top of page

NIS2 compliance? Check out regulation assessment in Microsoft Purview

  • Writer: Vlad Johansen
    Vlad Johansen
  • Nov 5, 2024
  • 2 min read

Updated: Nov 6, 2024

Good evening everyone!


NIS2 have been a hot topic for some months now in EU and EEA countries. Many customers have users, data and other stuff in different cloud solutions like GWC, AWS and Microsoft cloud, but someone gets frustrated on how to start on their compliance journey. Are you Microsoft customer? Good for you. Then you need to check out Microsoft Purview's regulation assessment in Microsoft Purview. BUT, there is always BUT. This regulation assessments is only available for E5/G5/A5 customers. E5/G5/A5 customers can choose 3 premium templates for free. Customer with other licenses need to purchase them.


Ok, so to set up your regulation assessment go to compliance.microsoft.com or purview.microsoft.com. I suggest to use the new purview.microsoft.com portal, because the old one will be retired in 2024.


Go to Compliance Manager in the left menu and press Assessments

ree

As you can see, I have already added a NIS2 assessment


Now, press Add assessment button


ree

Press on Select regulation


ree

Search for NIS2 and choose NIS2 Directive (EU) 2022/2555... and press Save


ree

Create or choose existing group and press Next. You don't need to edit the assessment name

ree

Press on Select services button that this assessment will apply to and choose your service, in this case we only have an active Microsoft 365 environment, so we will select this. It's also possible to add another services by pressing Add new services, but I haven't tested this out.


Now press Next

ree

and Create assessment


ree

Fine, we have now added our assessment to Compliance Manager


ree

As you can see, you have different tabs here.


One of them is Your improvement actions, actions that your organization needs to do. And Microsoft's actions, which Microsoft need to fix. This assessment is not 100% ready to use right now, but I'm not sure when they will finish this one, but hopefully asap. Let's take a closer look.


Press on you NIS2 template


There is some stuff remaining from Microsoft's side with status Incomplete. You can check more details by pressing Microsoft actions button , but we will skip this now.


ree

By pressing on Controls we can take a closer look on all controls which NIS2 requires


ree

and all Articles in NIS2 directive under Control ID


ree

Now, let's check Your improvement actions button


ree

This is similar to Secure score actually


Let's check out Assign trainings and send reminders by pressing once on the line

ree

Nice? Yeah. Here you have a guide , same which we can find in Secure Score in Defender portal.

ree

This is actually a good start on your NIS2 journey, but remember one thing. By completing all your improvement actions will not make your organization NIS2 compliant. This is only to help you out with your Microsoft 365 environment.





Comments


Latest Blog Posts

© 2024-2025 need4.cloud

bottom of page