NIS2 Directive

Article 21 wants measures. Article 23 wants speed.

NIS2 pulls the health sector into binding cybersecurity risk management, and the manufacture of medical devices sits in its annexes too. ELTON supplies the vulnerability handling measures and the incident answers, both on the directive's timelines. ELTON is an exploitability management platform, delivered as a managed program. Our team runs the testing continuously. You get the platform, the evidence, and a TestLink™ appliance, with no new headcount.

The directive

What NIS2 demands

NIS2 replaced the original NIS Directive with wider scope, named security measures, and harder deadlines. For medical device organizations, two articles do most of the work.

Article 21: risk management measures

Entities must take proportionate technical and organisational measures, and the article names the subjects: risk analysis, incident handling, supply chain security, security in development and maintenance, and vulnerability handling and disclosure.

Article 23: incident reporting

A significant incident triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The early warning already has to say whether malicious action is suspected, which is a technical question, not a legal one.

Health, squarely in scope

Hospitals and other health entities sit in the essential category, and manufacture of medical devices appears in the annexes as well. Where a supplier is not directly regulated, Article 21's supply chain measures reach it anyway, through customer contracts.

The ELTON mapping

Measures you can demonstrate, not describe

Auditors and hospital customers have stopped accepting a policy document as proof. ELTON turns the vulnerability handling measure into a running, documented process, where every claim traces to a test on the device.

Vulnerability handling that actually runs

A digital twin of each device, continuous discovery across hardware, firmware, software, web, mobile, and network, and AI verification of what is exploitable on the real product. The measure exists because it operates every day, not because a policy says it should.

An evidence trail an auditor can walk

Every finding and every dismissal is evidenced and scored, with VEX published in CycloneDX. When someone asks how vulnerability handling works here, you show the record: what was found, what was fixed, what was dismissed and why.

Answers inside the reporting window

ELTON supports verification in 4 hours, an early-warning determination in 24, and a full report in 72. That is the technical half Article 23 depends on: is it real, is it malicious, what is affected, what is the exposure.

Requirement to capability

Article 21 measures, Article 23 clock

One measure has to run continuously, one deadline arrives suddenly. The same platform covers both: the measure and the clock, mapped below to what ELTON produces.

NIS2 requirement → ELTON capabilityArticle 21: vulnerability handlinga named risk management measureTwin, discovery, verification, VEXrunning daily, evidenced for auditArticle 23 reporting clockELTON output0hsignificant incident24hearly warning72hnotification1 monthfinal report4hverified on device24hdetermination72hfull report72h+evidence for the final report
Vulnerability handling runs daily; when an incident lands, the evidence already exists.
Supply chain

Your customers' NIS2 becomes your questionnaire

Essential entities must manage supplier risk, so hospitals now ask device vendors for vulnerability handling evidence during procurement. A living, evidenced process answers the security questionnaire before it arrives, and answers it the same way every time.

Adjacent regimes

The same evidence, reused

The workflow that feeds Article 23 also feeds the CRA reporting regime and FDA 524B postmarket duties. One verified record, three filings. See EU MDR/CRAEU RED and FDA §524B.

Get started

Bring evidence to your next NIS2 conversation.

Start with one device. We stand up the twin, run continuous discovery and verification, and give you the record that answers auditors, customers, and the 24 hour clock.

Questions

Common questions about the NIS2 Directive.

What does NIS2 Article 21 require?

Article 21 requires proportionate technical and organisational measures, and it names the subjects: risk analysis, incident handling, supply chain security, security in development and maintenance, and vulnerability handling and disclosure. Auditors and hospital customers have stopped accepting a policy document as proof, so each measure has to be demonstrable.

What are the NIS2 incident reporting deadlines?

Article 23 sets three. A significant incident triggers an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month. The early warning already has to say whether malicious action is suspected, which is a technical question rather than a legal one.

Does NIS2 apply to medical device manufacturers?

Hospitals and other health entities sit in the essential category, and manufacture of medical devices appears in the NIS2 annexes as well. Where a supplier is not directly regulated, the Article 21 supply chain measures reach it anyway, through customer contracts.

Why are hospitals asking device vendors for NIS2 evidence?

Because essential entities must manage supplier risk, so procurement now asks device vendors for vulnerability handling evidence. A living, evidenced process answers the security questionnaire before it arrives, and answers it the same way every time. The record that satisfies an auditor satisfies the customer.

How do you evidence the vulnerability handling measure?

By running it, not describing it. ELTON keeps a digital twin of each device, runs continuous discovery across hardware, firmware, software, web, mobile and network, and verifies what is exploitable on the real product. Every finding and every dismissal is scored and evidenced, with VEX published in CycloneDX for an auditor to walk.

Exploitability management for medical devices. FDA §524B methodologyExploitability proven at runtime95% faster than legacy testing Book a Demo
Platform
OverviewAvoid FDA DeficienciesAvoid Consulting FeesDigital Twin TraceabilityAI PentestingExploitability VerificationVulnerability ChainingRemediation OptimizationRemote TestLink™Incident ResponseAutomated VEX & MetricsCVSSv4 Migration
Solutions
Postmarket SurveillanceIncident ResponseSecurity EngineeringRegulatory AffairsFDA §524BEU MDR/CRAEU REDNIS2IMDRF N60 / N73Japan MHLW
Why ELTON
Subscription TestingAI-NativeFDA ComplianceVerified ExploitabilityELTON vs. Legacy TestingThreat-Led AI PentestingMDDT MethodologyCredentialsDevice ModalitiesPricing
Resources
FDA Deficiency ListFDA Testing RequirementsFDA Cyber SOPs & TemplatesRemediation LibraryRegulatory GuidesWebinarsAI NewsletterThe End of Legacy TestingThe AI Vulnerability ExplosionSecurity AdvisoriesWhitepapersIntelligence & Blog
Company
AboutLeadershipCareersPartnershipsContact Meet ELTON