Skip to content
  • There are no suggestions because the search field is empty.

What are the recommended settings in the NIS2 compliance report?

Closed beta starting September 2026
The new report engine is accessible via a closed beta starting in September 2026. If you would like to participate in the beta, please reach out to your Customer Success Manager.

This article lists the settings we recommend for the NIS2 compliance report, alongside what ENISA specifies (or does not specify) for each. Use these as defaults and adjust them to make them relevant to your specific organization.

Setting:

ENISA:

Holm Security’s recommendation:

EPSS threshold

ENISA doesn’t specify a specific threshold.

Number of vulnerabilities allowed over 90% EPSS (extremely likely to be exploited within the next 30 days): 0

Remediation time

ENISA’s recommendation is that high and critical vulnerabilities should be resolved without undue delay.

Max remediation time:

  • Critical: 14 days
  • High: 30 days
  • Medium and low: 90 days

Assessment (scanning) interval

ENISA recommends assessments “at planned intervals”.

Scanning schedule to ensure new vulnerabilities are addressed swiftly:

  • Weekly or daily: critical systems
  • Monthly: other important systems

Asset scope

ENISA is assessing all relevant assets within the defined NIS2 scope, prioritizing them according to risk and asset criticality, rather than limiting assessments to internet-facing systems.

All assets required for the organization to operate should be included in the assessment scope.

Coming later in 2026:
CVSS severity scope

ENISA recommends focusing, at a minimum, on high and critical severity vulnerabilities.

Limit the report to cover the following severities:

  • Critical
  • High

Coming later in 2026:
CVSS severity volume threshold

ENISA doesn’t specify a specific threshold.

Threshold for the number of vulnerabilities within each severity:

  • Critical: 0

  • High: 0

  • Medium: none

  • Low: none

What is EPSS?
The Exploit Prediction Scoring System (EPSS) estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, expressed as a percentage from 0% to 100%.

  • 1% means the vulnerability is relatively unlikely to be exploited.
  • 25% means there is a meaningful exploitation likelihood.
  • 90% and above means the vulnerability is extremely likely to be exploited.

What is CVSS?
The Common Vulnerability Scoring System (CVSS) is a standardized way to measure the severity of a vulnerability on a scale from 0.0 to 10.0. In the platform, the CVSS score is translated into a severity level.

How does Holm Security translate the CVSS score versions to severity?

Disclaimer
Nothing in the report constitutes legal advice, and requirements for NIS2 compliance vary by member state.