NIS2 Compliance with Microsoft 365: Mapping Article 21 to the Tools You Already Own
tiagoscarvalho.com
NIS2 stopped being a future problem this year. In Portugal, where I work, Decreto-Lei 125/2025 entered into force on 3 April 2026 and expanded the regulated population from the old NIS1 universe to several thousand public and private organisations: mid-sized manufacturers, municipalities, higher education, logistics, managed service providers and digital providers. Across the EU, most Member States have now transposed the directive, while enforcement action continues against the remaining laggards. The important point for IT teams is no longer whether NIS2 will arrive; it is that national implementation is now real, uneven, and already creating obligations in live organisations: thousands that never thought of themselves as "critical infrastructure" are suddenly in scope, staring at ten risk-management obligations and a 24-hour incident reporting clock. Here is the part the consultancy PDFs will not tell you plainly: if you run a reasonably managed Microsoft 365 tenant, you already own the tooling for most of Article 21. Not the governance, not the paperwork, not the reporting process, but the technical controls themselves are largely sitting in licences you already pay for, many of them switched off. This article is the mapping: each Article 21 measure to the Microsoft 365 capability that answers it, the honest list of what the tenant cannot solve, the 24/72-hour reporting reality, and a 90-day readiness plan for a lean team. One disclaimer before anything else: I am a Microsoft 365 architect, not a lawyer. Scope determination and legal interpretation belong with counsel and your national authority; this article covers the technical execution once you know you are in.
Does NIS2 apply to you? (The honest five-minute version)
Two questions decide most cases, and your lawyer decides the rest.
First: sector. The directive lists sectors of high criticality (energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, space) and other critical sectors (postal services, waste, chemicals, food, manufacturing of certain goods, digital providers, research). National transpositions refine these lists; Portugal's Decreto-Lei 125/2025 notably pulls in municipalities above a size threshold and higher education, which is how the regulated population jumped from about a thousand entities to several thousand.
Second: size. As a practical starting point, NIS2 generally captures medium-sized and larger entities in listed sectors, using the EU SME definition, which considers employee headcount together with financial thresholds. The exact classification test, sector-specific rules and exceptions must be confirmed against the applicable national law. Micro and small enterprises are generally out of direct scope, with exceptions for specific activities (trust services, public electronic communications and a few others) where size does not matter. Essential versus important entity status follows from sector and size, and determines supervision intensity and fine ceilings.
Then the asterisks that fill legal blogs: national law can designate entities regardless of size, groups and supply-chain positions complicate things, and if you sell into in-scope customers you will inherit obligations contractually whatever your own status. Which is why the honest version of "does it apply to you" ends the same way every time: check your national law, register with your authority if required (the CNCS in Portugal, with its own registration and deadlines), and get scope confirmed in writing by someone whose signature means something in court. Mine does not, and this section deliberately stops here.
The shape of the obligation: ten measures, one clock, personal accountability
Strip the directive to what an IT team must internalise and three things remain:
- Article 21: ten risk-management measure areas, from incident handling to cryptography to supply chain, implemented "appropriately and proportionately" to your size and risk. Proportionality is written into the text; a 120-person manufacturer is not expected to run a 24/7 SOC. It is expected to prove the basics run.
- Article 23: the reporting clock. Significant incidents trigger an early warning to the authority within 24 hours, an incident notification within 72 hours, and a final report within one month of that incident notification. National portals and details vary; the clock does not.
- Management accountability. Leadership must approve the measures, oversee their implementation, and can be held liable for failures; fines reach 10M EUR or 2% of global turnover for essential entities, 7M or 1.4% for important ones. NIS2 was written specifically so that cybersecurity could no longer be delegated into the IT basement and forgotten.
