NIS2 and End-of-Life Dependencies: What Compliance Teams Need to Know
NIS2 treats an unsupported dependency as a known, quantifiable risk. If it is not in your risk plan, that is a gap.
.png)
The NIS2 Directive (European Union 2022/2555) required member-state transposition by October 2024 and expects essential and important entities to manage cybersecurity risk with appropriate and proportionate measures. An unsupported dependency is, by definition, a known and quantifiable risk, and if it is not in your risk analysis and treatment plan, that is a gap.
What does NIS2 ask for?
Rather than prescribing specific technologies, NIS2 requires an all-hazards, risk-based approach. Article 21 lists ten minimum categories of measures, including risk analysis and information-system security policies, vulnerability handling and disclosure, and security in the acquisition, development, and maintenance of systems, along with supply-chain security. Management bodies are accountable for these measures.
Why do end-of-life dependencies matter under NIS2?
An unsupported operating system, framework, or library is a known and quantifiable risk, so failing to identify and document it is a clear gap in the risk analysis NIS2 requires. Vulnerability handling also cannot depend on upstream fixes that no longer exist, and the directive's supply-chain scope reaches the open-source components inside the products and services you rely on.
Who is in scope?
NIS2 covers essential and important entities across a wide set of sectors, generally above defined size thresholds, and its supply-chain provisions extend expectations to the vendors and components those entities depend on. If you are in scope, the software in your estate, including its dependencies, is in scope with you.
How do you demonstrate diligence?
Maintain a Software Bill of Materials with end-of-life tracking, document risk treatment for each unsupported component, and apply compensating controls or extended support where migration cannot happen in time. HeroDevs Never-Ending Support provides a supported patch stream that lets you show vulnerability handling is in place for end-of-life open source.
This article is general information, not legal advice. Confirm your obligations with counsel.
Frequently asked questions
What is NIS2?
European Union Directive 2022/2555 on cybersecurity risk management, with transposition due by October 2024.
Does NIS2 require specific technical controls?
No. It requires appropriate and proportionate, risk-based measures across ten minimum categories in Article 21.
How do EOL dependencies affect NIS2 compliance?
They are known risks that must be identified, documented, and treated, and they cannot be patched upstream.
Does NIS2 cover my supply chain?
Yes. Supply-chain security is one of the required measures, reaching the components you depend on.
Can extended support help demonstrate vulnerability handling?
Yes. It restores a patch stream for end-of-life components you cannot yet retire.
Resources
View All Articles
.png)

