These are the 7 points this article covers on what NIS2 is and who needs to comply:
- What NIS2 is
- Who needs to comply with NIS2 (essential and important entities)
- What compliance involves
- Incident reporting and risk management
- Penalties for non-compliance
- Timelines and application in the EU
- How to prepare and what to do next
Cyber threats are no longer just a technical issue. They are a business risk. In response, the EU adopted NIS2, the directive that strengthens cybersecurity in critical sectors and among certain digital and ICT service providers. If you operate in Europe, especially in cloud services, managed services or other covered digital infrastructure, you need to assess whether NIS2 applies to your organisation.
This article explains what NIS2 is, who may be required to comply, what compliance involves, and which timelines and penalties may apply. It is broader and more enforceable than the original NIS Directive, but the exact obligations still depend on the Directive, national transposition and any sector-specific rules.
What is NIS2?
NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaces and extends the original NIS Directive with a wider sectoral scope, clearer cybersecurity risk-management obligations, management accountability, incident-reporting requirements and stronger supervision.
The aim is to establish a common baseline for managing cyber risk across the EU and to improve resilience and incident response. The NIS2 Directive sets the EU framework, but it is a directive rather than a single directly applicable regulation. The practical requirements, competent authority and enforcement process must therefore be checked in the country where the relevant entity operates.
Who needs to comply with NIS2?
NIS2 uses two main categories: essential entities and important entities. The category depends on the sector, the organisation’s size, its role in critical services and whether a Member State identifies it directly under the Directive or national law.
Essential entities
Essential entities generally include larger organisations in highly critical sectors such as:
- Energy
- Transport
- Banking and financial-market infrastructures
- Health
- Drinking water and wastewater
- Digital infrastructure
- ICT service management between businesses, including certain managed and managed-security services
- Public administration
- Space
Certain entities, such as qualified trust-service providers, top-level domain registries and DNS service providers, may be essential regardless of size. Public authorities, public electronic-communications providers and entities designated as critical under related EU rules may also fall within the essential category under the applicable conditions.
Important entities
Important entities include organisations in sectors such as:
- Postal and courier services
- Waste management
- Chemicals
- Food production, processing and distribution
- Manufacturing of certain products
- Digital providers, including certain online marketplaces, search engines and social-networking platforms
- Research
An entity in an Annex I or Annex II sector that is not classified as essential will generally be treated as important, subject to the Directive and national implementation rules.
Size, sector and national designation
Size matters, but the simplified test of “more than 50 employees or €10 million in turnover” should not be treated as a complete legal assessment. NIS2 generally uses the EU definition of medium-sized and larger enterprises, while applying specific exceptions and national-designation powers.
Smaller organisations can still be brought within scope if they provide a critical service, are identified by a Member State, operate certain digital infrastructure or form part of a critical supply chain. SaaS is not automatically subject to NIS2. A SaaS provider must assess the exact service, sector, customer role, size and national rules rather than assume that serving an important customer is enough by itself.
The European Commission has reported that some Member States had not yet notified complete transposition measures in its latest status update. Check the current national transposition position, competent authority and registration process in each country where you operate.
What does NIS2 compliance involve?
Essential and important entities must take appropriate and proportionate technical, operational and organisational measures to manage cybersecurity risk and minimise the impact of incidents. The exact controls should be proportionate to the risks and relevant to the entity’s services.
Cybersecurity risk-management measures
The measures in Article 21 include, among other areas:
- Risk analysis and information-system security policies
- Incident handling
- Business continuity, disaster recovery and crisis management
- Supply-chain security, including direct suppliers and service providers
- Security in the acquisition, development and maintenance of systems
- Vulnerability handling and disclosure
- Assessing the effectiveness of cybersecurity measures
- Cybersecurity training and basic cyber hygiene
- Cryptography and encryption where appropriate
- Human-resources security, access control and asset management
- Multi-factor authentication or continuous authentication where appropriate
- Secure communications and emergency-communication systems where appropriate
ENISA’s NIS2 technical implementation guidance provides practical examples of evidence and mappings for several digital infrastructure, ICT service-management and digital-provider sectors. ENISA guidance is not a substitute for national law, but it can help organisations structure implementation.
Management responsibility and training
Management bodies must approve and oversee cybersecurity risk-management measures. Members of management bodies must receive cybersecurity training, and organisations should provide regular training to employees. NIS2 does not require one specific job title, but responsibilities must be clearly assigned, resourced and supervised.
The organisation should be able to identify who owns the programme, who can accept or escalate risk, who coordinates incident reporting, and how management receives evidence that measures are operating. National law may also create liability or other consequences for management in cases of serious non-compliance.
