Directive (EU) 2022/2555 · NIS2

NIS2 compliance, done properly

NIS2 has applied across the EU since 18 October 2024. It covers 18 sectors, makes senior management personally accountable and carries fines of up to €10 million or 2% of worldwide turnover. We take you from “we have no idea where we stand” to a documented, defensible compliance programme.

Check if NIS2 applies to youBook a free consultation
18 Oct 2024
Applies since
18
Sectors in scope
24 / 72 h
Incident reporting deadlines
€10M / 2%
Maximum fine

This page is a practical summary of Directive (EU) 2022/2555, not legal advice. National transposition adds its own deadlines, registration procedures and sector definitions — we always verify your specific obligations against the law in force before we plan any work.

The basics

What NIS2 actually is

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaced the original NIS Directive (2016/1148), entered into force on 16 January 2023, had to be transposed into national law by 17 October 2024 and has applied since 18 October 2024.

Unlike NIS1, you are not “designated” by a regulator any more. If your organisation operates in one of the listed sectors and is a medium-sized enterprise or larger, you are in scope automatically — whether anyone has written to you or not.

And even if you are outside the direct scope, NIS2 reaches you through supply chain security: entities that are in scope must assess and manage the security of their suppliers and service providers. In practice that means security questionnaires, contractual security annexes and evidence requests landing on the desks of small IT vendors, agencies and SaaS providers across Europe.

What changed compared to NIS1

01

From 7 to 18 sectors

Manufacturing, food, chemicals, waste, postal and courier services, research organisations, public administration, space and managed service providers were all pulled in.

02

Automatic scope by size

The “size-cap rule” replaced national designation. Medium-sized and larger enterprises in a listed sector are in scope by operation of law.

03

Mandatory registration

Entities must submit their identifying details to the competent authority so national and EU-level registers of in-scope entities can be maintained.

04

One reporting clock for everyone

Early warning within 24 hours, incident notification within 72 hours, final report within one month — the same across every member state.

05

Management is accountable

Management bodies must approve the risk-management measures, supervise their implementation, undergo training — and can be held liable for infringements.

06

Fines with real teeth

Up to €10 million or 2% of worldwide annual turnover for essential entities — deliberately modelled on the GDPR scale.

Scope

Does NIS2 apply to you?

Two questions decide it: which sector you operate in, and how big you are. A handful of entity types are in scope regardless of size.

The size thresholds

Micro & smallUnder 50 staff and ≤ €10M turnover / balance sheetGenerally out of scope
Medium50–249 staff, or turnover above €10MIn scope — important entity
Large250+ staff, or turnover above €50M and balance sheet above €43MEssential entity in Annex I sectors

Based on Commission Recommendation 2003/361/EC. Headcount and financials are calculated for the enterprise as a whole, including linked and partner enterprises.

In scope regardless of size

  • DNS service providers and top-level domain (TLD) name registries
  • Qualified trust service providers
  • Providers of public electronic communications networks or publicly available electronic communications services
  • Public administration entities designated by the member state
  • Sole providers of a service that is critical for societal or economic activity in a member state
  • Entities identified as critical under the CER Directive (EU) 2022/2557

Annex I — sectors of high criticality

Large enterprises here are essential entities; medium-sized ones are important entities.

Energy
Electricity, district heating and cooling, oil, gas, hydrogen
Transport
Air, rail, water and road transport
Banking
Credit institutions
Financial market infrastructure
Trading venues, central counterparties
Health
Healthcare providers, EU reference laboratories, medicine manufacturers and distributors
Drinking water
Suppliers and distributors of water intended for human consumption
Waste water
Collection, disposal and treatment of urban, domestic and industrial waste water
Digital infrastructure
IXPs, DNS, TLD registries, cloud providers, data centres, CDNs, trust services, electronic communications
ICT service management (B2B)
Managed service providers and managed security service providers
Public administration
Central government entities and, where designated, regional ones
Space
Operators of ground-based infrastructure supporting space services

Annex II — other critical sectors

Medium-sized and large enterprises here are important entities.

Postal and courier services
Postal service providers and courier operators
Waste management
Undertakings carrying out waste management as a principal activity
Chemicals
Manufacture, production and distribution of chemicals
Food
Production, processing and distribution of food, including wholesale and industrial retail
Manufacturing
Medical devices, computer/electronic/optical products, electrical equipment, machinery, motor vehicles and other transport equipment
Digital providers
Online marketplaces, online search engines and social networking platforms
Research
Research organisations whose primary goal is applied research or experimental development

Essential vs. important entities

Both tiers have exactly the same security obligations. What differs is how they are supervised and how hard they can be fined.

Essential entitiesImportant entities
WhoLarge enterprises in Annex I sectors, plus specific entity types regardless of sizeMedium enterprises in Annex I sectors and all medium and large enterprises in Annex II sectors
Security obligationsThe full set of Article 21 measuresIdentical — the full set of Article 21 measures
SupervisionProactive: on-site inspections, regular and targeted audits, security scans, information requestsReactive: only where there is evidence or an indication of non-compliance
Maximum fine€10,000,000 or 2% of worldwide annual turnover — whichever is higher€7,000,000 or 1.4% of worldwide annual turnover — whichever is higher
Management banA temporary ban on the CEO or legal representative exercising management functions is possibleNot applicable

Quick scope check

Answer three questions for an indicative result. It follows Article 3 of the directive but cannot replace a proper legal assessment.

