NIS2 and data recovery.
NIS2 includes backup management and recovery among the measures needed for reliable operations. Regular tests help you check whether your backups are ready to use.
Art. 21(2)(c) NIS2 includes backup management and disaster recovery as part of business continuity. Point (f) requires procedures to assess the effectiveness of security measures. Restore tests provide concrete results for that assessment.
Specific testing duties for digital providers
For certain providers covered by NIS2, including cloud, data centre, and managed service providers, Implementing Regulation (EU) 2024/2690 sets out more detailed requirements. Its Annex requires regular backup integrity checks in point 4.2.3 and regular recovery tests in point 4.2.6. Results must be documented and any necessary corrections made.
From testing to fixing errors
RestoreTrust runs your scheduled tests and records the restore process and check results. You can notify your team by email or webhook. This helps you investigate errors and test again once they have been fixed.
Plan around your organisation
Which duties apply depends on your activities, size, and the applicable national law. Match the scope and frequency of tests to your risks and recovery goals. Art. 21 itself does not set a single testing interval.
NIS2: Art. 21 on security measures (EUR-Lex)
Implementing Regulation (EU) 2024/2690: Art. 1 and Annex 4.2 (EUR-Lex)
How RestoreTrust helps
- Regular restore tests
- Documented results for assessing effectiveness
- Notifications by email or webhook
How to put the tests into practice
- Identify the requirements that apply to your organisation
- Align tests with your contingency plans
- Plan how to fix errors and test again
Part of your security measures
RestoreTrust supports the part of your NIS2 measures that covers testing and documenting recoverability. Combined with your contingency plans, reporting procedures, and other security controls, test results become a regular part of your preparedness.