The Article 21 mapping: requirements to tools you already own
This is the table the consultancy decks charge for. Each Article 21 measure area, the Microsoft 365 capability that addresses it, and where I have already written the implementation guide. Licensing notes follow in their own section, because "you own it" depends on your SKU.
| Article 21 measure area | Microsoft 365 answer | Implementation guide on this blog |
|---|---|---|
| (a) Risk analysis & information system security policies | Secure Score as the technical posture tracker; Compliance Manager and a formal risk register for ownership, evidence and remediation tracking; documented configuration baselines | Tenant Health Scorecard, Secure Score: what matters |
| (b) Incident handling | Defender XDR detection and response; documented triage and containment procedures | IR Runbook: the first 60 minutes |
| (c) Business continuity, backup, crisis management | Microsoft 365 Backup (or third party) with tested restores; documented recovery objectives | M365 Backup decision guide |
| (d) Supply chain security | Guest and external access governance, cross-tenant access settings, app consent policies, vendor access reviews | External sharing policy, Guest lifecycle |
| (e) Security in acquisition, development, maintenance; vulnerability handling | Patch discipline via Intune / Autopatch; secure configuration profiles; workload identity hygiene for integrations | Autopatch, Workload identity hardening |
| (f) Assessing effectiveness of measures | Secure Score trend, periodic access reviews, restore tests, attack simulation results: recurring evidence that controls work | Security posture audit script |
| (g) Cyber hygiene practices and training | Attack simulation training (Defender for Office 365 P2); phishing-resistant guidance for users; documented onboarding security briefings | Phishing-resistant MFA rollout |
| (h) Cryptography and encryption policies | BitLocker via Intune; sensitivity labels with encryption; TLS enforcement, MTA-STS and DANE for mail in transit | Email authentication done right, Sensitivity labels setup |
| (i) HR security, access control, asset management | Joiner-mover-leaver discipline, PIM for privileged roles, access reviews, Intune as the asset inventory | Admin roles, PIM configuration |
| (j) MFA, secured communications, secured emergency systems | Conditional Access baseline with MFA everywhere, phishing-resistant methods for privileged users, break-glass procedures | CA baseline for SMBs |
The 24/72-hour reality
Article 23 is where NIS2 stops being a checklist and becomes a fire drill. A significant incident starts three timers: early warning to your authority within 24 hours of becoming aware, incident notification within 72 hours with an initial assessment, and a final report within one month of the 72-hour incident notification. Portugal routes this through the CNCS; every member state has its own portal and format, which is one more thing to know before the night you need it.
Split the requirement into its two halves, because they have different owners:
The half Microsoft 365 gives you
Detection and evidence. Defender XDR surfaces the incident and its timeline; the unified audit log in Purview preserves who did what and when; the incident graph gives you the blast radius your 72-hour notification must describe. If you have followed my first-60-minutes runbook, you already produce, as a by-product of good response, almost exactly the artefacts the notifications require. The technical muscle for Article 23 is the same muscle as good incident response; NIS2 just adds a regulator to the distribution list.
The half it cannot give you
The decision chain. Who decides an incident is "significant" under your national law's definition, at 02:00, with partial information? Who has the authority portal credentials? Who is the deputy when that person is on a beach? What does the 24-hour early warning template say when you barely know anything yet (the directive anticipates this; early warning is deliberately minimal)? None of this is a product. All of it must exist on paper, with names, before the first incident, because building a reporting process during an incident is how organisations miss statutory deadlines while actively working the breach.
What Microsoft 365 alone cannot solve
The vendor-flavoured NIS2 content stops at the mapping table. The audit finding starts here, so let us be honest about the gaps:
- Scope determination and registration. Deciding you are in scope, registering with your authority by its deadline, and classifying as essential or important: legal work, not tenant work.
- Governance and the paper layer. Article 21 asks for policies: approved, dated documents that management signed. A perfectly configured Conditional Access policy with no written access-control policy behind it is, to an auditor, half a control.
- Management accountability. The board approving risk measures and receiving reports is an organisational rhythm. The Copilot-style one-page reporting habit from my measurement guide transfers directly here: five numbers, quarterly, to people who sign things.
- Everything outside the tenant. The factory OT network, the on-premises ERP, physical access, the phone system. NIS2 scopes your services, not your Microsoft subscription. For many SMEs, the Microsoft 365 tenant represents a large part of the digital estate; the audit still covers 100% of what is in scope.
