Spring til indhold

v1.0 · 19 May 2026

NIS2 Article 21 → Microsoft 365, complete implementation mapping

This document maps each of the 10 requirements in NIS2 Article 21 (subsection 2) to concrete Microsoft 365 features, licence tiers, configuration steps, and the audit evidence you need to be able to produce.

All 10 controls are open, with no sign-up and no email required.

Ansvarsfraskrivelse

This document is technical guidance, not legal advice. The mappings between NIS2 requirements and Microsoft 365 features are Licensly's assessment based on publicly available documentation. Always consult your own legal counsel and a certified Microsoft partner before making compliance decisions.

Control contents

Control 1

Policies for risk analysis and information security

A. Legal requirement

Member States shall ensure that essential and important entities take appropriate and proportionate technical, operational and organisational measures to manage the risks posed to the security of network and information systems... including (a) policies on risk analysis and information system security.

Directive text: Medlemsstaterne sikrer, at væsentlige og vigtige enheder træffer passende og forholdsmæssige tekniske, operationelle og organisatoriske foranstaltninger for at håndtere risici for sikkerheden af netværks- og informationssystemer... herunder (a) politikker for risikoanalyse og informationssystemsikkerhed.

B. What it means in practice

You need written policies that document how you identify, assess, and handle cyber risks. It's not enough to say *"we take security seriously"*, you need concrete documents that are updated regularly and approved by leadership.

C. Microsoft 365 features

  • Microsoft Purview Compliance Manager(primary)
  • Microsoft Secure Score(primary)
  • Purview Risk Management(supplementary)

D. Licence requirement

Minimum licence: Business Prem

E. Configuration

  • Go to Microsoft 365 Defender → Secure Score and baseline your current score
  • Open Purview Compliance Manager and start a NIS2 assessment (or use IT-grundbeskyttelse as a proxy)
  • Export the Compliance Manager report monthly as documentation
  • Document your own policies (in SharePoint or an external tool)

F. Audit evidence

  • Exported Secure Score history (at least 12 months)
  • Compliance Manager assessment report, dated within the last 3 months
  • Written information security policy approved by leadership, version-stamped
  • Meeting minutes from leadership reviews of the policy (quarterly recommended)

Control 2

Incident handling

A. Legal requirement

(b) incident handling

Directive text: (b) hændelseshåndtering

B. What it means in practice

You need to be able to detect, log, investigate, and report cyber incidents. NIS2 requires an early warning within 24 hours and a formal report within 72 hours for serious incidents. That presupposes you can actually see what's happening in your environment, and that you have a team or partner that responds.

C. Microsoft 365 features

  • Microsoft Defender XDR portal (E5 or Defender Suite add-on)(primary)
  • Microsoft Defender for Business (Business Premium)(primary)
  • Microsoft Sentinel (separate Azure licence)(supplementary)

D. Licence requirement

Minimum licence: Business Prem · Full coverage requires: M365 E5

Business Premium covers baseline detection via Defender for Business. The Defender XDR portal and automated investigation require E5 or the Defender Suite add-on (since September 2025 the add-on can be bought directly on top of Business Premium, max 300 users).

E. Configuration

  • Enable Defender for Business (BP) or Defender XDR (E5) as primary detection
  • Configure automated response rules in Defender for known threats
  • Create an incident response playbook (written who-does-what procedure)
  • Test the playbook with tabletop exercises at least every six months
  • Set up 24/7 on-call or an MDR partner if you don't have your own SOC

F. Audit evidence

  • Defender incident log with timestamps (export from the portal, at least last 12 months)
  • Written incident response playbook with version history
  • Tabletop exercise reports (at least 2 per year)
  • Reports to the sector authority and CFCS, keep them as evidence the process works

Control 3

Business continuity and backup

A. Legal requirement

(c) business continuity, such as backup management and disaster recovery, and crisis management

Directive text: (c) business continuity, herunder backup-styring og disaster recovery, samt krisestyring

B. What it means in practice

You need to be able to keep the business running after an incident. That means tested backups, documented recovery times (RTO/RPO), and a crisis response plan. Built-in Microsoft 365 retention is NOT backup, it's versioning. Real backup requires Microsoft 365 Backup (add-on) or a third-party solution.

