Skip to content
  • There are no suggestions because the search field is empty.

What are the recommended settings in the NIS2 compliance report?

This article lists the settings we recommend for the NIS2 compliance report, alongside what ENISA specifies (or does not) for each. Use these as sensible defaults and adjust based on your organization's own risk appetite and asset criticality.

Setting:

ENISA:

Holm Security’s recommendation:

EPSS threshold

ENISA doesn’t specify a specific threshold.

Number of vulnerabilities allowed over 90% EPSS (extremely likely to be exploited within the next 30 days): 0

Remediation time

ENISA’s recommendation is that high and critical vulnerabilities should be resolved without undue delay.

Max remediation time:

  • Critical: 14 days
  • High: 30 days
  • Medium and low: 90 days
  • Weekly or daily: critical systems
  • Monthly: other important systems
  • Critical
  • High
  • Critical: 0
  • High: 0
  • Medium: none

Assessment (scanning) interval

ENISA recommends assessments “at planned intervals”.

Schedule interval to ensure new vulnerabilities are addressed swiftly:

Asset scope

ENISA is assessing all relevant assets within the defined NIS2 scope, prioritizing them according to risk and asset criticality, rather than limiting assessments to internet-facing systems.

All assets required for the organization to operate should be included in the assessment scope.

Coming later in 2026:
CVSS severity scope

ENISA recommends focusing, at a minimum, on high and critical severity vulnerabilities.

Limit the report to cover the following severities:

Coming later in 2026:
CVSS severity volume threshold

ENISA doesn’t specify a specific threshold.

Threshold for the number of vulnerabilities within each severity:

  • Critical: 0

  • High: 0

  • Medium: none

  • Low: none

What is EPSS?
EPSS stands for Exploit Prediction Scoring System. It estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, expressed as a percentage from 0% to 100%.

  • 1% means the vulnerability is relatively unlikely to be exploited.
  • 25% means there is a meaningful exploitation likelihood.
  • 90% and above means the vulnerability is extremely likely to be exploited.

What is CVSS?
CVSS stands for Common Vulnerability Scoring System. It is a standardized way to measure the severity of a vulnerability on a scale from 0.0 to 10.0. In the platform, the CVSS score is translated into a severity level: Info (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9), or Critical (9.0–10.0).

Related articles

Coming soon.