Regulatory Framework
NIS2 Compliance and Directive
EU Network and Information Security
NIS2 compliance is now a core cybersecurity requirement for organisations covered by the European Union’s Network and Information Security Directive. NIS2 establishes binding security measures for essential and important entities, strengthens management accountability, and requires documented cybersecurity controls, risk management, incident handling, supply chain security, and evidence of compliance.
Regulation Overview
Type
EU Mandatory Compliance Directive
Certificate
No – compliance evidenced through audit
Enforcement Status
Active – transposition deadline October 2024
Applicable To
Essential and important entities in 18 sectors
Max Penalty – Essential
10 million EUR or 2% global turnover
Max Penalty – Important
7 million EUR or 1.4% global turnover
Enforcement Active
NIS2 transposition deadline was October 2024. National competent authorities across EU member states are actively supervising essential entities. Non-compliance is not a future risk. It is a current exposure.
What It Is
Understanding
the NIS2 Directive
The Network and Information Security Directive 2 (NIS2/EU 2022/2555) replaced the original NIS Directive and expands mandatory cybersecurity obligations across the EU. NIS2 brings more organisations and sectors into scope and places greater emphasis on cybersecurity risk management, management accountability, incident response, supply chain security, and documented security measures.
NIS2 applies to essential entities and important entities across eighteen critical sectors. Essential entities face stricter supervision and higher maximum penalties. Important entities face reactive supervision. The classification depends on the sector and size thresholds defined in the directive.
More About
NIS2 Compliance
One of the most significant changes from NIS1 is stronger management body accountability. Under NIS2, management bodies of essential and important entities are responsible for approving cybersecurity risk management measures. Non-compliance can therefore create direct governance and management exposure.
NIS2 is not a certification standard. No certificate is issued. Compliance is demonstrated through evidence of implemented measures when audited by a national competent authority. The standard of evidence required is proportionate to the risk and the size of the organisation.
SUMMARY
Type
EU Mandatory Compliance Directive
Certificate
No – compliance evidenced through audit
Enforcement Status
Active – transposition deadline October 2024
Applicable To
Essential and important entities in 18 sectors
Max Penalty – Essential
10 million EUR or 2% global turnover
Max Penalty – Important
7 million EUR or 1.4% global turnover
NIS2 Compliance FAQs
NIS2 compliance questions answered
What is NIS2 compliance?
NIS2 compliance means implementing the cybersecurity risk management measures and related obligations that apply to an organisation under the NIS2 Directive and the relevant national transposition law. Compliance must be supported by appropriate controls, governance, procedures, and evidence.
Does NIS2 require a certification?
NIS2 is not presented as a certification standard. The page’s compliance model focuses on implementing the required security measures and maintaining evidence that can be reviewed by the relevant competent authority.
What are the main NIS2 requirements?
The core requirements include cybersecurity risk analysis, security policies, incident handling, business continuity, supply chain security, secure system acquisition and development, security assessments, cybersecurity training, cryptography, access control, and multi-factor authentication.
What does a NIS2 gap assessment include?
A NIS2 gap assessment compares the organisation’s current cybersecurity governance, controls, policies, and evidence against the applicable NIS2 requirements. The output can be used to prioritise remediation and build a practical compliance roadmap.
Who can benefit from NIS2 compliance consulting?
NIS2 compliance consulting is relevant to organisations that may be classified as essential or important entities, as well as organisations that support covered entities and need to address downstream supply chain requirements.
Who needs NIS2 compliance
NIS2 applies across eighteen critical sectors. Essential entities face proactive supervision and higher penalties, while important entities face reactive supervision. Organisations that supply essential and important entities can also face downstream cybersecurity and supply chain requirements through contractual relationships.
Essential Entities
Energy, Transport, Water, Health, Digital Infrastructure
Large organisations in energy, transport, water, wastewater, health, digital infrastructure, public administration, and banking sectors face the highest obligations and strictest supervision.
Important Entities
Postal, Waste, Chemicals, Food, Manufacturing
Mid-size organisations in postal services, waste management, chemicals, food production, manufacturing, and digital providers face NIS2 obligations with reactive rather than proactive supervision.
