Standards and guidance
NIS2 & AI Agents: Cybersecurity Review Context
An EU directive concerning cybersecurity risk management and reporting for covered entities.
How to use this reference
Check the applicable national implementation and entity scope. Agent identities, access, incident handling and supplier dependencies can form part of the security review; this is not a conclusion about national legal compliance.
Evidence to discuss
Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.
Source and status
Directive (EU) 2022/2555, official text
Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.
Entity and cybersecurity scope discussion
These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.
- Has the responsible team established entity scope and applicable national requirements?
- Which agent access paths affect the systems covered by the review?
- How do access controls, findings and recovery records connect to the existing cybersecurity process?
Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.
Start with a clear scope
Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.