The European NIS2 directive strengthens requirements for cyber risk management, incident management and security measures.
Monitoring and logging can help implement some of the capabilities needed for detection and response.
However, it would be incorrect to say:
“NIS2 requires all companies to install a SIEM.”
Compliance is not just about buying a product.
An organization must implement measures that are proportionate to its risks and context. A SIEM can be a technical component to support some of these measures, but it does not, on its own, constitute NIS2 compliance.