Supply Chain
Suppliers to Essential and Important Entities
Organisations that are not directly classified under NIS2 but supply services or products to essential entities face NIS2 Article 21(d) supply chain requirements passed down through contracts.
NIS2 requirements and security measures
NIS2 Article 21 defines ten categories of mandatory security measures. NIS2 compliance requires these measures to be implemented on a risk-proportionate basis and supported by appropriate policies, procedures, controls, responsibilities, and evidence.
Art.21(2)(a)
Risk Analysis and Information System Security Policies
Documented policies for risk analysis and information system security. Management body must approve these policies.
Mandatory
Art.21(2)(b)
Incident Handling
Procedures for detecting, responding to, and recovering from incidents. Must support the reporting timelines in Article 23.
Mandatory
Art.21(2)(c)
Business Continuity and Crisis Management
Backup management, disaster recovery, and crisis management procedures to maintain operations during and after significant incidents.
Mandatory
Art.21(2)(d)
Supply Chain Security
Risk management measures for the security of the supply chain including relationships with direct suppliers and service providers.
Mandatory
Art.21(2)(e)
Security in Network and Information Systems Acquisition
Security in the acquisition, development, and maintenance of network and information systems including vulnerability handling and disclosure.
Mandatory
Art.21(2)(f)
Policies and Procedures to Assess Security Measures
Assessment of the effectiveness of cybersecurity risk management measures including internal audits.
Mandatory
Art.21(2)(g)
Cybersecurity Training
Basic cybersecurity hygiene practices and training for all personnel. Management body training is specifically required.
Mandatory
Art.21(2)(h)
Cryptography and Encryption
Policies and procedures on the use of cryptography and where appropriate encryption.
Mandatory
Art.21(2)(i)
Human Resources Security and Access Control
Personnel security measures, access control policies, and asset management procedures.
Mandatory
Art.21(2)(j)
Multi-Factor Authentication
Use of multi-factor authentication or continuous authentication solutions and secured voice, video, and text communications.
Mandatory
10M EUR
Maximum Penalty for Essential Entities – Plus Personal Liability
NIS2 sets maximum financial penalties of 10 million EUR or 2 percent of global annual turnover for essential entities, whichever is higher. For important entities the maximum is 7 million EUR or 1.4 percent of global turnover. Beyond financial penalties, national competent authorities can hold individual managers personally liable and temporarily prohibit them from exercising management functions.
NIS2 compliance services and implementation
Our NIS2 compliance services help essential and important entities determine their obligations, assess gaps against the ten Article 21 measures, implement priority controls, build the required evidence base, and integrate NIS2 compliance into their broader cybersecurity programme.
Step 1 – Scope
NIS2 Entity Classification and Compliance Scoping
We confirm whether your organisation falls within the NIS2 essential or important entity categories, identify the applicable national transposition requirements, and scope the Article 21 obligations relevant to your sector, size, and operations.
Output: NIS2 classification confirmation and obligation scope definition
Step 2 – Gap Assessment
NIS2 Gap Assessment and Article 21 Analysis
We assess your current cybersecurity controls and governance against the ten NIS2 Article 21 measure categories and produce a prioritised gap register, remediation sequence, and practical improvement roadmap.
Output: NIS2 Article 21 gap report with prioritised finding register
Step 3 – Implement
NIS2 Compliance Implementation
We implement the required measures alongside your team. Policies written, controls deployed, management training delivered, incident response procedures built to meet Article 23 reporting timelines.
Output: Implemented Article 21 measures with evidence collection
Step 4 – Evidence
NIS2 Audit and Compliance Readiness
We assemble the NIS2 compliance evidence pack in the format national competent authorities expect, and prepare your leadership team for management body accountability requirements.
Output: NIS2 Article 21 evidence pack ready for competent authority review
Related
Connected frameworks
and services
Service
EU Digital Regulation programme
Explore →
Service
OT Security and IEC 62443
Explore →
Regulation
EU Cyber Resilience Act
Explore →
Is your organisation ready for NIS2 compliance?
Book a 30-minute discovery call. We will review your NIS2 classification, scope your Article 21 obligations, and identify the highest-risk gaps affecting your compliance programme.
You leave with:
- Your NIS2 classification
- Your Article 21 obligation scope
- Your top three remediation priorities