Directive (EU) 2022/2555 and national transposition

The obligation nobody
wrote down in one place

NIS 2 sets the frame, the national law sets the detail, sector rules add to it and your contracts pass parts of it down the chain. The obligation that actually applies to you exists only where those texts intersect.

The question it comes down to

"An incident affects a supplier, not you. Which notification duties are triggered, by when, and to whom?"

Article 23 sets the reporting stages. The national transposition names the authority and can tighten the detail. Your supply contract determines when the supplier must tell you — which decides whether the clock is even startable in time.

Why ordinary search does not get there

Four bodies of text, one answer.

Directive, national act, sector regulation and contract. Reading any one of them alone produces an answer that is confidently wrong.

Management is personally in scope.

Article 20 puts risk-management approval and oversight on management bodies. 'The tool said so' is not a defence anyone wants to rely on; the reasoning has to be inspectable.

Deadlines are short.

An early warning is measured in hours, not weeks. Working out the answer while the clock runs is the wrong time to be reading four documents.

A worked example

The query

A supplier reports a security incident affecting a service we operate. What are our duties?

  1. 01
    Directive, Article 23

    Sets the reporting stages and their content requirements.

  2. 02
    National transposition

    Names the competent authority and the channel for the notification.

  3. 03
    Supply contract, clause 11

    Obliges the supplier to notify us — but only within 48 hours.

  4. 04
    Internal escalation policy

    Defines who is authorised to file, and their deputy.

The answer

The duty and its stages follow from Article 23 and the national act; the contractual 48-hour supplier window is the practical constraint, and it is named as a finding rather than buried.

What ARGUS does here

Legal texts and internal documents in one index

Regulation, national law, policies and contracts are searchable together, so an answer can legitimately cross from one to the other.

Reasoning trace, not just an answer

The output shows which sub-question was resolved by which text — the part management needs to be able to inspect.

Conflict detection

Where a contractual term undercuts a statutory duty, both are surfaced together instead of the system picking one.

Reusable across the group

The same index answers for several entities, with the entity-specific documents kept apart by metadata filters.

What it does not do

Stated here rather than discovered in week three of a pilot.

  • ARGUS is not legal advice and does not replace counsel or your CISO.
  • National transpositions differ and change. The answer is only as current as the texts you have indexed — which is why the version is always named.
  • It does not file notifications and does not connect to authority portals.
  • Scenarios here are built and demonstrated, not drawn from production deployments.

Questions we get asked

Do we have to index the legal texts ourselves?+
You decide what goes in. Public legal texts can be ingested once and maintained; your policies and contracts stay in your environment throughout.
How current are the answers?+
As current as the index. Each answer names the version of the document it relied on, so an outdated basis is visible rather than assumed away.
Can it run fully offline?+
Yes, with a locally hosted model. Quality differs between models and we will tell you where the trade-off lies rather than pretending there isn't one.

Test it on a question you already lost time on

Bring one question your own documents should be able to answer, and the documents that ought to contain the answer. If the evidence is not there, that is the result — and it is worth knowing before an auditor finds it.