C. Microsoft 365 features

  • Exchange/SharePoint retention policies(primary)
  • Microsoft 365 Backup (separate add-on, ~$3-5/user/mo)(primary)
  • OneDrive Files Restore (30 days)(supplementary)

D. Licence requirement

Minimum licence: Business Prem

E. Configuration

  • Configure retention policies in Purview for Exchange, SharePoint, and OneDrive
  • Assess whether you need to buy the Microsoft 365 Backup add-on (ransomware rollback)
  • Document RTO/RPO per system
  • Write a crisis response plan with contact list and escalation steps
  • Test recovery at least every six months (tabletop or live)

F. Audit evidence

  • Written backup and disaster recovery policy with RTO/RPO
  • Recovery test reports (at least 2 per year)
  • Microsoft 365 Backup configuration report if purchased
  • Retention policy export from Purview

Control 4

Supply chain security

A. Legal requirement

(d) supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers

Directive text: (d) leverandørkæde-sikkerhed, herunder sikkerhedsrelaterede aspekter vedrørende forholdet mellem hver enhed og dens direkte leverandører eller tjenesteudbydere

B. What it means in practice

You need to manage the security of your suppliers, not just keep them on a list. That means contracts with security clauses, periodic assessments, and B2B access management. You're someone else's supplier too, so this documentation will be required FROM you by larger customers.

C. Microsoft 365 features

  • Conditional Access for B2B guests (Premium+)(primary)
  • Information Barriers (E5 or Purview Suite add-on)(supplementary)
  • Defender for Cloud Apps, vendor risk scoring (E5 or Defender Suite add-on)(supplementary)

D. Licence requirement

Minimum licence: Business Prem · Full coverage requires: M365 E5

Business Premium is enough to meet the baseline requirements via Conditional Access for B2B guests. Information Barriers and Defender for Cloud Apps' vendor risk scoring require E5 or the respective Suite add-ons.

E. Configuration

  • Create CA policies for external guests (require MFA, managed devices only)
  • Implement a supplier onboarding process with a security questionnaire
  • Use Information Barriers to separate data groups if you have competing customers
  • Maintain a supplier register with risk rating
  • Get contract clauses that require NIS2-equivalent security

F. Audit evidence

  • Supplier register with risk assessments
  • Signed security clauses in contracts
  • Export of CA policies for external access
  • Periodic supplier reviews (annually as minimum)

Control 5

Secure acquisition, development, and maintenance

A. Legal requirement

(e) security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure

Directive text: (e) sikkerhed i forbindelse med erhvervelse, udvikling og vedligeholdelse af netværks- og informationssystemer, herunder håndtering og offentliggørelse af sårbarheder

B. What it means in practice

The most "edge case" control for typical SMBs. If you do NOT develop software, the requirement is mainly patch management and a simple procurement checklist. If you do, it becomes enterprise territory with SAST/DAST, signed code, and secret scanning.

C. Microsoft 365 features

  • Intune patch management for endpoints(primary)
  • Defender for Cloud (Azure, only if you build on Azure)(supplementary)

D. Licence requirement

Minimum licence: Business Prem

E. Configuration

  • Patch management: configure Intune Update Rings for Windows and Office
  • Procurement checklist: simple template, does the supplier require MFA? CMMC? ISO 27001?
  • If you develop: Defender for Cloud DevOps integration + signed commits + Dependabot/Snyk
  • Vulnerability disclosure: publish a security.txt file on your domain with a contact email

F. Audit evidence

  • Patch compliance report from Intune
  • Written procurement policy
  • If development: SAST/DAST reports, signed commit logs
  • security.txt file available on the domain

Control 6

Effectiveness assessment

A. Legal requirement

(f) policies and procedures to assess the effectiveness of cybersecurity risk-management measures

Directive text: (f) politikker og procedurer til vurdering af effektiviteten af cybersikkerhedsrisikostyringsforanstaltningerne

B. What it means in practice

You need to regularly assess whether your security measures actually work. It's not enough to have policies, you need to measure. Compliance Manager assessments or an annual security audit covers the requirement. Plus meeting minutes with action items and follow-through.