Supplier and operational resilience
NIS2 requires organisations to consider supply-chain security and the cybersecurity practices of direct suppliers and service providers. Contracts should address security requirements, incident cooperation, access, audit information, vulnerability handling and exit arrangements where relevant.
Operational resilience also needs evidence. This may include continuity plans, recovery tests, incident simulations, vulnerability-management records, access reviews, supplier assessments and management-review minutes. If you also process personal data, best practices for implementing the GDPR and a periodic GDPR audit can complement the NIS2 programme.
Incident reporting and risk management
Incident reporting deadlines
One of the most demanding requirements is reporting a significant incident. Under Article 23 of the Directive, the reporting sequence generally includes:
- An early warning without undue delay and, in any event, within 24 hours of becoming aware of the significant incident
- An incident notification within 72 hours, including an initial assessment of severity and impact
- Intermediate updates where requested or where the incident remains ongoing
- A final report no later than one month after the incident notification, subject to the Directive’s rules for ongoing incidents
The NIS2 incident-reporting provisions should be read together with national reporting channels and any sector-specific rules. Trust-service providers and some regulated sectors may have different or additional reporting arrangements.
Organisations therefore need internal protocols to detect, assess and escalate incidents. The process should define what counts as a potentially significant incident, who makes the assessment, who contacts the CSIRT or competent authority, who informs customers and how legal, communications and technical teams coordinate.
Ongoing risk management
Risk management is not a one-off exercise. The organisation should review its risk register and treatment plan when systems, suppliers, business structure, threats or regulatory requirements change. It should also record management decisions, accepted residual risk, overdue actions and evidence that controls have been tested.
An assessment completed in 2024 is not enough if the organisation has since introduced new cloud services, acquired a business, changed a critical supplier or experienced an incident. The supervisory question is whether the programme remains appropriate and operational.
Penalties for non-compliance
NIS2 gives national regulators powers to investigate, request information, carry out audits, order corrective measures and impose sanctions. The Directive sets minimum maximum levels that Member States must reflect in national law.
For essential entities, administrative fines can reach at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities, the level can reach at least €7 million or 1.4% of worldwide annual turnover, whichever is higher. The exact procedure, authority and additional measures depend on national implementation.
Non-compliance can also lead to customer loss, exclusion from supply chains, corrective orders, service restrictions and management consequences. For organisations operating in Spain, the article on NIS2 transposition in Spain provides additional context on national implementation and supervisory expectations. The organisation should not assume that having policies is enough. It needs operational evidence showing that the measures are implemented, reviewed and improved.
Timelines and national implementation
NIS2 entered into force in January 2023, and Member States were required to transpose it into national law by 17 October 2024. The Directive also required Member States to establish lists of essential and important entities and relevant registration mechanisms.
Implementation is not identical across the EU. Each organisation should verify the national law, registration or notification process, competent authority, reporting channel, supervisory approach and any sector-specific legislation that applies to it.
The fact that a Member State has not completed or notified full transposition does not make cyber risk disappear. Organisations operating in covered sectors should continue preparing their governance, risk, incident and supplier processes while confirming the legal position in each relevant country.
How PrivaLex can help with NIS2 compliance
At PrivaLex Partners, we support organisations that need clarity on whether NIS2 applies and those already in scope that need to implement or maintain the required programme. We begin with a scope assessment covering the entity’s sector, services, size, group structure, countries, suppliers and role in the digital or critical-service ecosystem.
We then map the applicable NIS2 requirements to an operating roadmap. This can include a risk register and treatment plan, cybersecurity policy, management responsibilities, incident-reporting playbooks, continuity and recovery processes, supplier controls, vulnerability management, training and evidence requirements. For SaaS businesses, our NIS2 compliance support for SaaS companies helps connect the service model to the relevant scope and control questions.
Our work focuses on making compliance demonstrable. We help teams connect each priority risk to measures, owners, deadlines and records, then define how evidence will be collected and reviewed. We can facilitate incident exercises, review supplier arrangements, prepare management reporting and identify the evidence needed for an inspection or customer assessment.
The implementation process can include an initial gap assessment, prioritised remediation plan, policy and procedure design, workshops with management and technical teams, supplier-risk reviews, incident-tabletop exercises and readiness checks. We help clarify what the organisation must do itself, what can be supported by technology and where legal or sector-specific advice is required.
Where organisations already use ISO 27001, GDPR, DORA or other frameworks, we identify shared controls and duplicated evidence while keeping the NIS2-specific requirements visible. We do not treat certification as a substitute for legal scope analysis or national implementation advice.