- Supplier contracts. Supply-chain security means security requirements in contracts and supplier assessments: procurement work that IT informs but does not own.
- The reporting process itself, as covered above. Named humans, rehearsed steps.
The evidence pack: what you show the auditor
Compliance is proved, not claimed. The recurring exports and records a lean team should accumulate, most of them one click or one script away:
- Conditional Access policy export (and the written access policy it implements), refreshed on change.
- Secure Score trend, monthly snapshot: the effectiveness-assessment evidence for measure (f).
- Intune device inventory and compliance report: asset management plus configuration control in one artefact (my compliance report script automates it).
- Unified audit log retention confirmation and a sample investigation: proof the logging measure is real.
- Backup restore test records, quarterly: the continuity measure, evidenced. A backup nobody restored is a belief, not a control.
- Access review completions (privileged roles and guests) with dates and outcomes.
- Training and simulation records: attack simulation results and the follow-up actions taken.
- The incident notification sheet and, in time, records of any real notifications with their timestamps against the 24/72 clock.
Microsoft's Compliance Manager includes an NIS2 assessment template that structures much of this; treat it as scaffolding for the evidence rather than the compliance itself, and validate its current coverage against your national requirements.
The 90-day readiness plan for a lean team
- Days 1 to 15: scope and paper. Legal confirms scope and entity class; register with the authority if required. Inventory which of the ten measure areas have written policies (expect: almost none) and start the two most urgent documents: access control and incident handling.
- Days 15 to 45: the technical gap sprint. Run the tenant against the mapping table above. Typical findings and fixes, in priority order: MFA gaps and the CA baseline; backup absent or untested; audit log retention defaults; PIM unused; asset inventory incomplete because half the fleet is not enrolled. Every one of these has a guide in the third column of the mapping table.
- Days 45 to 60: the reporting muscle. Build the notification sheet, brief the decision owners, and run one tabletop: a simulated Tuesday-morning ransomware note, walked through to a drafted (not sent) 24-hour early warning. Ninety minutes, once, buys you composure that no tooling can.
- Days 60 to 90: evidence and rhythm. Stand up the evidence pack as a recurring habit: monthly Secure Score snapshot, quarterly access reviews and restore test, the board's one-page report. Book the first management review meeting, because their accountability is the law's design, and their calendar is your proof of it.
Ninety days does not produce "NIS2 compliance": it produces a defensible position, a documented trajectory, and evidence that the organisation took its obligations seriously before anyone asked. In regulatory reality, that position is most of the battle.
The licensing reality, capability by capability
The mapping table said "tools you already own"; here is where that claim needs footnotes. By SKU, roughly:
- Business Premium covers more than people expect: Conditional Access and MFA, Intune, Defender for Business, Defender for Office 365 P1, BitLocker management, sensitivity labels fundamentals. A disciplined Business Premium tenant can evidence most of Article 21 proportionately, which is exactly what the directive asks of a mid-sized entity.
- The P2-tier gaps that matter for NIS2: PIM and access reviews need Entra ID P2 (or the ID Governance add-on); attack simulation training needs Defender for Office 365 P2; longer audit retention and richer eDiscovery live in higher Purview tiers. These map to measures (f), (g) and (i), and they are the usual first upgrades a NIS2 project justifies.
- Microsoft 365 Backup is pay-as-you-go regardless of SKU (my backup guide has the maths), and measure (c) does not care which product you use, only that restores work and are tested.
- Validate everything against current licensing pages: these pairings shift, and a compliance budget built on a blog table (mine included) deserves five minutes of confirmation.
The mistakes I am watching organisations make
- Waiting for someone to tell them they are in scope.The authority's first contact may be a deadline, not an invitation. Sector plus size takes an afternoon to check and a lawyer a week to confirm; do it in that order, now.
- Buying a compliance platform before configuring the tenant.A GRC tool documenting the absence of MFA is an expensive confession. Controls first, dashboards second.
- Treating NIS2 as an IT project.The law was written to make it a management obligation, with personal accountability. If the board has not seen it, the project has not started, whatever IT has configured.
