Zscaler & Zero Trust operations glossary · Governance & sovereignty

What is NIS2 in IT operations?

Definition

NIS2 in IT operations means the practical, ongoing implementation of the EU NIS2 Directive in day-to-day IT work, not just a one-off piece of documentation. It covers continuously maintained access controls, traceable configuration states and robust logs that can prove the required risk management measures at any time. The exact obligations, deadlines and thresholds follow from each country's national implementation of the Directive, so they need checking case by case. For Zscaler operations, NIS2 mainly means lived, verifiable operational practice, not a policy written once and left in a drawer.

NIS2 in IT operations in detail

NIS2 requires appropriate technical and organisational risk management measures, including access control, multi-factor authentication, incident detection, and the ability to detect and report security-relevant events promptly. For day-to-day Zscaler operations, that translates into concrete, recurring tasks: keeping access rights current, regularly checking rule sets for drift, and keeping logs in a state that is actually usable for analysis when it matters.

The boundary matters here: Zscaler itself provides building blocks such as threat protection and logging, but it does not replace a company's entire NIS2 programme, which also includes organisational processes and reporting chains. In Germany, the implementation has applied since 6 December 2025; registration and the three-stage incident report (24 hours, 72 hours, one month) run through the BSI.

Why NIS2 matters in Zscaler operations

Many companies underestimate how much NIS2 evidence depends on day-to-day operations: a policy written once does not answer whether access rights still match the documented state today. Auditors and regulators increasingly ask about the actual, current state, rather than the concept paper.

For companies with direct or indirect NIS2 obligations, for example as a supplier to an affected customer, Zscaler operations become a place where compliance either proves itself or does not.

Common sources of error

NIS2 in practice: what CentaurNexus contributes

Compliance Mapping from CentaurNexus starts exactly here: it automatically maps real signals from the Zscaler tenant to NIS2 controls and bundles them into an exportable, auditor-ready evidence pack. Policy Health Saga adds a summary of the configuration state as a score with a prioritised action plan and an NIS2-ready PDF report, and the append-only audit trail provides the evidence trail for every write action carried out through CentaurNexus. That way, the evidence shows the actual state instead of a statement of intent. The guide below has more on systematic configuration checking: Get more out of your Zscaler licence.

See in the live demo how the Policy Health Saga report supports NIS2 evidence.Watch the live demo

Related terms

Frequently asked questions about NIS2 in IT operations

What does NIS2 specifically require from IT operations?

NIS2 requires appropriate technical and organisational risk management measures, including access control, multi-factor authentication, incident detection and reporting, and evidence of their effectiveness. The exact individual obligations depend on the respective national implementation; in Germany, the NIS2 Implementation Act took effect on 6 December 2025.

Is Zscaler alone enough for NIS2 compliance?

Zscaler provides important building blocks such as threat protection, policy enforcement and logging, but it does not cover every NIS2 requirement, such as organisational processes, reporting chains or supply chain checks. NIS2 compliance is an overall concept to which Zscaler operations contribute one part.

What role does the audit trail play for NIS2?

A complete audit trail documents who made which security-relevant change, and when. That is exactly what auditors and regulators require as evidence of working controls: not the claim that a process exists, but proof that it is actually lived out day to day.

Does NIS2 also affect mid-sized companies?

Yes, often directly: medium and large companies in the sectors listed in Annexes I and II are covered, broadly from 50 employees or more than €10 million in annual revenue. Many more are indirectly affected, because customers with NIS2 obligations demand evidence from their suppliers.

How often must NIS2 evidence be updated?

NIS2 requires continuous risk management, not a one-off piece of evidence. In practice, that means recurring reviews of configuration, access rights and logs, ideally spread throughout the year rather than only at the annual audit.

Sources & further reading:

Note: CentaurNexus is an independent product of SourcingBlox GmbH and not an offering of Zscaler, Inc. Product and brand names belong to their respective owners. For the specific NIS2 legal position, the respective national implementation is authoritative.

Legal notice: This article reflects our assessment after careful research of the original sources. It does not replace legal advice. Please have a qualified lawyer review whether and how the legal position described applies to your company. As of 19 July 2026.