NIS2 compliance, done properly
NIS2 has applied across the EU since 18 October 2024. It covers 18 sectors, makes senior management personally accountable and carries fines of up to €10 million or 2% of worldwide turnover. We take you from “we have no idea where we stand” to a documented, defensible compliance programme.
This page is a practical summary of Directive (EU) 2022/2555, not legal advice. National transposition adds its own deadlines, registration procedures and sector definitions — we always verify your specific obligations against the law in force before we plan any work.
The basics
What NIS2 actually is
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaced the original NIS Directive (2016/1148), entered into force on 16 January 2023, had to be transposed into national law by 17 October 2024 and has applied since 18 October 2024.
Unlike NIS1, you are not “designated” by a regulator any more. If your organisation operates in one of the listed sectors and is a medium-sized enterprise or larger, you are in scope automatically — whether anyone has written to you or not.
And even if you are outside the direct scope, NIS2 reaches you through supply chain security: entities that are in scope must assess and manage the security of their suppliers and service providers. In practice that means security questionnaires, contractual security annexes and evidence requests landing on the desks of small IT vendors, agencies and SaaS providers across Europe.
What changed compared to NIS1
From 7 to 18 sectors
Manufacturing, food, chemicals, waste, postal and courier services, research organisations, public administration, space and managed service providers were all pulled in.
Automatic scope by size
The “size-cap rule” replaced national designation. Medium-sized and larger enterprises in a listed sector are in scope by operation of law.
Mandatory registration
Entities must submit their identifying details to the competent authority so national and EU-level registers of in-scope entities can be maintained.
One reporting clock for everyone
Early warning within 24 hours, incident notification within 72 hours, final report within one month — the same across every member state.
Management is accountable
Management bodies must approve the risk-management measures, supervise their implementation, undergo training — and can be held liable for infringements.
Fines with real teeth
Up to €10 million or 2% of worldwide annual turnover for essential entities — deliberately modelled on the GDPR scale.
Scope
Does NIS2 apply to you?
Two questions decide it: which sector you operate in, and how big you are. A handful of entity types are in scope regardless of size.
The size thresholds
| Micro & small | Under 50 staff and ≤ €10M turnover / balance sheet | Generally out of scope |
|---|---|---|
| Medium | 50–249 staff, or turnover above €10M | In scope — important entity |
| Large | 250+ staff, or turnover above €50M and balance sheet above €43M | Essential entity in Annex I sectors |
Based on Commission Recommendation 2003/361/EC. Headcount and financials are calculated for the enterprise as a whole, including linked and partner enterprises.
In scope regardless of size
- DNS service providers and top-level domain (TLD) name registries
- Qualified trust service providers
- Providers of public electronic communications networks or publicly available electronic communications services
- Public administration entities designated by the member state
- Sole providers of a service that is critical for societal or economic activity in a member state
- Entities identified as critical under the CER Directive (EU) 2022/2557
Annex I — sectors of high criticality
Large enterprises here are essential entities; medium-sized ones are important entities.
Annex II — other critical sectors
Medium-sized and large enterprises here are important entities.
Essential vs. important entities
Both tiers have exactly the same security obligations. What differs is how they are supervised and how hard they can be fined.
| Essential entities | Important entities | |
|---|---|---|
| Who | Large enterprises in Annex I sectors, plus specific entity types regardless of size | Medium enterprises in Annex I sectors and all medium and large enterprises in Annex II sectors |
| Security obligations | The full set of Article 21 measures | Identical — the full set of Article 21 measures |
| Supervision | Proactive: on-site inspections, regular and targeted audits, security scans, information requests | Reactive: only where there is evidence or an indication of non-compliance |
| Maximum fine | €10,000,000 or 2% of worldwide annual turnover — whichever is higher | €7,000,000 or 1.4% of worldwide annual turnover — whichever is higher |
| Management ban | A temporary ban on the CEO or legal representative exercising management functions is possible | Not applicable |
Quick scope check
Answer three questions for an indicative result. It follows Article 3 of the directive but cannot replace a proper legal assessment.
Indicative only. Group structure, joint ventures and sector-specific rules (for example DORA for financial entities) can change the answer.
Article 21
The ten minimum measures
Every in-scope entity must take appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach. The directive spells out ten of them as a minimum.
Risk analysis and security policies
A documented methodology, a maintained risk register and information system security policies approved at management level.
Incident handling
Detection, classification, response and post-incident review — with named roles and an escalation path that works at 3 a.m.
Business continuity
Backup management, disaster recovery and crisis management — including restore tests, not just backup jobs that report green.
Supply chain security
Security assessment of direct suppliers and service providers, plus contractual security requirements and a vendor register.
Secure acquisition, development and maintenance
Security built into the lifecycle of network and information systems, including vulnerability handling and disclosure.
Measuring effectiveness
Policies and procedures to assess whether the risk-management measures actually work — metrics, reviews and internal audit.
Cyber hygiene and training
Basic cyber hygiene practices for everyone and cybersecurity training that is actually delivered and recorded.
Cryptography and encryption
Policies on the use of cryptography, including where encryption is mandatory and how keys are managed.
HR security, access control and asset management
Joiners, movers and leavers handled properly, least-privilege access, and an asset inventory that is kept current.
