Tackling NIS2: What Microsoft Purview can (and can't) do for you

NIS2 is no longer something you only prepare for. In many EU countries it has been turned into national law, and supervisory authorities are starting to use their powers. Germany is a good example. Let’s look at the Bundesamt für Sicherheit in der Informationstechnik (BSI) numbers:
- Around 29,500 organizations are expected to register.
- The legal deadline passed on 6 March 2026.
- By that date, around 11,500 had registered.
- By 30 June, the total had reached 17,729.
The BSI asked the remaining organizations to complete their registration by 31 July 2026. It also made clear that this was a temporary enforcement pause, not a new legal deadline. Organizations that missed the 6 March deadline were already not compliant.
That leaves around 12,000 organizations that hadn’t even completed the basic registration form, in a country where the supervisory authority can issue fines and start supervisory proceedings immediately after the deadline.
This does not stop in Germany. Belgium’s Centre for Cybersecurity Belgium (CCB) required NIS2 entities to register by 18 March 2025, while essential entities faced a later conformity evidence milestone on 18 April 2026. Italy’s Agenzia per la Cybersicurezza Nazionale (ACN) runs NIS2 as an annual cycle, with registration or renewal generally taking place between 1 January and 28 February. France shows the other extreme. The Agence nationale de la sécurité des systèmes d’information (ANSSI) is the French national cybersecurity authority. The Senate adopted the transposition bill in March 2025, and a parliamentary committee approved the text in September 2025, but it has still not reached a floor vote. On 8 July 2026, the European Commission referred France to the Court of Justice for failing to notify complete transposition measures. ANSSI published the Référentiel Cyber France in March 2026, but it remains a working document until the law passes.
There is one more development worth flagging. On 20 January 2026, the Commission proposed targeted amendments to NIS2 itself. So some countries are still transposing a text that is already being rewritten. Check the current position before you commit anything to a project plan.
We have not seen large fines yet, but the pattern feels very familiar from GDPR. First, authorities focus on registration and governance. Then they look at the actual security measures, and fines usually follow only for organizations that keep ignoring the rules. In other words, being early in the process does not mean you are out of risk.
Microsoft Purview can help with specific parts of NIS2 readiness, such as structuring a Microsoft 365 compliance assessment, collecting audit evidence, classifying sensitive data, supporting DLP investigations and detecting insider risk signals. Before we look at the tooling, let’s first look at the actual NIS2 requirements.
Are you in scope, and what must you do?
Before we look at what Microsoft Purview can do for you, two questions need answering: does NIS2 apply to you, and what does it actually ask for?
Are you in scope?
NIS2 uses two categories, essential entities and important entities. Your sector and the size of your organization decide which one applies to you. The following table provides more information:
| Category | Who | Supervision |
|---|---|---|
| Essential entities | Large organizations in the 11 highly critical sectors of Annex I. These include energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. In broad terms, this means 250+ employees or more than 50 million euro turnover. | Proactive. Audits and inspections without cause. |
| Important entities | Medium and large organizations across Annex I and Annex II that are not essential. Annex II adds postal services, waste management, chemicals, food, manufacturing, digital providers and research. | Reactive. Supervision follows evidence of a problem. |
The general size threshold is 50 or more employees, or annual turnover above 10 million euro. Some entities are in scope regardless of size, including DNS service providers, TLD registries, trust service providers and certain public administration bodies.
Be aware: financial organizations that fall under the Digital Operational Resilience Act (DORA) generally follow DORA for overlapping cybersecurity risk management and incident reporting rules, because NIS2 gives priority to sector-specific EU rules when those rules are at least equivalent in effect. This is the lex specialis principle.
What must you do?
The wording differs per country, but the obligations are broadly the same. Dutch readers will recognize them as registratieplicht, zorgplicht and meldplicht. In Germany, the same discussion is usually framed around Registrierungspflicht, Risikomanagementmaßnahmen and Meldepflicht.
Registration
Organizations must register with their national authority, providing details such as name, contact information, sector and the member states where they operate. This is a filing obligation with a deadline, and no tool will remind you.
Duty of care
Article 21 of NIS2 sets out ten minimum measures. These include risk analysis and security policies, incident handling, business continuity and crisis management, supply chain security, secure acquisition and development, checks to see whether measures work, cyber hygiene and training, cryptography and encryption, human resources security and access control, and multifactor authentication.
Do you notice what this list is mostly about? It is a cybersecurity list, not a data governance list.
Incident reporting
Once you become aware of a significant incident, the reporting deadlines start to run.
| Deadline | What you must submit |
|---|---|
| 24 hours | Early warning to your CSIRT and competent authority |
| 72 hours | Incident notification including an initial assessment of severity and impact |
| 1 month | Final report describing the incident, its root cause and the mitigation applied |
Twenty-four hours isn’t very long. This is the part of NIS2 most likely to fail in practice, because it depends on detection, escalation and a named person knowing what to do. Each member state routes this differently, through its own CSIRT, portal or form. Find out which route applies to your organization before you need it.
Managing NIS2 with Microsoft Purview
Let’s be clear about where Purview fits within NIS2. NIS2 is a cybersecurity directive. Purview is a data security and governance toolset. Those areas overlap, but they are not the same. Much of Article 21 is covered by Microsoft Defender, Microsoft Sentinel, Microsoft Entra and Microsoft Intune rather than by Purview. That said, four Purview capabilities are incredibly helpful for your organization.
Compliance Manager: the NIS2 assessment template
Compliance Manager includes a dedicated NIS2 assessment template. It maps the directive’s requirements to technical and organizational measures in Microsoft 365. This is a useful starting point because it turns a long and extensive directive into a list of controls, owners and evidence.
Setting it up works exactly like the EU AI Act assessment we walked through in Compliance Manager. The regulation is available in the Compliance Manager:

