Why NIS2 Matters to Your Organization
NIS2 is the European Union's expanded cybersecurity law, formally Directive (EU) 2022/2555. It replaces the original 2016 NIS Directive, widens the rules to roughly 160,000 entities across 18 sectors, and puts cybersecurity governance squarely on the desk of senior management. Member states had until 17 October 2024 to write it into national law. NIS2 raises the bar on risk management, incident reporting, and supply-chain security, and for the first time makes management bodies personally accountable, with fines reaching €10 million or 2 per cent of global turnover. This guide explains what NIS2 is, who it covers, what it requires, what non-compliance costs, and what organizations should do now.
What NIS2 Actually Is
The Successor to the 2016 NIS Directive
NIS2, formally Directive (EU) 2022/2555, is the second-generation EU law on the security of network and information systems. It replaces the original NIS Directive of 2016, which the EU judged too narrow and too unevenly applied across member states. NIS2 keeps the same goal, a common high level of cybersecurity across the Union, but widens the scope, tightens the obligations, and standardizes enforcement.
A Directive, Not a Regulation
NIS2 is a directive, which means it does not apply directly. Each of the 27 member states has to transpose it into national law, and details such as the exact fine ceilings, registration processes, and supervisory authorities can vary from country to country. This is a key difference from the EU AI Act or GDPR, which are regulations that apply uniformly. With NIS2, the obligation an organization faces is the national law, written on the NIS2 baseline. The European Commission's NIS2 page sets out that common baseline.
Why It Exists
The drivers are familiar: ransomware, supply-chain attacks, and the exposure of critical services have all grown sharply since 2016. NIS2 responds by bringing more sectors into scope, demanding board-level ownership, and harmonizing incident reporting so that a serious attack on a hospital, a port, or a cloud provider triggers the same baseline response wherever it happens in the Union.
Who NIS2 Covers
Essential and Important Entities
NIS2 sorts in-scope organizations into two classes. Essential entities, in the most critical sectors, face proactive supervision, meaning regular audits and inspections. Important entities face reactive supervision, triggered by an incident or evidence of a problem. Both classes have to meet the same core security obligations; the difference is in how closely they are watched and how high the fines can go.
The 18 Sectors
Coverage spans 18 sectors, split into sectors of high criticality and other critical sectors. High-criticality sectors include energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Other critical sectors include postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research. The reach into manufacturing, food, and digital providers is what pulls so many new organizations into scope.
Size Thresholds and Reach Beyond the EU
As a rule, NIS2 applies to medium and large organizations in the listed sectors, and excludes micro and small enterprises, though some entities are caught regardless of size because of their criticality. The directive also reaches certain non-EU providers of digital services that operate in the Union, which must designate an EU representative. The ECSO transposition tracker is a useful way to check how each member state has implemented these boundaries, since national variation is real.
What NIS2 Requires
Cybersecurity Risk-Management Measures
NIS2 requires in-scope entities to take appropriate and proportionate technical, operational, and organizational measures. The directive names a baseline set, including risk analysis and information-system security policies, incident handling, business continuity and backup, supply-chain security, secure procurement and development, vulnerability handling, basic cyber hygiene and training, cryptography, access control, and multi-factor authentication. Many organizations map these to ISO/IEC 27001 as the management-system scaffold.
Incident Reporting on a Tight Clock
Reporting is one of the sharpest changes. For a significant incident, an entity must send an early warning to its national authority or CSIRT within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. The short clock means the reporting workflow, decision rights, and escalation path have to be designed and rehearsed in advance, not improvised during a live incident.
Supply-Chain Security and Board Oversight
NIS2 makes supply-chain risk an explicit obligation, requiring entities to address the security of their suppliers and service providers. It also requires management bodies to approve the cybersecurity measures and oversee their implementation, and to undergo training. The WEF Global Cybersecurity Outlook documents why supply-chain and board-level cyber risk have become the dominant concerns for senior leaders, which is exactly the ground NIS2 now regulates.
Penalties and Personal Accountability
| Category | Maximum administrative fine | Supervision |
|---|---|---|
| Essential entities | Up to €10 million or 2% of total worldwide annual turnover, whichever is higher. | Proactive: regular audits, inspections, and security scans. |
| Important entities | Up to €7 million or 1.4% of total worldwide annual turnover, whichever is higher. | Reactive: triggered by an incident or evidence of non-compliance. |
| Senior management | Personal liability, possible temporary bans from management roles, and public disclosure of responsibility. | Management must approve and oversee measures and complete cyber training. |
Member states may set fines above these floors but not below them; some, such as Germany, have legislated higher ceilings. The headline change is not just the size of the fines but the move to personal accountability: NIS2 makes the board, not only the IT function, answerable for cybersecurity. That is what turns NIS2 from an IT project into a governance one.
What Organizations Should Do Now
Confirm Scope and Classification
The first step is to determine whether the organization is in scope at all, and if so, whether it is an essential or important entity under the relevant national law. Many companies, especially in manufacturing, food, and digital services, are surprised to find themselves caught. Suppliers to in-scope entities are often pulled in contractually even when the directive does not name them directly.
Close the Gap Against the Baseline
With scope confirmed, run a gap assessment against the NIS2 risk-management measures and the national transposition. The fastest route for most organizations is to align with an established framework such as ISO/IEC 27001 and then map the NIS2-specific requirements, particularly incident reporting and supply-chain security, on top of it.
Build Board-Level Capability
Because NIS2 mandates management oversight and training, cyber literacy at board and executive level is now a legal expectation, not a nice-to-have. Structured programs across cybersecurity and digital transformation help senior teams meet the oversight obligation and make the reporting and governance workflows real before an incident tests them.
NIS2 is best read not as an IT compliance task but as a governance shift: it puts cybersecurity on the board agenda, ties it to personal accountability, and sets a clock on how fast an organization has to respond when something goes wrong.
Frequently Asked Questions
What is the difference between NIS and NIS2?
NIS2 is the 2022 successor to the original 2016 NIS Directive. It widens the number of sectors and entities in scope, standardizes security and reporting obligations across member states, introduces stricter supervision and fines, and makes senior management personally accountable for cybersecurity.
Does NIS2 apply to my company?
Generally NIS2 applies to medium and large organizations operating in one of its 18 sectors, with some smaller entities caught because of their criticality. Certain non-EU digital-service providers active in the Union are also in scope. Because it is a directive, the precise test is set by national law.
What are the NIS2 incident-reporting deadlines?
For a significant incident, an early warning is due within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. The short timelines mean the escalation and reporting process has to be designed and rehearsed in advance.
What are the fines for NIS2 non-compliance?
For essential entities, up to €10 million or 2 per cent of global annual turnover, whichever is higher. For important entities, up to €7 million or 1.4 per cent. Member states may set higher ceilings, and senior managers can face personal liability and temporary management bans.
How does NIS2 relate to ISO/IEC 27001?
NIS2 is a binding legal requirement; ISO/IEC 27001 is a voluntary information-security management standard. Many organizations use ISO/IEC 27001 as the framework that operationalizes the NIS2 risk-management measures, then add the NIS2-specific obligations such as incident reporting and supply-chain security on top.
Turn NIS2 From a Compliance Risk Into a Governance Strength
EuroQuest International delivers cybersecurity, governance, and digital-transformation programs for boards, security leaders, and the teams that support them. Build the oversight, incident-response, and supply-chain capability NIS2 now expects, before an audit or an incident tests it.
Browse EuroQuest Training Categories