Multi-factor authentication and secure communications
MFA or continuous authentication, secured voice, video and text communications, and secured emergency communication systems.
Article 23
The reporting clock
A significant incident is one that has caused or is capable of causing severe operational disruption or financial loss, or that has affected or is capable of affecting other people by causing considerable material or non-material damage. Once you spot one, the clock starts.
Notify the CSIRT or competent authority, stating whether the incident is suspected to be caused by unlawful or malicious acts, or could have a cross-border impact.
Update the early warning with an initial assessment: severity, impact and, where available, indicators of compromise.
The CSIRT or competent authority can ask for a status update on the handling of the incident at any point.
A detailed description, the type of threat and root cause, the mitigation measures applied and any cross-border impact. If the incident is still ongoing, submit a progress report instead and the final one within a month of finishing the handling.
On top of that: where appropriate you must inform the recipients of your services about significant incidents and about significant cyber threats, including any measures they can take themselves. Twenty-four hours is not enough time to work out who does what — that is why the procedure has to exist before the incident.
Articles 20, 32 and 34
Why the board cannot delegate this
Approve
Management bodies must approve the cybersecurity risk-management measures themselves — an IT department decision is not enough.
Oversee
They must oversee implementation and can be held liable for the entity’s infringements of the directive.
Train
Members of management bodies are required to follow training, and must offer similar training to employees on a regular basis.
Answer personally
For essential entities, authorities may temporarily prohibit the CEO or legal representative from exercising management functions.
Fines are not the only lever. Competent authorities can issue warnings and binding instructions, order you to notify affected customers, publish aspects of the infringement, and suspend a certification or authorisation.
What we offer
From scoping to evidence you can show an auditor
We are an engineering team, not a paper mill. Policies matter, but so does the MFA that is actually switched on, the backup that has actually been restored and the incident report that can actually be filed in 24 hours. Every package below ends with something that works, not just a binder.
NIS2 Gap Assessment
Start here if you do not yet know where you stand
- Formal scope determination: essential, important or out of scope, with the reasoning written down
- Inventory of systems, data, third parties and the services that depend on them
- Assessment against all ten Article 21 measures, scored and evidenced
- External attack surface review and a check of your current backup and MFA posture
- Prioritised remediation roadmap with effort, cost and owner per item
- Management briefing so the board can approve the plan knowingly
NIS2 Implementation
The full programme — documents, technology and drills
- Complete policy set: information security, risk methodology and register, access control, cryptography, asset management, HR security, supplier security, acceptable use
- Incident response plan plus 24/72-hour notification templates, ready to send
- Business continuity and disaster recovery plan with a real, timed restore test
- Technical hardening: MFA rollout, endpoint protection, patch and vulnerability management, network segmentation, centralised logging, e-mail authentication with SPF, DKIM and DMARC
- Supplier programme: vendor register, security questionnaire, contractual security annex
- Training: a session for the management body and cyber hygiene plus phishing simulation for staff
- Registration support and an evidence register structured the way a supervisor will ask for it
NIS2 Managed Compliance
Compliance is a state you maintain, not a project you finish
- Quarterly risk review and policy updates, with the audit trail kept current
- Continuous monitoring, 24/7 alerting and managed endpoint protection
- Recurring vulnerability scans and an annual penetration test
- Incident stand-by: we help you contain, and we draft the 24, 72-hour and final reports with you
- Annual tabletop exercise for the management body
- Ongoing supplier reassessment as your vendor list changes
- We stand beside you during a supervisory inspection or audit
The capabilities behind the packages
Security engineering
Official Kaspersky and Bitdefender partners. Endpoint protection, hardening, segmentation and monitoring deployed and maintained by us.
Backup and recovery you have actually tested
Managed hosting with daily backups, documented RPO and RTO targets and a restore drill you can put in front of an auditor.
Identity and access
MFA rollout across e-mail, VPN, admin panels and cloud consoles, least-privilege reviews and a joiner–mover–leaver process that is followed.
Secure software development
If we build or maintain your systems, Article 21(2)(e) is covered by how we work: code review, dependency scanning, secrets management and a vulnerability disclosure route.
Documentation that survives an audit
Policies written for your organisation, not templates with the name swapped — reviewed, versioned, approved and dated.
Incident response on call
A number to ring, a playbook already written and someone who has drafted a 24-hour early warning before.
How we work
Five steps from unknown to defensible
Free 30-minute call
We work out whether NIS2 touches you at all, and what the honest size of the job is. If it does not apply to you, we say so.
Scope and gap assessment
Two to three weeks of interviews, system review and testing, ending in a scored report against the ten measures.
Roadmap and board approval
Priorities, budget and owners. The management body approves the measures formally, which is itself an Article 20 obligation.
Implementation
Documents and technology in parallel, in priority order, with the highest-risk gaps closed first. You see progress every two weeks.
Maintain and prove
Quarterly reviews, drills, scans and a living evidence register — so that the day a regulator or a customer asks, the answer already exists.
Frequently Asked Questions
Start with the question that actually matters: where do you stand?
Tell us your sector and roughly how big you are. We will come back within one working day with an honest read on whether NIS2 applies to you and what the work would involve. No obligation, and if it does not apply we will tell you that too.