NIS2 Directive

Article 21 wants measures. Article 23 wants speed.

NIS2 pulls the health sector into binding cybersecurity risk management, and the manufacture of medical devices sits in its annexes too. ELTON supplies the vulnerability handling measures and the incident answers, both on the directive's timelines.

The directive

What NIS2 demands

NIS2 replaced the original NIS Directive with wider scope, named security measures, and harder deadlines. For medical device organizations, two articles do most of the work.

Article 21: risk management measures

Entities must take proportionate technical and organisational measures, and the article names the subjects: risk analysis, incident handling, supply chain security, security in development and maintenance, and vulnerability handling and disclosure.

Article 23: incident reporting

A significant incident triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The early warning already has to say whether malicious action is suspected, which is a technical question, not a legal one.

Health, squarely in scope

Hospitals and other health entities sit in the essential category, and manufacture of medical devices appears in the annexes as well. Where a supplier is not directly regulated, Article 21's supply chain measures reach it anyway, through customer contracts.

The ELTON mapping

Measures you can demonstrate, not describe

Auditors and hospital customers have stopped accepting a policy document as proof. ELTON turns the vulnerability handling measure into a running, documented process, where every claim traces to a test on the device.

Vulnerability handling that actually runs

A digital twin of each device, continuous discovery across hardware, firmware, software, web, mobile, and network, and AI verification of what is exploitable on the real product. The measure exists because it operates every day, not because a policy says it should.

An evidence trail an auditor can walk

Every finding and every dismissal is evidenced and scored, with VEX published in CycloneDX. When someone asks how vulnerability handling works here, you show the record: what was found, what was fixed, what was dismissed and why.

Answers inside the reporting window

ELTON supports verification in 4 hours, an early-warning determination in 24, and a full report in 72. That is the technical half Article 23 depends on: is it real, is it malicious, what is affected, what is the exposure.

Requirement to capability

Article 21 measures, Article 23 clock

One measure has to run continuously, one deadline arrives suddenly. The same platform covers both: the measure and the clock, mapped below to what ELTON produces.

NIS2 requirement → ELTON capabilityArticle 21: vulnerability handlinga named risk management measureTwin, discovery, verification, VEXrunning daily, evidenced for auditArticle 23 reporting clockELTON output0hsignificant incident24hearly warning72hnotification1 monthfinal report4hverified on device24hdetermination72hfull report72h+evidence for the final report
Vulnerability handling runs daily; when an incident lands, the evidence already exists.
Supply chain

Your customers' NIS2 becomes your questionnaire

Essential entities must manage supplier risk, so hospitals now ask device vendors for vulnerability handling evidence during procurement. A living, evidenced process answers the security questionnaire before it arrives, and answers it the same way every time.

Adjacent regimes

The same evidence, reused

The workflow that feeds Article 23 also feeds the CRA reporting regime and FDA 524B postmarket duties. One verified record, three filings. See EU MDR/CRAEU RED and FDA §524B.

Get started

Bring evidence to your next NIS2 conversation.

Start with one device. We stand up the twin, run continuous discovery and verification, and give you the record that answers auditors, customers, and the 24 hour clock.

Automate medical device vulnerability discovery and verification. FDA §524B methodologyExploitability proven on-device95% faster than legacy testing Book a Demo
Platform
Platform OverviewDigital TwinAutonomous TestingExploitability VerificationVulnerability GraphRemediation OptimizationELTON TestLink™Lifecycle & MetricsCVSSv4 Migration
Solutions
FDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Postmarket SurveillanceIncident Response
Why ELTON
Why ELTONPricing
Resources
Intelligence & BlogRegulatory GuidesWebinarsWhitepapers
Company
AboutLeadershipCareersContact Book a Demo