C. Microsoft 365 features

  • Microsoft Purview Compliance Manager assessments(primary)
  • Audit Premium (E5 or Purview Suite add-on), 1-year retention(supplementary)

D. Licence requirement

Minimum licence: Business Prem · Full coverage requires: M365 E5

Business Premium provides basic Compliance Manager, enough to run a NIS2 assessment and document it. Audit Premium with 1-year retention of high-value events requires E5 or the Purview Suite add-on (typically relevant for finance and healthcare).

E. Configuration

  • Run an annual Compliance Manager assessment against NIS2 (or IT-grundbeskyttelse)
  • Configure Audit Premium (E5 or Purview Suite) if you have legal retention requirements
  • Hold quarterly security reviews with leadership
  • Get an external audit at least every other year

F. Audit evidence

  • Compliance Manager assessment reports (at least annually)
  • Meeting minutes from security reviews
  • External auditor report (if performed)
  • Action item tracker with status

Control 7

Cyber hygiene and awareness training

A. Legal requirement

(g) basic cyber hygiene practices and cybersecurity training

Directive text: (g) grundlæggende cyberhygiejne-praksis og cybersikkerhedstræning

B. What it means in practice

Employees need regular training, phishing, password hygiene, how to report a suspicious email. Best practice is quarterly simulations and annual formal training. Completion tracking per employee must be available for inspection.

C. Microsoft 365 features

  • Defender for Office 365 Attack Simulator (Premium+)(primary)
  • Defender Training campaigns with completion tracking(supplementary)

D. Licence requirement

Minimum licence: Business Prem

E. Configuration

  • Configure Attack Simulator with quarterly phishing campaigns
  • Set up training campaigns for employees who fall for simulations
  • Require annual formal awareness training (internal or external provider)
  • Track completion per employee and document it

F. Audit evidence

  • Phishing simulation reports (at least 4 per year)
  • Training campaign completion reports per employee
  • Annual awareness training evidence (signed attendance list or LMS export)
  • Written awareness policy

Control 8

Encryption

A. Legal requirement

(h) policies and procedures regarding the use of cryptography and, where appropriate, encryption

Directive text: (h) politikker og procedurer vedrørende brugen af kryptografi og, hvor det er hensigtsmæssigt, kryptering

B. What it means in practice

Data must be encrypted both in transit and at rest. Microsoft 365 has this by default for cloud services, but endpoints require BitLocker (Windows Enterprise via E3+). Plus key management, for an SMB, Microsoft-managed keys are normally sufficient.

C. Microsoft 365 features

  • BitLocker via Intune (Windows Enterprise. E3+)(primary)
  • Sensitivity Labels with encryption (Premium+)(primary)
  • Microsoft Purview Message Encryption(supplementary)

D. Licence requirement

Minimum licence: Business Prem · Full coverage requires: M365 E5

Manual sensitivity labelling and BitLocker are covered by Business Premium. Auto-labelling (policy-based automatic classification) and Customer Key for your own key management require E5 or the Purview Suite add-on plus Azure Key Vault.

