All articles

NIS2

NIS2 Enforcement Has Started: 8 Questions Your Board Must Answer in the First 30 Days

NIS2 is now enforced across most of the EU. Article 20 puts directors personally on the hook. Eight questions every board must answer in 30 days.

Sylvio Sorel··7 min read
A chess board mid-game — boards now have to make calculated, defensible moves on NIS2.

NIS2 enforcement is now active across most of the EU in 2026, with the transposition deadline having passed in October 2024. Under Article 20 of the directive, members of management bodies face personal liability for non-compliance, including potential temporary bans on managerial functions. In the member states that have transposed, competent authorities are conducting systematic compliance assessments and first enforcement actions are expected this year. Transposition is not universal: France notably has still not transposed, and the Commission referred it to the Court of Justice on 8 July 2026 — a reprieve on the calendar for French entities, not an exemption from the obligation.

The directive applies to medium and large businesses in 18 covered sectors. Boards can no longer treat NIS2 as a future problem — the window for preparation has closed.

Why 30 days?

Thirty days is not a legal deadline but an executive one. Article 20 explicitly requires that management bodies approve cybersecurity risk management measures, oversee their implementation, and complete relevant training.

Approval without understanding is not approval. Oversight without evidence is not oversight.

The first 30 days identify whether boards can answer critical questions and reveal exactly what must be built before external auditors arrive.

Key penalties and scope

  • Penalty ceiling: €10 million or 2% of global turnover — whichever is higher.
  • Transposition deadline: October 2024 (missed by several states; enforcement live in 2026 wherever national law has landed).
  • Personal consequence: Article 20 enables temporary bans on managerial functions.

NIS2 applies to:

  • 18 sectors including digital infrastructure, managed services, manufacturing, food, chemicals, postal services, and public administration.
  • Medium or large enterprises (50+ employees or €10M+ turnover).
  • Certain entities regardless of size: DNS providers, TLD registries, trust service providers, electronic communications providers.

The 8 critical questions

1. Are we actually in scope — and which of our entities, specifically?

The easy question (“does NIS2 apply to us?”) often gets a simple yes or no. The harder version requires identifying which specific legal entities are in scope, in which member states, and under which competent authority.

For groups with multiple EU entities, national transpositions consistently require that a management body be allocated to each in-scope entity separately. A single centralised cybersecurity function at headquarters does not fulfil entity-level obligations. Boards need a definitive, written scope assessment — entity by entity, country by country — naming the governing regulation.

2. Has our management body formally approved our cybersecurity risk management measures?

Article 20 requires the management body itself — not the CISO, IT director, or outsourced provider — to approve measures adopted under Article 21. This must be a documented decision, minuted at board level, with specific substance of what was approved.

“Approved at board level in 2023 as part of the IT strategy” is insufficient. The board must have approved something that maps to the 10 risk management areas Article 21 enumerates:

  • Risk analysis policies
  • Incident handling
  • Business continuity
  • Supply chain security
  • Secure acquisition and development
  • Effectiveness assessment
  • Cyber hygiene and training
  • Cryptography
  • Access control and asset management
  • Multi-factor authentication with secure communications

3. Have all members of our management body completed cybersecurity training — and can we prove it?

Article 20(2) explicitly requires management body members to complete training sufficient to identify cybersecurity risks and assess the adequacy of management practices. National authorities expect granular, timestamped, exportable evidence: who was trained, when, on what content, and with what assessed outcome.

This must be board-level training — not the same module the general workforce receives. It must address the board’s specific governance responsibilities, the organisation’s risk landscape, NIS2’s legal obligations, and the personal liability framework. External expert delivery adds credibility and independence.

4. Do we know, today, what counts as a “significant incident” — and who reports it within 24 hours?

NIS2 mandates a three-stage incident reporting cadence:

  • Early warning to the competent authority within 24 hours of becoming aware of a significant incident.
  • Incident notification within 72 hours.
  • Final report within one month.