Be aware: the NIS2 template is a premium regulation template. Organizations with an E5 license can choose up to three premium templates at no extra cost.
After clicking on the regulation, you see an overview of all the controls:

Audit: the evidence behind your 72-hour report
Your incident notification has to describe what happened and how serious the impact was. The unified audit log is where that evidence lives: who accessed what, when, and from where.
We flagged the same warning in our EU AI Act article: audit retention is often shorter than people think, and changing the setting does not bring back records that have already expired. If an investigation needs older records, those records may be gone.

Sensitivity labels and DLP: knowing what was actually exposed
During an incident, one of the first questions is going to be: what data was actually exposed? Not how many files, but what kind of files. That answer decides how severe your NIS2 report has to be, and whether you also need to start the GDPR data breach reporting process.
Sensitivity labels give you the first half of the answer. They show how sensitive a file is, and where those labelled files live in your Microsoft 365 environment. For example:

There is a second benefit that matters more during an incident than most people would expect. Sensitivity labels can apply encryption, and the encryption stays with the file. If an attacker steals a labelled and encrypted file, they have the file, but the content is protected.
That materially changes your impact assessment. In a 72-hour notification, there is a big difference between “the file was stolen” and “the file was stolen, but the content was still encrypted.”
DLP gives you the second half: what actually happened after a matched DLP rule. The activity explorer shows every DLP rule match, and the detail pane tells you the name of the policy, which sensitive information type, and where the activity took place. For example:

Insider Risk Management: the threat from inside
Article 21 covers human resources security and access control. Insider Risk Management detects the patterns that precede an internal incident, such as mass downloads before a resignation. Microsoft Purview contains Insider Risk Management with a series of useful policies. For example:

