How do I set up an NIS2 compliance report?
Closed beta starting September 2026
The new report engine is accessible via a closed beta starting in September 2026. If you would like to participate in the beta, please reach out to your Customer Success Manager.
This article describes how to set up an NIS2 compliance report in Security Center. First, create a report template with the settings required for NIS2 compliance. Then, use that template to generate the report.
Create the template
- Log in to Security Center.
- Hover over Reports > Templates, then click + Create template.
- Enter a name for the template, e.g., "NIS2 compliance template".
- Optionally, under Filters, check Only include non-compliant assets to limit the report to assets that are non-compliant.
- Under Max remediation time, review or adjust the default number of days allowed to remediate vulnerabilities by severity: Critical, High, Medium, and Low. Vulnerabilities must be remediated within this timeframe to maintain compliance.
- Optionally, under Max remediation time by tag, click + Add tag to override the default remediation times for assets with specific tags.
- Under EPSS threshold, set the default Exploit Prediction Scoring System (EPSS) threshold. Vulnerabilities with an EPSS score above this threshold are considered non-compliant.
- Optionally, under EPSS threshold by tag, click + Add tag to override the default EPSS threshold for assets with specific tags.
- Click OK to create the template.
- Done!
Generate the report
- Hover over Reports > Reports, then click + Create report.
- Under Select assets, select what to include in the report: Include all assets, Select with tags, Select assets, or Select IP network. Click Continue.
- Under Filters & constraints, under Asset types, check the asset types to include: Network assets, Web applications, and Devices. Click Continue.
- Under Layout, enter a name for the report and select the template you created earlier from the Layout template drop-down, e.g., "NIS2 compliance template".
- Alternatively, click Customize layout to build a custom layout instead of using a saved template.
- Click Generate report.
- Done!
Schedule a report
- Hover over Reports > Schedules, then click + Create schedule.
- Under Select assets, select what to include in the report: Include all assets, Select with tags, Select assets, or Select IP network. Click Continue.
- Under Filters & constraints, under Asset types, check the asset types to include: Network assets, Web applications, and Devices. Click Continue.
- Under Layout, enter a name for the report. Optionally, select a template from the Layout template drop-down, e.g., "NIS2 compliance template". If no template is selected, a custom layout is used.
- Optionally, click Customize layout to build a custom layout instead of using a saved template.
- Click Schedule settings.
- Under Schedule, optionally check Skip empty reports to avoid generating a report when no data is available.
- Set the Start date, Time, Time zone, and Repeat settings to define when the report should run.
- Make sure Active is turned on to enable the schedule.
- Click Submit.
- Done!
Rerun a report
- Hover over Reports > Reports.
- Click on the rerun icon next to the report you want to run again. This opens the New compliance report wizard.
- Complete the Select assets, Filters & constraints, and Layout steps as described above, then click Generate report.
- Done!
Related articles
What are the recommended settings in the NIS2 compliance report?
What is the NIS2 compliance report?
What are ENISA’s recommendations for vulnerability management?
How does the NIS2 compliance report relate to ENISA’s recommendations?
Disclaimer
Nothing in the report constitutes legal advice, and requirements for NIS2 compliance vary by member state.