Try For Free
NIS2, Directive (EU) 2022/2555

Prove NIS2 control of your Microsoft 365 and AI estate

NIS2 makes management accountable for cybersecurity risk measures, and the agents, automations and workspaces in your Microsoft tenant sit inside that scope while most stay in no asset register.

The Rencore Governance Operation dashboard: an Operation Compliance donut at 98 per cent with 441 high, 1,703 medium and 228 low violations beside 145.55k compliant items; a violations list topped by 198 Teams with very few owners, 73 mailboxes near storage quota and 70 Teams with many users; and six policy tiles with three-month trend charts, including Teams with private channels at 22, Teams with very few owners at 198 and Teams that use forbidden or misleading words at 78.

Trusted by the world’s leading organizations

  • MAPAL
  • bam
  • VDL
  • Wacker
  • Grundfos
  • Amgen
  • Lufthansa
  • thyssenkrupp
  • Sunrise
  • Pattern

What NIS2 requires

Member states had to transpose NIS2, Directive (EU) 2022/2555, by 17 October 2024. Four of its duties land on the Microsoft estate, on asset management and accountability rather than perimeter security:

Art. 20

Management accountability

The board approves and oversees the risk measures, and can be held liable.

Art. 21(2)

Risk-management measures

Technical and organizational measures sized to the risk across the estate.

Art. 21(2)(i)

Asset and access control

Manage the assets, and who and which agents can reach them.

Art. 23

Incident reporting timelines

A 24-hour early warning, a 72-hour notification, a one-month final report.

Who it applies to

Applies to essential and important entities in the sectors its annexes list, across the EU and EEA, transposition deadline 17 October 2024.

Where the Microsoft estate breaks it

Most Microsoft tenants grow their fastest attack surface outside every security process, and NIS2’s minimum measures fail quietly inside it:

Ungoverned agents and automations

Any licensed user ships a Copilot agent or Power Platform flow with data access and no owner.

Access nobody re-reviews

Permissions pile up as people change roles, and the access-control policy stays on paper.

No register for business-built assets

Workspaces, apps and agents multiply while asset management covers servers and vendor software only.

External access accumulates

Guest accounts and sharing links widen a surface your incident reports will have to explain.

How Rencore maps to NIS2

Rencore inventories, governs and evidences the Microsoft slice of your NIS2 scope, from Copilot and AI agents to Power Platform and Microsoft 365 collaboration; it complements Defender, Entra and Purview rather than replacing them.

NIS2 Art. 21(2)(i)

Full-estate inventory, agents included

Every agent, app, automation and workspace in your tenant, with its owner and the data it can reach: the asset view your risk-management measures rest on.

A Rencore Governance Microsoft 365 dashboard: an inventory tile counting 1,150 users, 383 groups, 12 sensitivity labels, 13 subscriptions, 428 message centre messages and 77 apps; a compliance summary donut at 80 per cent with 973 high, 2,713 medium and 15 low violations; and three licence cost cards showing EUR 4,063 a month for unused licences, EUR 2,914 for disabled users and EUR 2,974 for external users.
NIS2 Art. 21(2)(i)

Access reviews on a schedule

Recertify who, including guests and agents, can reach each workspace, with a dated record of what was checked and revoked.

A Rencore Governance review named Review all Teams that sends a review to all teams and their responsible owners: a Summary panel listing the reviewed object Teams, a manual trigger, manual frequency and an archive action, beside a Metrics panel showing completion at 7 of 55 with a twelve-month completion trend chart.
NIS2 Art. 20

Ownership and lifecycle policies

Every asset carries an accountable owner, and orphaned agents and apps are flagged, reassigned or retired.

A Rencore Governance policy checking every Power Apps canvas app that has no owner and no co-owner: an insights panel counting 24 in total, up 9 or 60 per cent, beside a three-month trend chart of total, new and removed findings.
NIS2 Art. 32, 33

Reports and exportable evidence

Reports and exports, scheduled or on demand, so an authority request is answered with evidence instead of screenshots.

A Rencore Governance Microsoft 365 report card listing reports by title, value and trend: licences with unused seats at 17,945, licences assigned to inactive users at 1,435, users by type at 1,150, users by region at 1,150 and internal users at 941, each with a rising trend line.

Mapping at a glance

How each Rencore capability answers a specific article of NIS2.

