What are the recommended settings in the NIS2 compliance report?
Closed beta starting September 2026
The new report engine is accessible via a closed beta starting in September 2026. If you would like to participate in the beta, please reach out to your Customer Success Manager.
This article lists the settings we recommend for the NIS2 compliance report, alongside what ENISA specifies (or does not specify) for each. Use these as defaults and adjust them to make them relevant to your specific organization.
|
Setting: |
ENISA: |
Holm Security’s recommendation: |
|
EPSS threshold |
ENISA doesn’t specify a specific threshold. |
Number of vulnerabilities allowed over 90% EPSS (extremely likely to be exploited within the next 30 days): 0 |
|
Remediation time |
ENISA’s recommendation is that high and critical vulnerabilities should be resolved without undue delay. |
Max remediation time:
|
|
Assessment (scanning) interval |
ENISA recommends assessments “at planned intervals”. |
Scanning schedule to ensure new vulnerabilities are addressed swiftly:
|
|
Asset scope |
ENISA is assessing all relevant assets within the defined NIS2 scope, prioritizing them according to risk and asset criticality, rather than limiting assessments to internet-facing systems. |
All assets required for the organization to operate should be included in the assessment scope. |
|
Coming later in 2026: |
ENISA recommends focusing, at a minimum, on high and critical severity vulnerabilities. |
Limit the report to cover the following severities:
|
|
Coming later in 2026: |
ENISA doesn’t specify a specific threshold. |
Threshold for the number of vulnerabilities within each severity:
|
What is EPSS?
The Exploit Prediction Scoring System (EPSS) estimates the likelihood that a vulnerability will be exploited in the wild within the next 30 days, expressed as a percentage from 0% to 100%.
- 1% means the vulnerability is relatively unlikely to be exploited.
- 25% means there is a meaningful exploitation likelihood.
- 90% and above means the vulnerability is extremely likely to be exploited.
What is CVSS?
The Common Vulnerability Scoring System (CVSS) is a standardized way to measure the severity of a vulnerability on a scale from 0.0 to 10.0. In the platform, the CVSS score is translated into a severity level.
How does Holm Security translate the CVSS score versions to severity?
Related articles
What is the NIS2 compliance report?
What are ENISA’s recommendations for vulnerability management?
How does the NIS2 compliance report relate to ENISA’s recommendations?
Disclaimer
Nothing in the report constitutes legal advice, and requirements for NIS2 compliance vary by member state.