NIS2

Mandatory · EU

Defensible NIS2 compliance, without enterprise overhead.

Risk management, incident reporting, governance, and supply-chain security for essential and important entities under the EU NIS2 directive. Under Article 20, accountability sits with senior management — personally. Sized for SMBs.

Overview

A directive that crossed the line into board accountability.

NIS2 is the EU directive that replaces the original 2016 NIS Directive. It expands the cybersecurity baseline across 18 sectors and divides covered organisations into two tiers — essential entities (the larger, higher-criticality ones) and important entities — with a single set of mandatory security measures and a harmonised three-stage incident reporting timeline.

The shift from NIS1 is significant. Article 20 makes senior management personally accountable for approving and overseeing security measures; non-compliance can result in temporary bans from management roles. Article 21 specifies 10 mandatory security measures every covered entity must implement and document. Article 23 sets the three-stage notification timeline that begins the moment you become aware of a significant incident.

Entities subject to NIS2 increasingly deploy AI in core operations — and the EU AI Act layers Article 26 deployer obligations on top of NIS2 Article 21 risk management for any Annex III high-risk AI in scope. Our AI Governance & Security service extends the NIS2 risk-management framework to your AI estate, with ISO/IEC 42001 readiness mapped from day one.

Who NIS2 applies to

Two tests. Both must be satisfied for the directive to apply: (a) you operate in one of the 18 covered sectors, and (b) you meet the size threshold for that sector.

  • Essential entities

    Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space — at 250+ employees or €50M+ turnover.

  • Important entities

    Postal/courier, waste, chemicals, food, manufacturing (medical devices, electronics, vehicles, machinery), digital providers, research — at 50–249 employees or €10M–€50M turnover.

  • Special category — size-exempt

    Only four families are in scope regardless of size: DNS service providers, TLD name registries, trust service providers, and providers of public electronic communications. Cloud, datacentres, CDNs, MSPs and MSSPs are not — they follow the normal size threshold, so a small cloud provider can be out of scope entirely.

  • Other applicability triggers

    Entities identified as critical under the CER Directive, and providers of domain name registration services, are in scope regardless of size. Sole providers of an essential service, national or regional criticality, and cross-border impact bring smaller entities in too — but those are designations your member state makes case by case, not tests you can apply to yourself.

Article 21

Ten security measures, mandatory for every covered entity.

  1. 01Art. 21(2)(a)

    Risk analysis & security policies

    Documented information security policies and a working risk analysis-and-treatment process.

  2. 02Art. 21(2)(b)

    Incident handling

    Documented procedures for detection, classification, response, and reporting — including the NIS2 notification timelines.

  3. 03Art. 21(2)(c)

    Business continuity & crisis management

    Continuity plans, backup management, disaster recovery, and crisis management procedures.

  4. 04Art. 21(2)(d)

    Supply-chain security

    Security requirements for direct suppliers and service providers, including assessment of each supplier's practices.

  5. 05Art. 21(2)(e)

    Security in acquisition & development

    Security across procurement, development, and maintenance of network and information systems, including vulnerability handling.

  6. 06Art. 21(2)(f)

    Effectiveness assessment

    Policies and procedures for assessing the effectiveness of risk management measures — regular audits and testing.

  7. 07Art. 21(2)(g)

    Cyber hygiene & training

    Basic hygiene practices and awareness training for all staff, plus dedicated governance training for management bodies under Article 20.

  8. 08Art. 21(2)(h)

    Cryptography & encryption

    Policies on the use of cryptography and, where appropriate, encryption of data at rest and in transit.

  9. 09Art. 21(2)(i)

    HR security & access control

    Access control, asset management, joiner/mover/leaver processes, and the security of human resources.

  10. 10Art. 21(2)(j)

    MFA & secure communications

    Multi-factor authentication, continuous authentication where appropriate, and encrypted voice/video/text communications.

Penalties & consequences

Article 20: management liability is the real teeth.

Beyond the fines, national authorities can impose temporary bans on senior management from performing management functions. They can also issue binding instructions, require organisations to inform customers about threats or incidents, and publicly name non-compliant organisations.

For any SMB operating in B2B markets or regulated sectors, the reputational consequences of a public enforcement action — or a notified breach — typically far outweigh the fine itself.

  • Essential entity max fine

    €10M / 2%

    whichever is higher, of total worldwide annual turnover.

  • Important entity max fine

    €7M / 1.4%

    whichever is higher, of total worldwide annual turnover.

  • Three-stage report

    24h · 72h · 1mo

    early warning, full notification, final report — from the moment you become aware.

Our approach

NIS2 readiness, scoped and defensible.

What we deliver

  • Scoping assessment — confirms whether NIS2 applies, identifies entity category and registration obligations
  • Article 21 gap analysis — clause-by-clause assessment with prioritised gap register and costed roadmap
  • Risk register and risk-treatment plan aligned to Article 21(2)(a)
  • Incident response procedures with pre-written notification templates for all three reporting stages
  • Supply-chain security framework with supplier assessment process and contractual provisions
  • Management training under Article 20 — governance, oversight, and personal liability
  • Registration support with the national competent authority (e.g. ANSSI in France, BSI in Germany, CCB in Belgium, NCSC-NL in the Netherlands)
  • Ongoing governance under our vCISO service to maintain compliance year-round

Typical timeline

It depends on your starting baseline. ISO 27001 already in place? Faster.

  1. 4–8 weeks

    From an existing ISO 27001 baseline

    A focused gap-remediation program closing the NIS2-specific deltas: 24-hour notification process, Article 30 register, supply-chain assessment, management training.

  2. 3–6 months

    From limited existing controls

    End-to-end: gap analysis, risk assessment, policy build, incident response, supply-chain assessment, staff training, technical control implementation.

Free tool

Where do you stand on NIS2?

Run our free 8-minute readiness assessment and receive a personalised PDF report — your score, top gaps, and a 90-day roadmap. No slideware, no follow-up sequence.

Start the NIS2 assessment

About 8 minutes · Personalized PDF · No spam

FAQ

Common questions.

Does ISO 27001 satisfy NIS2 requirements?
NIS2 explicitly recognises ISO 27001 as evidence of compliance with its Article 21 risk management requirements — and a well-scoped ISMS typically satisfies 60–70% of NIS2 obligations. The remaining 30–40% is NIS2-specific: the 24-hour early warning, registration with the national authority, and the supply-chain security obligations of Article 21(2)(d). We design ISO 27001 implementations with NIS2 alignment built in from the start.
How do we register with our national authority?
Essential and important entities must register with their national competent authority — examples include ANSSI in France, BSI in Germany, CCB in Belgium, NCSC-NL in the Netherlands, ACN in Italy. The registration covers entity category (essential or important), sector, primary security contact, and compliance status. We assist organisations through the full registration process across EU member states, including determining the correct category and preparing the documentation.
What's the difference between essential and important entities?
Both must implement the same Article 21 measures and the same notification timelines. The differences are size thresholds (essential entities are larger), maximum penalties (€10M/2% vs €7M/1.4%), and supervisory approach. Essential entities are subject to proactive supervision — authorities can inspect them and require compliance evidence without waiting for an incident. Important entities are subject to reactive supervision — investigated after an incident, complaint, or intelligence indicating non-compliance.
How does NIS2 affect our suppliers?
Article 21(2)(d) creates a cascading obligation. Covered entities must assess the security practices of their direct suppliers and reflect appropriate security requirements in supplier relationships. In practice, NIS2-covered organisations are increasingly requiring their suppliers — even those below NIS2 thresholds — to demonstrate security controls, provide assessments, or comply with contractual requirements. If you supply services to a NIS2-covered organisation, expect more security questionnaires and contractual obligations.
How long does NIS2 compliance take to implement?
For an SMB starting with limited existing controls, reaching a defensible NIS2 compliance position typically takes 3–6 months. Organisations with existing ISO 27001 certification or a functioning ISMS can often reach compliance in 4–8 weeks of focused gap remediation. We work to your specific deadlines — including urgent timelines for organisations under regulatory or client pressure.
What does a NIS2 gap analysis produce?
A clause-by-clause assessment of your current compliance status (fully met / partially met / not yet implemented), a prioritised gap register identifying highest-risk non-conformities, a costed implementation roadmap with realistic timelines, and a management summary designed to brief board-level stakeholders on compliance exposure and required investment. The gap analysis is the essential first step — it tells you precisely what needs to be done and in what order.