Indicative only. Group structure, joint ventures and sector-specific rules (for example DORA for financial entities) can change the answer.

Article 21

The ten minimum measures

Every in-scope entity must take appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach. The directive spells out ten of them as a minimum.

Risk analysis and security policies

A documented methodology, a maintained risk register and information system security policies approved at management level.

Incident handling

Detection, classification, response and post-incident review — with named roles and an escalation path that works at 3 a.m.

Business continuity

Backup management, disaster recovery and crisis management — including restore tests, not just backup jobs that report green.

Supply chain security

Security assessment of direct suppliers and service providers, plus contractual security requirements and a vendor register.

Secure acquisition, development and maintenance

Security built into the lifecycle of network and information systems, including vulnerability handling and disclosure.

Measuring effectiveness

Policies and procedures to assess whether the risk-management measures actually work — metrics, reviews and internal audit.

Cyber hygiene and training

Basic cyber hygiene practices for everyone and cybersecurity training that is actually delivered and recorded.

Cryptography and encryption

Policies on the use of cryptography, including where encryption is mandatory and how keys are managed.

HR security, access control and asset management

Joiners, movers and leavers handled properly, least-privilege access, and an asset inventory that is kept current.

Multi-factor authentication and secure communications

MFA or continuous authentication, secured voice, video and text communications, and secured emergency communication systems.

Article 23

The reporting clock

A significant incident is one that has caused or is capable of causing severe operational disruption or financial loss, or that has affected or is capable of affecting other people by causing considerable material or non-material damage. Once you spot one, the clock starts.

Within 24 hoursEarly warning

Notify the CSIRT or competent authority, stating whether the incident is suspected to be caused by unlawful or malicious acts, or could have a cross-border impact.

Within 72 hoursIncident notification

Update the early warning with an initial assessment: severity, impact and, where available, indicators of compromise.

On requestIntermediate report

The CSIRT or competent authority can ask for a status update on the handling of the incident at any point.

Within 1 monthFinal report

A detailed description, the type of threat and root cause, the mitigation measures applied and any cross-border impact. If the incident is still ongoing, submit a progress report instead and the final one within a month of finishing the handling.

On top of that: where appropriate you must inform the recipients of your services about significant incidents and about significant cyber threats, including any measures they can take themselves. Twenty-four hours is not enough time to work out who does what — that is why the procedure has to exist before the incident.

Articles 20, 32 and 34

Why the board cannot delegate this

Approve

Management bodies must approve the cybersecurity risk-management measures themselves — an IT department decision is not enough.

Oversee

They must oversee implementation and can be held liable for the entity’s infringements of the directive.

Train

Members of management bodies are required to follow training, and must offer similar training to employees on a regular basis.

Answer personally

For essential entities, authorities may temporarily prohibit the CEO or legal representative from exercising management functions.

Fines are not the only lever. Competent authorities can issue warnings and binding instructions, order you to notify affected customers, publish aspects of the infringement, and suspend a certification or authorisation.

What we offer

From scoping to evidence you can show an auditor

We are an engineering team, not a paper mill. Policies matter, but so does the MFA that is actually switched on, the backup that has actually been restored and the incident report that can actually be filed in 24 hours. Every package below ends with something that works, not just a binder.

NIS2 Gap Assessment

Start here if you do not yet know where you stand

2–3 weeksPriced per scope
  • Formal scope determination: essential, important or out of scope, with the reasoning written down
  • Inventory of systems, data, third parties and the services that depend on them
  • Assessment against all ten Article 21 measures, scored and evidenced
  • External attack surface review and a check of your current backup and MFA posture
  • Prioritised remediation roadmap with effort, cost and owner per item
  • Management briefing so the board can approve the plan knowingly
Request a quote

NIS2 Implementation

The full programme — documents, technology and drills

2–4 monthsPriced per scope
  • Complete policy set: information security, risk methodology and register, access control, cryptography, asset management, HR security, supplier security, acceptable use
  • Incident response plan plus 24/72-hour notification templates, ready to send
  • Business continuity and disaster recovery plan with a real, timed restore test
  • Technical hardening: MFA rollout, endpoint protection, patch and vulnerability management, network segmentation, centralised logging, e-mail authentication with SPF, DKIM and DMARC
  • Supplier programme: vendor register, security questionnaire, contractual security annex
  • Training: a session for the management body and cyber hygiene plus phishing simulation for staff
  • Registration support and an evidence register structured the way a supervisor will ask for it
Request a quote

NIS2 Managed Compliance

Compliance is a state you maintain, not a project you finish

Monthly retainerPriced per scope
  • Quarterly risk review and policy updates, with the audit trail kept current
  • Continuous monitoring, 24/7 alerting and managed endpoint protection
  • Recurring vulnerability scans and an annual penetration test
  • Incident stand-by: we help you contain, and we draft the 24, 72-hour and final reports with you
  • Annual tabletop exercise for the management body
  • Ongoing supplier reassessment as your vendor list changes
  • We stand beside you during a supervisory inspection or audit
Request a quote

The capabilities behind the packages

Security engineering

Official Kaspersky and Bitdefender partners. Endpoint protection, hardening, segmentation and monitoring deployed and maintained by us.

