> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/certifications/certifications-overview/nis2-directive-2022-2555.md).

# NIS2 Directive 2022/2555

Compliance with European cybersecurity obligations for digital and cloud service providers

### What it is

The NIS2 Directive (Network and Information Security Directive 2 — EU Directive 2022/2555) is the European Union's main legislative act on cybersecurity, repealing and replacing the previous NIS Directive (2016/1148). Transposed in Italy by Legislative Decree 138/2024, it sets binding requirements for cybersecurity risk management, incident notification and business continuity for organizations classified as essential or important entities in strategic sectors.

Compared to the original NIS Directive, NIS2 significantly broadens the scope of obligated entities — including cloud and digital service providers — and introduces stricter requirements in terms of governance, supply chain security and management accountability.

Memori, as a provider of cloud and artificial intelligence services, falls within the scope of the NIS2 Directive and has formalized its compliance with the obligations set by the legislation, with registration in the register of the National Cybersecurity Agency (ACN) and adoption of the required security measures.

### What it concretely guarantees

**Cybersecurity governance**

The NIS2 Directive requires company management to take direct responsibility for cybersecurity management. At Memori this translates into:

* **Formal oversight** of security processes by management (CTO and CEO), integrated into the ISO 27001:2022-certified ISMS
* **Periodic updating** of staff cybersecurity skills through regular training
* **Documented policies** for the security risk management of networks and information systems

**Security risk management**

Memori adopts technical and organizational measures proportionate to the identified risks, which include:

* **Continuous risk assessment** updated in the management system, with documented tracking of nonconformities and corrective actions
* **Protection against cyber threats:** detection and prevention systems active on the cloud infrastructure, with automatic scanning via AWS GuardDuty of files uploaded to the platform
* **Protection of communications and data:** all communications take place via HTTPS/TLS; sensitive data is protected in accordance with the security policies documented in the management system

**Security incident management**

In accordance with the notification obligations set by NIS2:

* Significant incidents are identified, classified and managed through a documented process that provides for **timely notification to the ACN** within the regulatory deadlines (pre-notification within 24 hours, full notification within 72 hours)
* Platform admins are notified by email of incidents, outages or serious issues
* At the end of each incident, the technical team conducts a post-incident retrospective to analyze the causes and prevent recurrence

**Business continuity and disaster recovery**

* **Planned platform updates** that keep the service running without unexpected downtime
* **Continuous monitoring** of availability via Uptime Kuma, with automatic alerts in case of anomalies
* **Encrypted backups** stored in separate environments on European cloud infrastructure (Italy, Ireland, Germany)
* Business continuity plan integrated with the disaster recovery measures managed by the partner Cloudsome

**Supply chain security**

NIS2 introduces explicit obligations on supply chain security. At Memori this applies to:

* **Qualification and monitoring of critical suppliers:** cloud providers (Cloudsome, AWS, Hetzner), LLM providers (OpenAI, Anthropic, Mistral, etc.) and ancillary services (DeepL, ConvertAPI, Azure AI Speech) are selected, assessed and managed according to documented procedures
* **Contractual agreements** that define the security requirements for each supplier (SLA, DPA, data retention policies)
* **Transparency towards the customer** on the sub-processors involved in data processing and on their security policies

**Protection of the networks and information systems of AIsuru**

NIS2 compliance is integrated with what has already been implemented under ISO 27001:2022 and ISO 27017:2015 for the AIsuru platform:

* **Logical segregation** of multi-tenant environments: each customer sees only its own Agents, users and configurations
* **Separation of environments** development → staging → production, with automated deployment via Bitbucket Pipelines and mandatory code review on every change
* **Logging and monitoring:** centralized logs via Kibana and Injest, with tracking of all activities of users and system administrators and automatic alerts for anomalous behavior

**Audit and periodic review**

NIS2 compliance is subject to periodic review, integrated into the audit cycle of the Information Security Management System (ISO 27001:2022). Security measures are updated in response to the evolution of threats and to ACN guidance.

***

{% file src="/files/4Q0Rc4Iaqa3FC4LhY2bw" %}
