Regulatory Framework

NIS2 Compliance and Directive

NIS2 compliance is now a core cybersecurity requirement for organisations covered by the European Union’s Network and Information Security Directive. NIS2 establishes binding security measures for essential and important entities, strengthens management accountability, and requires documented cybersecurity controls, risk management, incident handling, supply chain security, and evidence of compliance.

Regulation Overview

Type

EU Mandatory Compliance Directive

Certificate

No – compliance evidenced through audit

Enforcement Status

Active – transposition deadline October 2024

Applicable To

Essential and important entities in 18 sectors

Max Penalty – Essential

10 million EUR or 2% global turnover

Max Penalty – Important

7 million EUR or 1.4% global turnover

Enforcement Active

NIS2 transposition deadline was October 2024. National competent authorities across EU member states are actively supervising essential entities. Non-compliance is not a future risk. It is a current exposure.

What It Is

Understanding
the NIS2 Directive

The Network and Information Security Directive 2 (NIS2/EU 2022/2555) replaced the original NIS Directive and expands mandatory cybersecurity obligations across the EU. NIS2 brings more organisations and sectors into scope and places greater emphasis on cybersecurity risk management, management accountability, incident response, supply chain security, and documented security measures.

NIS2 applies to essential entities and important entities across eighteen critical sectors. Essential entities face stricter supervision and higher maximum penalties. Important entities face reactive supervision. The classification depends on the sector and size thresholds defined in the directive.

More About
NIS2 Compliance

One of the most significant changes from NIS1 is stronger management body accountability. Under NIS2, management bodies of essential and important entities are responsible for approving cybersecurity risk management measures. Non-compliance can therefore create direct governance and management exposure.

NIS2 is not a certification standard. No certificate is issued. Compliance is demonstrated through evidence of implemented measures when audited by a national competent authority. The standard of evidence required is proportionate to the risk and the size of the organisation.

SUMMARY

Type

EU Mandatory Compliance Directive

Certificate

No – compliance evidenced through audit

Enforcement Status

Active – transposition deadline October 2024

Applicable To

Essential and important entities in 18 sectors

Max Penalty – Essential

10 million EUR or 2% global turnover

Max Penalty – Important

7 million EUR or 1.4% global turnover

NIS2 Compliance FAQs

NIS2 compliance questions answered

What is NIS2 compliance?

NIS2 compliance means implementing the cybersecurity risk management measures and related obligations that apply to an organisation under the NIS2 Directive and the relevant national transposition law. Compliance must be supported by appropriate controls, governance, procedures, and evidence.

Does NIS2 require a certification?

NIS2 is not presented as a certification standard. The page’s compliance model focuses on implementing the required security measures and maintaining evidence that can be reviewed by the relevant competent authority.

What are the main NIS2 requirements?

The core requirements include cybersecurity risk analysis, security policies, incident handling, business continuity, supply chain security, secure system acquisition and development, security assessments, cybersecurity training, cryptography, access control, and multi-factor authentication.

What does a NIS2 gap assessment include?

A NIS2 gap assessment compares the organisation’s current cybersecurity governance, controls, policies, and evidence against the applicable NIS2 requirements. The output can be used to prioritise remediation and build a practical compliance roadmap.

Who can benefit from NIS2 compliance consulting?

NIS2 compliance consulting is relevant to organisations that may be classified as essential or important entities, as well as organisations that support covered entities and need to address downstream supply chain requirements.

Who needs NIS2 compliance

NIS2 applies across eighteen critical sectors. Essential entities face proactive supervision and higher penalties, while important entities face reactive supervision. Organisations that supply essential and important entities can also face downstream cybersecurity and supply chain requirements through contractual relationships.

Essential Entities

Energy, Transport, Water, Health, Digital Infrastructure

Large organisations in energy, transport, water, wastewater, health, digital infrastructure, public administration, and banking sectors face the highest obligations and strictest supervision.

Important Entities

Postal, Waste, Chemicals, Food, Manufacturing

Mid-size organisations in postal services, waste management, chemicals, food production, manufacturing, and digital providers face NIS2 obligations with reactive rather than proactive supervision.

