1800-32?

You hold NIS2 Directive and have been told to do NIST SP 1800-32. Here is how much overlaps, control by control.

36% of NIST SP 1800-32 you already have

NIS2 Directive already covers about 36% of NIST SP 1800-32, leaving 28 of 44 controls as genuinely new work.

Already covered 0 Likely covered 16 New work 28

No control in NIS2 Directive maps directly to one in NIST SP 1800-32. Everything counted as covered is covered because both map to the same third standard, which is what a crosswalk is, but it is an inference rather than a lookup.

What is genuinely new work

Nothing in NIS2 Directive reaches these. This is the list to scope.

DER-DE-01
Continuous Monitoring of DER Communications
DER-DE-02
Logging and Audit Trail Collection
DER-DE-03
Integrity Monitoring of DER Settings
DER-GV-01
DER Cybersecurity Governance
DER-GV-02
Supply Chain Risk Management for DER
DER-ID-01
DER Asset Inventory
DER-ID-02
Data Flow Mapping for DER
DER-ID-03
DER Threat and Risk Assessment
DER-PR-01
Authentication for DER Communications
DER-PR-02
Secure Configuration of DER Devices
DER-PR-03
Network Segmentation for DER Operations
DER-PR-04
Cryptographic Protection of DER Communications
DER-PR-05
Identity and Access Management for DER Operators
DER-PR-06
Secure Firmware Update Process
DER-RC-01
Recovery Planning for DER
DER-RC-02
Backup and Configuration Restoration
DER-RC-03
Lessons Learned and Continuous Improvement
DER-RS-01
Incident Response for DER
DER-RS-02
Isolation and Containment Procedures
DER-RS-03
Communication with External Stakeholders
NIST1800-32-01
Critical asset identification and inventory
NIST1800-32-03
Security governance structure
NIST1800-32-04
Roles and responsibilities for critical systems
NIST1800-32-06
Physical and logical access controls
NIST1800-32-10
Revocation of access procedures
NIST1800-32-15
Ports and services management
NIST1800-32-16
Incident response plan for operational disruptions
NIST1800-32-17
Recovery plan for critical systems
Show the 16 you already have
NIST1800-32-02
System security categorization
NIST1800-32-05
Security policy for operational technology
NIST1800-32-07
Personnel risk assessment
NIST1800-32-08
Electronic access perimeter management
NIST1800-32-09
Interactive remote access security
NIST1800-32-11
Security patch management for OT
NIST1800-32-12
Malware prevention for operational systems
NIST1800-32-13
Network security monitoring
NIST1800-32-14
System security hardening
NIST1800-32-18
Reporting obligations to authorities
NIST1800-32-19
Coordination with sector-specific agencies
NIST1800-32-20
Exercises and drills for OT incidents
NIST1800-32-21
Supply chain risk management for critical components
NIST1800-32-22
Configuration management for OT systems
NIST1800-32-23
Change management procedures
NIST1800-32-24
Vulnerability assessment for critical systems

How this is calculated

Already covered means a mapping runs from a control in NIS2 Directive to that control. Likely covered means no direct mapping exists but both frameworks map to the same control in a third standard. New work means neither. We keep those separate rather than adding them into one friendlier number, because blending them would present a two-hop inference as a verified fact.

Coverage is not symmetric. Run it the other way and you will get a different number; both are correct.

From 332,959 cross-framework control mappings across 723 frameworks, 531 of them verified against their source documents. It does not tell you that you are compliant: a mapped control means the two standards ask for the same thing, not that you have done it.

Try another pair ยท Today's edition