A “significant incident” includes any that causes severe operational disruption, material financial loss, or considerable material or non-material damage to others.

Boards need answers to two questions: first, is there a named person — with a named backup — whose job is to make the 24-hour call? Second, who authorises that notification? Regulators pay close attention to how fast an organisation moves in the first day of an incident. An unclear escalation path is one of the most common findings in early NIS2 supervisory reviews.

5. Do we know who our critical suppliers are, and have we assessed their security?

Article 21 requires explicit supply chain security measures. This is a new obligation in scope and specificity. Boards must name suppliers whose compromise would materially disrupt operations — cloud providers, managed service providers, software vendors, critical SaaS platforms — and show evidence their security posture has been assessed, not just procured.

This reaches beyond direct scope. Even organisations not directly regulated increasingly receive security questionnaires from regulated customers. If you are a supplier to an NIS2-obligated entity, compliance questions are already reaching you through contracts.

6. Does our incident response plan actually work — and when did we last test it?

Documented plans are a minimum; tested plans are what regulators seek. A business continuity plan never rehearsed, disaster recovery procedures never executed end-to-end, or crisis communication protocols existing only in documents do not satisfy NIS2’s operational readiness expectations.

The board question is simple: when was the last tabletop exercise? What was the outcome? What changed as a result? If the answers are “never,” “we haven’t done one,” and “nothing,” this represents the highest-return 30-day investment a board can authorise.

7. Have we registered with our national competent authority?

Most national transpositions require in-scope entities to register with the designated competent authority, typically within a defined window after the national law enters into force. Registration timelines, authorities, and required information vary by member state. A group with entities in Belgium, Germany, Italy, and France faces four different registration processes with four different authorities.

Boards need a register documenting which entities have registered, where, by when, and with which authority name and contact. This is routine compliance hygiene frequently missed in cross-border groups and is one of the first things supervisory authorities check.

8. What is our budget for NIS2 — and is it proportionate to our risk?

Article 21 requires measures that are “appropriate and proportionate” to the entity’s risk exposure, size, and the likelihood and severity of incidents. One practical interpretation of proportionality is financial: a budget line item for NIS2 compliance and cybersecurity reflecting the scale of required obligations.

A generic “IT maintenance” budget is insufficient. National enforcement guidance increasingly treats absent dedicated cybersecurity resourcing as evidence of insufficient board oversight. This does not mean spending more for its own sake — it means boards explaining, with numbers, why current investment is proportionate to risk, with documented reasoning.

Consequences of non-compliance

Financial penalties

  • Essential entities: €10 million or 2% of global annual turnover.
  • Important entities: €7 million or 1.4% of global annual turnover.

These are minimum harmonised thresholds — national laws can set higher maximums.

Additional regulatory actions

Supervisory authorities can:

  • Issue binding instructions.
  • Order security audits at the entity’s expense.
  • Impose temporary bans on individuals exercising managerial functions in cases of serious or repeated violations.

Personal liability under NIS2 is not limited to gross negligence or intentional misconduct. The directive enables liability for infringements — meaning failure to comply, even without deliberate fault.

Directors and Officers (D&O) insurance may not provide backstop protection. Many policies exclude knowing violations of regulations. A board member aware of cybersecurity deficiencies who did not act may find their insurer declines to cover resulting claims.

The 30-day board agenda: a realistic plan

Week 1

  • Commission a written scope assessment.
  • Confirm competent authority registration status.

Week 2

  • Review and formally approve cybersecurity risk management measures under Article 21.
  • Ensure proper documentation of approvals.

Week 3

  • Schedule and complete board-level training.
  • Retain records of training completion.

Week 4

  • Validate incident response capability with a tabletop exercise.
  • Finalise the supplier risk register.

None of these require completing full compliance. They establish, on the record, that the management body understands its obligations and is actively discharging them.

Key takeaway

If your board cannot answer these questions in the next 30 days, the gap is not a technical one — it is a gap in how the organisation is being run. Documented policies are not the same as operational readiness. NIS2 makes that distinction legally binding.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.