E. Configuration

  • Enable BitLocker via Intune device configuration profile
  • Create Sensitivity Labels for classification (Confidential, Internal, Public)
  • Configure auto-labelling for sensitive data (requires E5 or Purview Suite)
  • Enable Message Encryption for external email traffic
  • Write an encryption policy with key management

F. Audit evidence

  • Intune device compliance report (BitLocker status per device)
  • Sensitivity Labels policy export from Purview
  • Written encryption policy
  • Message Encryption usage report

Control 9

HR security, access control, and asset management

A. Legal requirement

(i) human resources security, access control policies and asset management

Directive text: (i) sikkerhed i forbindelse med menneskelige ressourcer, politikker for adgangskontrol og enhedsstyring (asset management)

B. What it means in practice

The entire employee lifecycle: hiring → access → changes → termination. Plus device and data management. Least privilege, joiner-mover-leaver processes, and regular access reviews. Intune gives you visibility into which devices exist and who has them.

C. Microsoft 365 features

  • Microsoft Entra ID Governance (E5 or Entra ID Governance SKU)(primary)
  • Entra Access Reviews (Entra ID P2, part of E5)(primary)
  • Intune device inventory(supplementary)

D. Licence requirement

Minimum licence: M365 E5

This is the one control where Business Premium is *not* sufficient at baseline. Entra ID Governance and Access Reviews require Entra ID P2, either via E5 or via Entra ID Governance as a standalone SKU ($7/user/mo on top of a P1 or P2 licence at list price, current price shown in the comparison tool). For SMBs a combination is common: Business Premium for the majority plus the Entra ID Governance SKU for 3-5 IT and compliance specialists.

E. Configuration

  • Document joiner-mover-leaver processes in writing
  • Configure Access Reviews (quarterly for privileged roles, half-yearly for the rest)
  • Use Entitlement Management for access to resource packages
  • Use Intune for central device registration and remote wipe on offboarding
  • Privileged Identity Management (PIM) for admin roles, just-in-time access only

F. Audit evidence

  • Written joiner-mover-leaver policy
  • Access Review reports (complete log of approved and denied access)
  • Intune device inventory export
  • PIM activation log for admin roles

Control 10

MFA and secure communications

A. Legal requirement

(j) the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate

Directive text: (j) brugen af multi-faktor autentificering eller kontinuerlige autentificeringsløsninger, sikrede tale-, video- og tekstkommunikation samt sikrede beredskabskommunikationssystemer i enheden, hvor det er hensigtsmæssigt

B. What it means in practice

MFA is no longer optional, supervisors ask about it first. Plus encrypted communications (Teams does it by default), and a plan for how you communicate if the primary system is down. Conditional Access provides granular MFA enforcement, for example only from unfamiliar locations or new devices.

C. Microsoft 365 features

  • Microsoft Entra MFA (all plans)(primary)
  • Conditional Access (Premium+ for granular control)(primary)
  • Teams Premium for advanced meeting protection(supplementary)

D. Licence requirement

Minimum licence: Business Prem

E. Configuration

  • Require MFA on all accounts, including service accounts where possible
  • Configure CA policies: MFA from unfamiliar locations, block sign-in from high-risk countries, require compliant device for admin portals
  • Turn legacy auth off (Basic Auth in Exchange)
  • Implement passkeys or FIDO2 for privileged accounts
  • Emergency communications: document a backup channel if Teams is down (e.g. Signal, phone tree)

F. Audit evidence

  • MFA registration report (all accounts registered with MFA)
  • Conditional Access policy export
  • Sign-in log with MFA claims (at least 12 months)
  • Written emergency communications plan

I har nu hele mappingen. Hvad nu?

Mappingen ovenfor er udgangspunktet for jeres NIS2-implementering. Regn med et projekt over flere måneder, ikke en hurtig løsning. Næste skridt:

  • Lav en gap-analyse mod de 10 kontroller — hvad har I, hvad mangler I?
  • Vurder jeres licens-niveau — særligt om I har behov for E5 eller Purview Suite-add-on til kontrol 6, 8 og 9
  • Få ledelses-opbakning og en projektplan — NIS2 kræver dokumenteret styring

Want the mapping as a PDF and a walkthrough?

Write to me and I'll send it and look at where you stand against the 10 controls.

Get in touch