Standards and guidance

NIS2 & AI Agents: Cybersecurity Review Context

An EU directive concerning cybersecurity risk management and reporting for covered entities.

How to use this reference

Check the applicable national implementation and entity scope. Agent identities, access, incident handling and supplier dependencies can form part of the security review; this is not a conclusion about national legal compliance.

Evidence to discuss

Identify the system scope, control owner, implementation evidence, test results, exceptions and the reviewer responsible for acceptance. Requirements are mapped to the agreed source version; missing and untested controls remain visible.

Source and status

Directive (EU) 2022/2555, official text

Reference checked on 7 October 2026. This page is an engineering overview, not legal advice or a claim of accreditation, partnership or endorsement.

Entity and cybersecurity scope discussion

These are engineering discussion prompts, not a substitute for the source requirements or the appointed reviewer's criteria.

  • Has the responsible team established entity scope and applicable national requirements?
  • Which agent access paths affect the systems covered by the review?
  • How do access controls, findings and recovery records connect to the existing cybersecurity process?

Use the security review checklist to organise owners, test records and gaps. The assessment method explains how coverage limits are recorded.

Start with a clear scope

Tell us which systems, actions and review requirements are in scope. We will discuss the work, responsibilities and deliverables before you commit.