What NIS2 requires
Member states had to transpose NIS2, Directive (EU) 2022/2555, by 17 October 2024. Four of its duties land on the Microsoft estate, on asset management and accountability rather than perimeter security:
Management accountability
The board approves and oversees the risk measures, and can be held liable.
Risk-management measures
Technical and organizational measures sized to the risk across the estate.
Asset and access control
Manage the assets, and who and which agents can reach them.
Incident reporting timelines
A 24-hour early warning, a 72-hour notification, a one-month final report.
Who it applies to
Applies to essential and important entities in the sectors its annexes list, across the EU and EEA, transposition deadline 17 October 2024.
Where the Microsoft estate breaks it
Most Microsoft tenants grow their fastest attack surface outside every security process, and NIS2’s minimum measures fail quietly inside it:
Ungoverned agents and automations
Any licensed user ships a Copilot agent or Power Platform flow with data access and no owner.
Access nobody re-reviews
Permissions pile up as people change roles, and the access-control policy stays on paper.
No register for business-built assets
Workspaces, apps and agents multiply while asset management covers servers and vendor software only.
External access accumulates
Guest accounts and sharing links widen a surface your incident reports will have to explain.
How Rencore maps to NIS2
Rencore inventories, governs and evidences the Microsoft slice of your NIS2 scope, from Copilot and AI agents to Power Platform and Microsoft 365 collaboration; it complements Defender, Entra and Purview rather than replacing them.
Full-estate inventory, agents included
Every agent, app, automation and workspace in your tenant, with its owner and the data it can reach: the asset view your risk-management measures rest on.

Access reviews on a schedule
Recertify who, including guests and agents, can reach each workspace, with a dated record of what was checked and revoked.

Ownership and lifecycle policies
Every asset carries an accountable owner, and orphaned agents and apps are flagged, reassigned or retired.

Reports and exportable evidence
Reports and exports, scheduled or on demand, so an authority request is answered with evidence instead of screenshots.
Mapping at a glance
How each Rencore capability answers a specific article of NIS2.
- Full-estate inventory Art. 21(2)(i)
The asset view your risk-management measures rest on.
- Access reviews Art. 21(2)(i)
Recertify who and which agents can reach each workspace.
- Ownership and lifecycle Art. 20
A named owner for every asset, orphans retired.
- Reports and evidence Art. 32, 33
Hand authorities exports instead of screenshots.
Inventory, control and exportable evidence for your Microsoft estate.
No tool makes you NIS2-compliant on its own; that judgement stays with your entity and its national authority, on the evidence.
Trusted by security, IT, and platform leaders
Security, IT, and platform leaders use Rencore to see their Microsoft estate, cut cost and risk, and roll out Copilot and agents on a governed foundation.
Frequently asked questions
Is a Copilot agent part of NIS2 asset management?
How does NIS2 relate to DORA?
What evidence do national authorities actually ask for?
Can managers be held personally liable under NIS2?
Related reading
The neighboring EU regulations converge on the same Microsoft inventory. These cover the obligations next door:



