Defensible NIS2 compliance, without enterprise overhead.
Risk management, incident reporting, governance, and supply-chain security for essential and important entities under the EU NIS2 directive. Under Article 20, accountability sits with senior management — personally. Sized for SMBs.
Overview
A directive that crossed the line into board accountability.
NIS2 is the EU directive that replaces the original 2016 NIS Directive. It expands the cybersecurity baseline across 18 sectors and divides covered organisations into two tiers — essential entities (the larger, higher-criticality ones) and important entities — with a single set of mandatory security measures and a harmonised three-stage incident reporting timeline.
The shift from NIS1 is significant. Article 20 makes senior management personally accountable for approving and overseeing security measures; non-compliance can result in temporary bans from management roles. Article 21 specifies 10 mandatory security measures every covered entity must implement and document. Article 23 sets the three-stage notification timeline that begins the moment you become aware of a significant incident.
Entities subject to NIS2 increasingly deploy AI in core operations — and the EU AI Act layers Article 26 deployer obligations on top of NIS2 Article 21 risk management for any Annex III high-risk AI in scope. Our AI Governance & Security service extends the NIS2 risk-management framework to your AI estate, with ISO/IEC 42001 readiness mapped from day one.
Who NIS2 applies to
Two tests. Both must be satisfied for the directive to apply: (a) you operate in one of the 18 covered sectors, and (b) you meet the size threshold for that sector.
Essential entities
Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space — at 250+ employees or €50M+ turnover.
Important entities
Postal/courier, waste, chemicals, food, manufacturing (medical devices, electronics, vehicles, machinery), digital providers, research — at 50–249 employees or €10M–€50M turnover.
Special category — size-exempt
Only four families are in scope regardless of size: DNS service providers, TLD name registries, trust service providers, and providers of public electronic communications. Cloud, datacentres, CDNs, MSPs and MSSPs are not — they follow the normal size threshold, so a small cloud provider can be out of scope entirely.
Other applicability triggers
Entities identified as critical under the CER Directive, and providers of domain name registration services, are in scope regardless of size. Sole providers of an essential service, national or regional criticality, and cross-border impact bring smaller entities in too — but those are designations your member state makes case by case, not tests you can apply to yourself.
Article 21
Ten security measures, mandatory for every covered entity.
- 01Art. 21(2)(a)
Risk analysis & security policies
Documented information security policies and a working risk analysis-and-treatment process.
- 02Art. 21(2)(b)
Incident handling
Documented procedures for detection, classification, response, and reporting — including the NIS2 notification timelines.
- 03Art. 21(2)(c)
Business continuity & crisis management
Continuity plans, backup management, disaster recovery, and crisis management procedures.
- 04Art. 21(2)(d)
Supply-chain security
Security requirements for direct suppliers and service providers, including assessment of each supplier's practices.
- 05Art. 21(2)(e)
Security in acquisition & development
Security across procurement, development, and maintenance of network and information systems, including vulnerability handling.
- 06Art. 21(2)(f)
Effectiveness assessment
Policies and procedures for assessing the effectiveness of risk management measures — regular audits and testing.
- 07Art. 21(2)(g)
Cyber hygiene & training
Basic hygiene practices and awareness training for all staff, plus dedicated governance training for management bodies under Article 20.
- 08Art. 21(2)(h)
Cryptography & encryption
Policies on the use of cryptography and, where appropriate, encryption of data at rest and in transit.
- 09Art. 21(2)(i)
HR security & access control
Access control, asset management, joiner/mover/leaver processes, and the security of human resources.
- 10Art. 21(2)(j)
MFA & secure communications
Multi-factor authentication, continuous authentication where appropriate, and encrypted voice/video/text communications.
Penalties & consequences
Article 20: management liability is the real teeth.
Beyond the fines, national authorities can impose temporary bans on senior management from performing management functions. They can also issue binding instructions, require organisations to inform customers about threats or incidents, and publicly name non-compliant organisations.
For any SMB operating in B2B markets or regulated sectors, the reputational consequences of a public enforcement action — or a notified breach — typically far outweigh the fine itself.
Essential entity max fine
€10M / 2%
whichever is higher, of total worldwide annual turnover.
Important entity max fine
€7M / 1.4%
whichever is higher, of total worldwide annual turnover.
Three-stage report
24h · 72h · 1mo
early warning, full notification, final report — from the moment you become aware.
Our approach
NIS2 readiness, scoped and defensible.
What we deliver
- Scoping assessment — confirms whether NIS2 applies, identifies entity category and registration obligations
- Article 21 gap analysis — clause-by-clause assessment with prioritised gap register and costed roadmap
- Risk register and risk-treatment plan aligned to Article 21(2)(a)
- Incident response procedures with pre-written notification templates for all three reporting stages
- Supply-chain security framework with supplier assessment process and contractual provisions
- Management training under Article 20 — governance, oversight, and personal liability
- Registration support with the national competent authority (e.g. ANSSI in France, BSI in Germany, CCB in Belgium, NCSC-NL in the Netherlands)
- Ongoing governance under our vCISO service to maintain compliance year-round
Typical timeline
It depends on your starting baseline. ISO 27001 already in place? Faster.
4–8 weeks
From an existing ISO 27001 baseline
A focused gap-remediation program closing the NIS2-specific deltas: 24-hour notification process, Article 30 register, supply-chain assessment, management training.
3–6 months
From limited existing controls
End-to-end: gap analysis, risk assessment, policy build, incident response, supply-chain assessment, staff training, technical control implementation.
Free tool
Where do you stand on NIS2?
Run our free 8-minute readiness assessment and receive a personalised PDF report — your score, top gaps, and a 90-day roadmap. No slideware, no follow-up sequence.
Start the NIS2 assessmentFAQ