- Confusing configured with evidenced.The auditor cannot see your good intentions, only your exports, policies and test records. Ten minutes of evidence discipline per control is the cheapest compliance work there is.
- Building the reporting process during the first incident.The 24-hour clock does not pause while you find out who has the portal password. One page, two names, one rehearsal.
- Gold-plating.Proportionality is in the directive's text. A 60-person firm buying a 24/7 SOC because a vendor said NIS2 demands it has been sold, not secured. Match measures to risk and size, and document the reasoning; that documentation is itself compliance.
- Ignoring it because you are "too small".Your largest customer's supply-chain questionnaire is NIS2 arriving by contract. The small firms that can answer well will quietly win deals from the ones that cannot.
NIS2 and Microsoft 365 FAQ
We are a 30-person company. Are we out of scope?
Probably out of direct scope, unless you operate in one of the always-in activities (trust services, public electronic communications and similar) or your national law designates you. But read the supply-chain measure again: your in-scope customers are obliged to push security requirements down to you, so NIS2 will likely reach you as questionnaires and contract clauses. The controls in the mapping table are the same either way; only the paperwork differs. And confirm scope with counsel, not with a blog.
Does using Microsoft 365 make us NIS2 compliant?
No product makes you compliant, and be suspicious of anything marketed that way. Microsoft 365 provides technical controls for most Article 21 measures; compliance is those controls configured, documented in approved policies, evidenced continuously, governed by accountable management, and wrapped in a working incident reporting process. The tenant is often the easier part; the harder part is governance, evidence, people and rehearsal.
What should we show an auditor from the tenant itself?
The evidence pack above: CA policy exports against a written access policy, Secure Score trend, Intune inventory and compliance, audit log configuration, restore test records, access review completions, training records. Compliance Manager's NIS2 template can structure the collection. The pattern the auditor wants is not perfection; it is a control, its policy, and its recurring evidence, ten times over.
Is Business Premium enough, or do we need E5?
For a proportionate mid-sized entity, a disciplined Business Premium tenant covers most technical measures; the usual justified upgrades are Entra ID P2 (PIM, access reviews) and Defender for Office 365 P2 (attack simulation), which map directly to specific Article 21 measures. Buy upgrades against named gaps, not against fear. An undocumented E5 tenant fails audits that a documented Business Premium tenant passes.
How does the 24-hour reporting work if we barely know anything yet?
By design, the early warning is minimal: essentially "something significant appears to be happening, here is what we know, suspected cause, cross-border indications if any". The fuller picture belongs to the 72-hour notification and the one-month final report. The trap is not the content; it is not having decided who sends it and where. Portugal's route is the CNCS; know your member state's portal before you need it at 02:00.
We are an MSP serving in-scope customers. What changes for us?
Two things. First, managed service providers are themselves a listed sector: check your own scope with counsel, because many MSPs are in, not adjacent. Second, your customers' supply-chain obligations make you their favourite questionnaire recipient; the MSPs that can hand over a clean security posture pack (much of it generated from the evidence list above, per tenant) will turn NIS2 from an annoyance into a differentiator. The tenants where you did the hygiene work years ago are about to pay for themselves.
- Directive (EU) 2022/2555 (NIS2), full text on EUR-Lex
- European Commission: NIS2 transposition status by member state
- ENISA: NIS2 Directive resources and technical guidance
- Decreto-Lei n.º 125/2025 (Portuguese transposition, in force 3 April 2026)
- CNCS: Diretiva NIS 2 (Portuguese national authority, NIS2 page)
- Microsoft Purview Compliance Manager assessment templates (including NIS2)
- Microsoft compliance offering: NIS2 Directive
Not sure where your Microsoft 365 tenant stands against NIS2 Article 21?
I review Microsoft 365 environments against the technical controls mapped in this article: Conditional Access, MFA, privileged access, endpoint management, audit, incident readiness, backup and evidence. You get a prioritised gap assessment, not a generic compliance checklist. The legal half belongs to your counsel; the execution half is a conversation away.
Talk to me