The NIS2 Directive (EU) 2022/2555 entered into force on January 16, 2023, and replaced the original NIS Directive. EU member states were required to transpose it into national law by 17 October 2024. If you operate in the EU, provide services to EU customers, or sit anywhere in their supply chain, you are likely in scope whether your HQ is in Berlin, Dublin, or Boston.
For many organisations, NIS2 represents the first time cybersecurity moves from an IT operational task to a boardroom liability.
Who Does NIS2 Apply To?
NIS1 covered 7 sectors. NIS2 expands that to 18 sectors and around 300,000 entities.
It introduces two tiers.
- Essential Entities that are critical to society and the economy.
This includes energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.
2. Important Entities and other sectors where disruption would have significant impact.
This includes postal and courier services, waste management, chemicals, food production and distribution, manufacturing of medical devices, computers and electronics, machinery, motor vehicles, and digital providers like online marketplaces, search engines and social networking platforms.
Size matters, but not how you think. The general rule is: if you have 50+ employees or €10M+ annual turnover and operate in one of those sectors, you are in. And even smaller organizations can be included if they are a sole provider in a region, or critical to a supply chain. Non-EU companies operating in the EU must also comply.
The key shift: under NIS1, member states decided who was in scope.
Under NIS2, you are automatically in scope if you meet the criteria.
What’s Actually New in NIS2?
There are three big changes
a. Broader and deeper risk management.
NIS2 shifts cybersecurity to a mandatory risk management framework, integrating technical controls, and continuous awareness training across all organizational levels.
b. Tougher reporting and supervision.
Regulators have more powers, and incident reporting is much faster.
c. Direct management
Management bodies have direct, non-delegable accountability and liability for approving and overseeing cybersecurity measures. Regulatory compliance and oversight rest strictly with leadership.
And in January 2026, the European Commission issued targeted implementation guidelines and administrative simplifications to ease the compliance burden for nearly 29,000 businesses, including 6,200 micro and small enterprises.
.
The 10 Minimum Cybersecurity Measures You Must Cover
Article 20 of NIS2 lists 10 baseline measures that every compliance program must address.
- Risk analysis and information system security policies.
Documented, regularly reviewed policies that cover your entire information system, not just critical assets.
- Incident handling. Prevention, detection, and response procedures.
Who does what, when, and with which tools.
- Business continuity and crisis management.
Backup management, disaster recovery, and crisis communication plans that are actually tested.
- Supply chain security.
Assess and mitigate cyber risks from your direct suppliers and service providers, including managed security providers and software vendors.
- Security in acquisition, development and maintenance.
Secure-by-design principles, vulnerability handling and coordinated disclosure.
- Policies to assess effectiveness.
Regular cybersecurity audits, assessments, and compliance checks.
- Basic cyber hygiene and cybersecurity training.
From MFA and patching to phishing training for all staff, including management.
- Cryptography and encryption.
Policies on appropriate use of encryption where relevant.
- Human resources security, access control and asset management.
Least-privilege access, asset inventories, and onboarding/offboarding controls.
- Use of multi-factor authentication, secured communications.
Where appropriate, you must use MFA, secured voice, video and text communications, and secured emergency systems.
If you already have ISO 27001, you have a head start, but ISO alone does not equal NIS2 compliance. NIS2 is more prescriptive on supply chain, reporting, and management accountability.
The Clock Is Ticking on Incident Reporting
This is where many teams will fail. NIS2 introduces a 3-stage reporting timeline to your national CSIRT. The clock starts the moment your team becomes aware of a significant incident:
- 24 hours: Early warning. Was there an incident? Is it potentially malicious and cross-border?
- 72 hours: Incident notification with initial assessment, severity and impact.
- Final report within one month: Root cause, mitigation, and cross-border impact. (If the incident is still ongoing at 30 days, file an intermediate progress report instead).
That means you need detection, logging, and escalation playbooks that work on a weekend, not just during office hours.
Management Liability and Penalties: Why Boards Are Paying Attention
NIS2 harmonizes penalties across the EU.
For Essential Entities it introduces administrative fines of up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher.
For Important Entities the fines are up to €7,000,000 or 1.4% of total worldwide annual turnover.
But the real change is personal. Member states must provide for management bodies to be held accountable, including potential temporary bans from management functions and personal liability for infringements. National transpositions are going further, with some countries introducing director liability and even criminal sanctions for serious negligence.
Other enforcement measures include warnings, suspension of certification or authorisation, and suspension of operations.
Your 6-Step Roadmap to NIS2 Compliance
If you operate in the EU, here is a practical path that works for mid-market and enterprise alike.
Step 1: Scoping and gap assessment.
Confirm if you are Essential or Important, which national laws apply to you (you may have multiple), and map where you stand against the 10 measures. Most organizations find their biggest gaps in supply chain, incident reporting SLAs, and evidence collection.
Step 2: Get management on the record.
NIS2 requires management bodies to approve cybersecurity risk-management measures and follow training. Schedule a board briefing, document approval of your cybersecurity strategy, and assign clear ownership.
Step 3: Build the risk management foundation.
Update your information security policies, asset inventory, access controls, backup and BCM plans, and secure development procedures. Implement MFA, encrypt data at rest and in transit, and centralize logging.
Step 4: Lock down the supply chain.
Inventory all direct suppliers with access to your systems or data. Add NIS2 security clauses to contracts, require SBOMs or attestation where possible, and define criteria for supplier risk assessments.
Step 5: Test your incident response.
Rewrite your IR playbook to meet the 24h/72h/30-day timeline. Run a tabletop exercise with legal, comms, IT, and management. Make sure you can produce the evidence a regulator will ask for: when you detected, what you knew, when you notified.
Step 6: Document, audit, repeat. NIS2 supervision is ongoing.
You will need continuous monitoring, periodic audits, and proof of effectiveness. You must have your mandatory compliance documentation and technical measures fully implemented so you can instantly produce evidence upon request by your CSIRT or during a post-incident review.
In summary
NIS2 is not just another checkbox regulation. It is the EU’s attempt to create a uniform cybersecurity baseline across member states, and it bridges the gap between IT engineering and boardroom governance.
Organisations operating in the EU must take proactive steps toward NIS2 readiness now. In a regulatory inspection, strong technical controls and clear compliance evidence go hand in hand. You cannot succeed without both.
Start with three questions for your next leadership meeting.
Are we in scope?
Who in the management body owns this?
And can we report a major incident in 24 hours?
If you can’t answer all three with confidence, your NIS2 project should have already started.