  • Full-estate inventory Art. 21(2)(i)

    The asset view your risk-management measures rest on.

  • Access reviews Art. 21(2)(i)

    Recertify who and which agents can reach each workspace.

  • Ownership and lifecycle Art. 20

    A named owner for every asset, orphans retired.

  • Reports and evidence Art. 32, 33

    Hand authorities exports instead of screenshots.

Inventory, control and exportable evidence for your Microsoft estate.

No tool makes you NIS2-compliant on its own; that judgement stays with your entity and its national authority, on the evidence.

Trusted by security, IT, and platform leaders

Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.

  • With Rencore's scalable automation solutions, organizations can not only meet current challenges but also prepare themselves for future technological advancements.
    Case Study
    Philipp Widmer Philipp Widmer Head of Platform Services Universitätsspital Basel
  • 26% vs 3%

    Organizations that govern Microsoft 365 well realize significant Copilot value 26% of the time, versus 3% for those that do not.

    Gartner, 2025 Microsoft 365 Copilot Survey
  • As we continue to expand our cloud capabilities, the foundation laid by Rencore Governance will undoubtedly play a crucial role in ensuring that each step forward is taken with confidence, security, and compliance in mind.
    Case Study
    Claude Bisdorff Claude Bisdorff Head of IT Systems Ville de Luxembourg
  • 116%

    ROI from Microsoft 365 Copilot once the program is adopted and governed, in Forrester’s Total Economic Impact study.

    Forrester Total Economic Impact
  • I currently estimate that we save around €80k per year by freeing up our IT admin team to do the work that counts.
    Case Study
    Undisclosed Undisclosed Former Lead O365 Competence Center Royal BAM
  • 71%

    of enterprises name security and governance among their top challenges to deploying Microsoft 365 Copilot.

    Gartner
  • Rencore's centralized governance tool excelled at ensuring secure data in Microsoft 365 and minimizing the risk of unauthorized access.
    Case Study
    Greg Bowles Greg Bowles IT Operations Manager Specialist Risk Group
  • 150,000+

    AI agents in use at the average Fortune 500 company by 2028. Agent sprawl is the next sprawl.

    Gartner
  • With Rencore Governance we are able to reduce manual governance activities, improve our service quality and generate valuable insights across our Microsoft service stack.
    Undisclosed Undisclosed Head of AI & Process Automation Wacker Chemie AG

Frequently asked questions

Is a Copilot agent part of NIS2 asset management?
NIS2 requires cybersecurity risk-management measures to include asset management (Art. 21(2)(i)). A Copilot agent runs in your tenant and reads business data at the permissions granted to it, so it belongs in that asset scope, alongside the Power Platform flows and custom apps built the same way. An asset practice that cannot list your agents does not cover the risk Art. 21 is written for.
How does NIS2 relate to DORA?
Where a sector-specific EU act imposes cybersecurity and incident-reporting obligations at least equivalent to NIS2, that act applies instead (Art. 4). For financial entities that act is DORA, so banks, insurers and investment firms follow DORA rather than the corresponding NIS2 duties. The estate underneath is the same, which is why this page has a direct sibling for DORA.
What evidence do national authorities actually ask for?
Requests follow the articles: proof the management body approved and oversees the measures (Art. 20), the measures themselves (Art. 21(2)), and incident reports on the Art. 23 timelines, a 24-hour early warning, a 72-hour notification and a final report within one month. Authorities can require information and order audits (Art. 32 for essential entities, Art. 33 for important ones). Rencore exports the Microsoft-estate part of each as reports you can hand over.
Can managers be held personally liable under NIS2?
Yes. The management body approves the risk-management measures, oversees their implementation and can be held liable for infringements (Art. 20(1)), and for essential entities authorities can temporarily suspend managers from their duties (Art. 32(5)). Fines reach EUR 10 million or 2 percent of worldwide turnover (Art. 34). An accountability trail per asset is what turns that exposure into something a board can oversee.

See your estate the way an authority will

Start with the inventory: every agent, automation and workspace in your Microsoft tenant, with owners, access and the data sources they reach, ready to back your risk-management measures.

Rencore Governance inventory tile for Microsoft 365 counting 1,150 users, 380 groups, 12 sensitivity labels, 13 subscriptions, 527 service assignments, 428 message center messages, 77 apps, 6,918 user activities and 50 deleted users