Be aware: in our experience, relatively few organizations are working with Microsoft Purview Insider Risk Management. If that is your situation, the human resources and access control measures in Article 21 still apply. You will be answering them with employee access lifecycle processes, access reviews and Conditional Access instead.
The limitations of Microsoft Purview
This is where the difference between tooling and compliance becomes really crucial. Microsoft Purview can support parts of NIS2, especially around data protection, evidence and reporting. But this section shows why it cannot carry the full obligation. Most of Article 21 sits in broader cybersecurity controls, your NIS2 scope is wider than Microsoft 365, and several requirements depend on ownership, process and evidence outside the tenant.
Most of Article 21 lives outside Purview
Multifactor authentication is part of Microsoft Entra. Endpoints are managed with Intune and Defender. Network segmentation, vulnerability management and threat detection are mostly handled through Defender and Sentinel. Backup and disaster recovery sit in your wider infrastructure. Purview helps with data protection, not with all ten measures.
Be aware: if a vendor tells you one product delivers NIS2 compliance, ask which of the ten Article 21 measures it actually covers. The answer can’t be all of them.
The same caution applies to certifications. Many organizations assume an ISO 27001 certificate settles the question. France makes the gap measurable: ANSSI has stated that ISO 27001 does not automatically imply NIS2 compliance, and that on its own it covers only 2 of the 20 objectives in the French framework. A certificate is useful evidence for part of the work. It is not the work.
The Compliance Manager assessment only covers Microsoft 365
This is the limitation that matters most. The NIS2 template assesses your Microsoft 365 configuration. Your NIS2 scope is your whole organization. That may include the factory floor, the OT network, the supplier portal and the server nobody has patched since 2019.
A green NIS2 assessment in Compliance Manager tells you that part of your Microsoft environment is well configured. It doesn’t say much about the rest of your estate, and that is where many incidents begin.
You can see the boundary when you create the assessment. For example:

