Tabletop exercise

NIS 2 Directive (EU 2022/2555) tabletop exercise

EU-wide baseline: management accountability, ten measures, strict incident clocks.

We can run the NIS 2 Directive (EU 2022/2555) exercise for your team, or set you up as a facilitator to run it yourself.

What the room works through

EU NIS 2 Directive (2022/2555) cyber risk management measures and reporting duties

Essential or important entity in a critical sector (energy, transport, health, digital infrastructure, public administration). Use article refs such as Art.20, Art.21(2)(a)-(j), Art.23 and domains Governance, Risk management, Incident handling, Continuity, Supply chain, Reporting. Emphasise management-body liability, 24-hour early warning, 72-hour notification and one-month final report.

Clauses
20
Rounds
10 across two stages
Room size
Up to 20 participants

Stage 1 — assess

Tables rate control maturity, agree the risk that matters for the room, then face an audit round where a peer table challenges the call. Every decision is logged against a NIS 2 Directive (EU 2022/2555) clause.

Stage 2 — survive

Incidents and complications hit the tables: crisis injects, budget cuts and a concealed insider. Controls bought in Stage 1 pay out — or the gap shows.

What you take away

  • Clause-by-clause coverage across NIS 2 Directive (EU 2022/2555)
  • A gap list ranked by what the room could not defend
  • Per-table divergence, so you can see where opinion split
  • Word and CSV exports plus a drafted findings narrative

New to facilitating? Start with the facilitator manual or read the session walkthrough.

Other standards