The result is a programme that can be explained to management, customers and authorities: a documented scope decision, accountable owners, current risks, tested response procedures and evidence that controls are operating and improving over time.
How to prepare for NIS2
To comply with NIS2, an organisation must not only have cybersecurity measures but also demonstrate that they are governed and operating. A practical readiness review should cover:
- Scope assessment and essential or important-entity classification
- Registration or notification requirements in each relevant Member State
- A current risk register and treatment plan
- Cybersecurity policy and assigned management responsibilities
- Tested incident-notification procedure and contact list
- Business-continuity, disaster-recovery and crisis-management evidence
- Supplier and ICT-service-provider due diligence and contract controls
- Vulnerability management, access control, MFA and asset-management records
- Role-based training records for management and employees
- Evidence of resilience testing, internal reviews and corrective actions
An information security management system aligned with ISO 27001 certification for EU startups can help organise many of these measures because both frameworks use a risk-based approach. ISO 27001 does not automatically prove NIS2 compliance, so the organisation should map the NIS2 requirements and national obligations separately.
5 Common NIS2 mistakes
1. Assuming NIS2 does not apply without checking
Organisations in digital or critical sectors should assess the exact service, size, role and national rules. SaaS, cloud and managed-service providers should not rely on a generic industry label.
2. Failing to assign management accountability
Without a named programme owner, management oversight and clear escalation routes, policies become difficult to operate and evidence.
3. Training only the IT team
NIS2 expects management training and regular employee awareness. Training should be documented, role-appropriate and connected to the risks employees actually create or manage.
4. Waiting until an incident to define reporting
The 24-hour early-warning window requires pre-agreed criteria, contacts, authority channels and decision rights. Improvising during an incident increases both operational and regulatory risk.
5. Treating risk assessment as a one-time exercise
NIS2 requires ongoing risk management. New systems, suppliers, threats and incidents should trigger review and, where necessary, changes to controls and treatment plans.
Conclusion
NIS2 is broader than the original NIS Directive, but the question “who needs to comply?” cannot be answered by sector labels alone. Organisations must assess their service, size, role, country, supply-chain position and any national designation or exception.
The most reliable preparation combines a documented scope decision, management accountability, risk-based controls, tested incident reporting, supplier oversight, employee training and evidence that the programme works. Verify the national position in every country where you operate and keep the assessment current as the organisation changes.
Schedule a strategic session with PrivaLex to clarify whether your organisation needs to comply with NIS2 and define a practical readiness plan.
Frequently Asked Questions (FAQs)
NIS2 is the EU directive on network and information security (Directive 2022/2555). Essential entities (energy, transport, banking, health, digital infrastructure, etc.) and important entities (including cloud service providers, SaaS, online marketplaces, managed IT services) must comply.
Size (employees and turnover) and role in critical supply chains also matter; each country has specified scope in its transposition.
If your SaaS company operates in the EU and falls under the definition of essential or important entity (by sector, size or role in critical infrastructure), yes.
Digital service providers that serve sensitive sectors or host critical data are often in scope. Check your Member State’s national transposition to confirm.
The directive requires reporting serious incidents with an early warning within a very short period (in practice within 24 hours of detection) and full notification within a longer period (e.g. 72 hours), with information on impact and measures. Member States may specify exact deadlines in national law.
For essential entities: up to €10 million or 2% of global annual turnover. For important entities: up to €7 million or 1.4% of global turnover. Authorities can also impose corrective measures, and in cases of serious negligence there may be personal liability for managers.
Yes. NIS2 requires that employees receive periodic cybersecurity training and that senior management is trained to understand risks and responsibilities. Training must be recurring, documented and role-appropriate. Authorities can request evidence during an inspection.
Check whether your organisation is an essential or important entity under national transposition; assign a compliance lead; carry out a cybersecurity risk assessment (infrastructure, services, APIs, third-party dependencies); implement proportionate technical and organisational measures (access control, multi-factor authentication, incident response, ongoing training); establish a tested incident notification protocol with defined roles; design a documented, role-based training programme; and keep documentation and evidence up to date.
Audits or inspections under NIS2 are not one-off; authorities can request evidence at any time, so integrating compliance into business-as-usual is key. A partner like PrivaLex can support you with assessment and implementation.
Next Step
Knowing what NIS2 is and who needs to comply is the first step; the next is to check whether your organisation is in scope and prepare in good time. Schedule a strategic session with PrivaLex and turn regulatory compliance into your competitive advantage.