It will not tell you what you have
Article 21 starts with a risk analysis. You cannot analyse risk across systems you have not listed. Purview can tell you a lot about data. It will not give you a full register of all SharePoint sites, Teams, Power Platform environments and applications, who owns each one, and which ones are no longer used.
The organizational obligations are yours
Four obligations sit entirely outside any product. They are the ones most likely to be forgotten, because none of them look like security work:
- Registration: a filing obligation with the national authority. Nothing in your tenant will remind you.
- Board training: Article 20 obliges members of management bodies to follow training. That is a calendar item, not a configuration.
- Supplier assessment: you must assess and document the cyber risks of your suppliers. That is a procurement and contracting process.
- Incident reporting: Purview and Defender produce the evidence. Submitting it to the right CSIRT within 24 hours is a runbook with names in it.
Business case & scenarios for NIS2
One of the challenges with NIS2 is making a strong business case for the people who need to fund your NIS2 project. “The law says so” is not always enough to unlock budget. A stronger business case shows that NIS2 is not only about avoiding fines. It is also about management responsibility, customer trust and being ready when the first incident happens.
Two articles do most of the work in these conversations. Article 20 puts accountability on management bodies. Article 21 sets out the measures themselves. We covered both earlier; here is why they matter to the people holding the budget.
Management can no longer treat cyber risk as an IT issue
Organizations face fines of up to 10 million euro or 2% of worldwide annual turnover, whichever is higher. Important entities face fines of up to 7 million euro or 1.4%. Those numbers matter, but Article 20 is what changes the boardroom conversation. Management must approve the cybersecurity measures, oversee whether they work and follow training themselves. That makes NIS2 a governance topic, not only a security project.
Your customers may ask before the regulator does
NIS2 also looks at supply chain risk. Organizations in scope must understand and manage the cyber risks of their suppliers. That means your customers may ask for evidence, even if your own organization is not directly covered by NIS2.
For many suppliers, the first NIS2 moment will not be a letter from a regulator. It will be a customer questionnaire, supplier assessment or security review asking about incident response, access control, backup testing, supplier risk and security monitoring. Organizations that can answer with evidence will move faster. Organizations that cannot may slow down sales, renewals or procurement.
Incident reporting needs to work before the incident happens
NIS2 gives organizations very little time once a significant incident is known. An early warning may be due within 24 hours, followed by a detailed notification within 72 hours. That can’t be the moment you need to find out who owns the process, which authority to contact, whether your logs still exist, or who is available outside office hours.
These three scenarios show that NIS2 is about more than passing an audit. Together, they give you a stronger case for funding the work: management accountability, customer trust and incident readiness.
Adoption & education
NIS2 is a bit unusual because training is not optional. Article 20 requires management to complete a training course. Article 21 also requires cyber hygiene practices and cybersecurity training as part of the risk management measures.
We advise organizing this in two tracks. For staff, use phishing simulations, training campaigns and learning paths already available in Microsoft 365. For management, arrange a proper NIS2-focused training course and record the attendance. This record is evidence for an obligation that applies to them personally.
Microsoft provides several useful resources for the staff training track. They do not replace formal NIS2 training for management bodies, and they are not a complete NIS2 adoption programme. They are useful building blocks for the Article 21 requirement around cyber hygiene and cybersecurity training, especially because they help you show who was assigned a training course, who completed it and where a follow-up is needed. Here’s an overview of useful resources:
- Attack Simulation Training
- Training campaigns
- Training modules and notifications
- Microsoft Learn security fundamentals
- Microsoft Security adoption resources
Be aware: do not confuse Microsoft training resources with full NIS2 readiness. They help with education, awareness and evidence, but management accountability, board training, supplier governance and incident reporting still need an organizational programme around them.
A note from Rencore
Article 21 starts with a risk analysis, and the section above already made the point: you cannot analyse risk across systems you have not listed. That gap is not a Purview problem specifically. It is a Microsoft 365 problem. Native tooling tells you about data. It does not hand you a register of every site, team, group and app, who owns it, and whether anyone still uses it.
This is deliberately where Rencore sits next to Purview rather than in front of it. Purview classifies and protects the data. Rencore builds and keeps current the inventory Article 21’s risk analysis depends on: every SharePoint site, Team, Power App, Flow, group and user, with usage, health and lifecycle status attached, so “who owns this and is it still active” has an answer instead of a search party. Access and sharing configurations are checked against the policies you switch on, so oversharing and orphaned sites surface before an auditor or an incident finds them for you.
Be clear about what this does and does not solve. It will not register you with your national authority, sit your management board through Article 20 training, or write your 24-hour incident runbook. Those stay organizational work, exactly as the rest of this article argues. What it does is give you the register Article 21’s risk analysis assumes you already have, and an answer to “who owns each one, and which ones are no longer used” that doesn’t depend on someone remembering.
Conclusion
NIS2 is no longer a future topic. Across the EU, it is becoming national law, registration deadlines are passing, and supervisory authorities are moving from preparation to enforcement. Tens of thousands of organizations are directly in scope, and many more will feel the impact through customer questionnaires, supplier assessments and contract requirements.
Microsoft Purview gives you a useful starting point. Purview Compliance Manager helps you structure a NIS2 assessment for Microsoft 365, Purview Audit gives you evidence for incident reports, and sensitivity labels, DLP and Insider Risk Management support parts of Article 21. That is valuable, but it is not the same as NIS2 compliance.
The bigger work sits around the tooling. You need management ownership under Article 20, cybersecurity risk management measures under Article 21, a working incident reporting process, supplier governance, training records and an inventory of the systems and services that are actually in scope. Your Microsoft 365 tenant is only part of that picture. We are here to help, and we strongly encourage you to follow these steps:
- Confirm whether you are in scope under your national law. Start with sector and size, but check the local implementation rather than relying only on the directive.
- Register with your national authority. This is a legal obligation with a deadline, not a technical configuration.
- Build a register of the services, systems, suppliers and owners that are actually in scope. Article 21 starts with risk analysis, and risk analysis starts with knowing what you run.
- Create the NIS2 assessment in Compliance Manager. Use it to understand where Microsoft 365 helps and where you still need additional controls, owners and evidence.
- Check your audit retention. Your incident evidence is only available for as long as your retention allows.
- Write and test the 24-hour incident runbook, with names. Twenty-four hours is short, especially outside office hours.
- Arrange and document cybersecurity training courses for management and staff. Under NIS2, training is part of the obligation, and attendance records become evidence.
Start with Purview, but do not stop there. NIS2 readiness is an organization-wide responsibility.
Last updated 10 September 2026




.png)