Backup and recovery you have actually tested

Managed hosting with daily backups, documented RPO and RTO targets and a restore drill you can put in front of an auditor.

Identity and access

MFA rollout across e-mail, VPN, admin panels and cloud consoles, least-privilege reviews and a joiner–mover–leaver process that is followed.

Secure software development

If we build or maintain your systems, Article 21(2)(e) is covered by how we work: code review, dependency scanning, secrets management and a vulnerability disclosure route.

Documentation that survives an audit

Policies written for your organisation, not templates with the name swapped — reviewed, versioned, approved and dated.

Incident response on call

A number to ring, a playbook already written and someone who has drafted a 24-hour early warning before.

How we work

Five steps from unknown to defensible

Free 30-minute call

We work out whether NIS2 touches you at all, and what the honest size of the job is. If it does not apply to you, we say so.

Scope and gap assessment

Two to three weeks of interviews, system review and testing, ending in a scored report against the ten measures.

Roadmap and board approval

Priorities, budget and owners. The management body approves the measures formally, which is itself an Article 20 obligation.

Implementation

Documents and technology in parallel, in priority order, with the highest-risk gaps closed first. You see progress every two weeks.

Maintain and prove

Quarterly reviews, drills, scans and a living evidence register — so that the day a regulator or a customer asks, the answer already exists.

FAQ

Frequently Asked Questions

Two tests. First, does your main activity fall into one of the 18 sectors in Annex I or Annex II of the directive? Second, are you a medium-sized enterprise or larger — 50 or more staff, or turnover above €10 million? If both are yes, you are in scope. A few entity types, such as DNS providers, TLD registries, qualified trust service providers and certain public administration bodies, are in scope regardless of size.
None at all in terms of what you must do — both tiers owe the full set of Article 21 measures and the same reporting deadlines. The difference is supervision and penalties. Essential entities face proactive supervision, including inspections and audits without any suspicion of wrongdoing, and fines of up to €10 million or 2% of worldwide turnover. Important entities are supervised reactively and face up to €7 million or 1.4%.
No. The directive does not mandate any particular certification — it requires appropriate and proportionate measures. That said, an ISO 27001-style management system maps very neatly onto the ten Article 21 measures, and member states may require the use of certain certified ICT products or services in specific cases. We normally build the management system properly and leave certification as a separate business decision.
Not directly, but in practice yes. Article 21(2)(d) obliges in-scope entities to manage the security risks arising from their suppliers and service providers. Their auditors will therefore ask them about you. Expect security questionnaires, contractual security annexes, requirements around MFA and backups, and requests for evidence. Suppliers who can answer quickly keep the contract; those who cannot get replaced.
Significant incidents. Within 24 hours of becoming aware, an early warning to the CSIRT or competent authority, saying whether the incident is suspected to be malicious or could have cross-border effects. Within 72 hours, a notification with an initial assessment of severity, impact and indicators of compromise. Within one month, a final report covering the root cause, the mitigation applied and any cross-border impact. If the incident is still running at the one-month mark, you file a progress report and the final report a month after handling ends.
Yes. Article 20 requires management bodies to approve the risk-management measures and oversee their implementation, and states that they can be held liable for the entity’s infringements. Members of management bodies are also required to follow training. For essential entities, Article 32 allows the authorities to temporarily prohibit the chief executive or legal representative from exercising management functions where enforcement measures have been ignored. This is deliberately designed so cybersecurity cannot be quietly parked with the IT team.
The gap assessment takes two to three weeks. Full implementation typically runs two to four months, depending on how many systems you have, how much documentation already exists and how quickly your team can make decisions. Cost is driven by scope — number of sites, systems, staff and suppliers — so we quote after the initial call rather than guessing on a web page. The assessment can be booked on its own, and its report tells you exactly what the rest will cost.
You are in the same position as a very large share of European companies, and the practical answer is to start now and to document that you started. Supervisors weigh the seriousness and duration of an infringement and the steps taken to prevent or mitigate damage. An approved plan, a dated risk assessment and visible progress are a materially better position than nothing, and they are also what your customers will ask to see. The first useful step is the scope determination — you cannot plan against an obligation you have not defined.

Start with the question that actually matters: where do you stand?

Tell us your sector and roughly how big you are. We will come back within one working day with an honest read on whether NIS2 applies to you and what the work would involve. No obligation, and if it does not apply we will tell you that too.

We use your details only to answer this enquiry. See our privacy policy. /privacy

Related services:CybersecurityIT SupportHosting & BackupSoftware Development