Supply Chain

Suppliers to Essential and Important Entities

Organisations that are not directly classified under NIS2 but supply services or products to essential entities face NIS2 Article 21(d) supply chain requirements passed down through contracts.

NIS2 requirements and security measures

NIS2 Article 21 defines ten categories of mandatory security measures. NIS2 compliance requires these measures to be implemented on a risk-proportionate basis and supported by appropriate policies, procedures, controls, responsibilities, and evidence.

Art.21(2)(a)

Risk Analysis and Information System Security Policies

Documented policies for risk analysis and information system security. Management body must approve these policies.

Mandatory

Art.21(2)(b)

Incident Handling

Procedures for detecting, responding to, and recovering from incidents. Must support the reporting timelines in Article 23.

Mandatory

Art.21(2)(c)

Business Continuity and Crisis Management

Backup management, disaster recovery, and crisis management procedures to maintain operations during and after significant incidents.

Mandatory

Art.21(2)(d)

Supply Chain Security

Risk management measures for the security of the supply chain including relationships with direct suppliers and service providers.

Mandatory

Art.21(2)(e)

Security in Network and Information Systems Acquisition

Security in the acquisition, development, and maintenance of network and information systems including vulnerability handling and disclosure.

Mandatory

Art.21(2)(f)

Policies and Procedures to Assess Security Measures

Assessment of the effectiveness of cybersecurity risk management measures including internal audits.

Mandatory

Art.21(2)(g)

Cybersecurity Training

Basic cybersecurity hygiene practices and training for all personnel. Management body training is specifically required.

Mandatory

Art.21(2)(h)

Cryptography and Encryption

Policies and procedures on the use of cryptography and where appropriate encryption.

Mandatory

Art.21(2)(i)

Human Resources Security and Access Control

Personnel security measures, access control policies, and asset management procedures.

Mandatory

Art.21(2)(j)

Multi-Factor Authentication

Use of multi-factor authentication or continuous authentication solutions and secured voice, video, and text communications.

Mandatory

10M EUR

Maximum Penalty for Essential Entities – Plus Personal Liability

NIS2 sets maximum financial penalties of 10 million EUR or 2 percent of global annual turnover for essential entities, whichever is higher. For important entities the maximum is 7 million EUR or 1.4 percent of global turnover. Beyond financial penalties, national competent authorities can hold individual managers personally liable and temporarily prohibit them from exercising management functions.

NIS2 compliance services and implementation

Our NIS2 compliance services help essential and important entities determine their obligations, assess gaps against the ten Article 21 measures, implement priority controls, build the required evidence base, and integrate NIS2 compliance into their broader cybersecurity programme.

Step 1 – Scope

NIS2 Entity Classification and Compliance Scoping

We confirm whether your organisation falls within the NIS2 essential or important entity categories, identify the applicable national transposition requirements, and scope the Article 21 obligations relevant to your sector, size, and operations.

Output: NIS2 classification confirmation and obligation scope definition

Step 2 – Gap Assessment

NIS2 Gap Assessment and Article 21 Analysis

We assess your current cybersecurity controls and governance against the ten NIS2 Article 21 measure categories and produce a prioritised gap register, remediation sequence, and practical improvement roadmap.

Output: NIS2 Article 21 gap report with prioritised finding register

Step 3 – Implement

NIS2 Compliance Implementation

We implement the required measures alongside your team. Policies written, controls deployed, management training delivered, incident response procedures built to meet Article 23 reporting timelines.

Output: Implemented Article 21 measures with evidence collection

Step 4 – Evidence

NIS2 Audit and Compliance Readiness

We assemble the NIS2 compliance evidence pack in the format national competent authorities expect, and prepare your leadership team for management body accountability requirements.

Output: NIS2 Article 21 evidence pack ready for competent authority review

Related

Connected frameworks
and services

Service

EU Digital Regulation programme

Explore →

Service

OT Security and IEC 62443

Explore →

Regulation

EU Cyber Resilience Act

Explore →

Is your organisation ready for NIS2 compliance?

Book a 30-minute discovery call. We will review your NIS2 classification, scope your Article 21 obligations, and identify the highest-risk gaps affecting your compliance programme.

You leave with:

  • Your NIS2 classification
  • Your Article 21 obligation scope
  • Your top three remediation priorities
Scroll to Top