Regulatory Framework

NIS2 Directive

NIS2 is the European Union’s mandatory cybersecurity directive for essential and important entities across critical infrastructure sectors. It establishes binding security measures, 24-hour incident reporting obligations, and personal liability for management bodies. It has been enforceable since October 2024, requiring stronger governance, risk management, supply chain security, and documented cybersecurity controls.

Regulation Overview

Type

EU Mandatory Compliance Directive

Certificate

No – compliance evidenced through audit

Enforcement Status

Active – transposition deadline October 2024

Applicable To

Essential and important entities in 18 sectors

Max Penalty – Essential

10 million EUR or 2% global turnover

Max Penalty – Important

7 million EUR or 1.4% global turnover

Enforcement Active

NIS2 transposition deadline was October 2024. National competent authorities across EU member states are actively supervising essential entities. Non-compliance is not a future risk. It is a current exposure.

What It Is

Understanding
the NIS2 Directive

The Network and Information Security Directive 2 (NIS2/EU 2022/2555) replaced the original NIS Directive in January 2023 and required transposition into national law across EU member states by October 2024. It significantly expands the scope of mandatory cybersecurity obligations in the EU.

NIS2 applies to essential entities and important entities across eighteen critical sectors. Essential entities face stricter supervision and higher maximum penalties. Important entities face reactive supervision. The classification depends on the sector and size thresholds defined in the directive.

More About
NIS2 Directive

The most significant change from NIS1 is the introduction of management body accountability. Under NIS2, the management bodies of essential and important entities are personally responsible for approving cybersecurity risk management measures. They can be held personally liable for non-compliance, and national competent authorities can temporarily prohibit individuals from exercising management functions.

NIS2 is not a certification standard. No certificate is issued. Compliance is demonstrated through evidence of implemented measures when audited by a national competent authority. The standard of evidence required is proportionate to the risk and the size of the organisation.

SUMMARY

Type

EU Mandatory Compliance Directive

Certificate

No – compliance evidenced through audit

Enforcement Status

Active – transposition deadline October 2024

Applicable To

Essential and important entities in 18 sectors

Max Penalty – Essential

10 million EUR or 2% global turnover

Max Penalty – Important

7 million EUR or 1.4% global turnover

Who is affected

NIS2 applies across eighteen critical sectors. Essential entities face proactive supervision and higher penalties. Important entities face reactive supervision. Supply chain partners face downstream obligations.

Essential Entities

Energy, Transport, Water, Health, Digital Infrastructure

Large organisations in energy, transport, water, wastewater, health, digital infrastructure, public administration, and banking sectors face the highest obligations and strictest supervision.

Important Entities

Postal, Waste, Chemicals, Food, Manufacturing

Mid-size organisations in postal services, waste management, chemicals, food production, manufacturing, and digital providers face NIS2 obligations with reactive rather than proactive supervision.

Supply Chain

Suppliers to Essential and Important Entities

Organisations that are not directly classified under NIS2 but supply services or products to essential entities face NIS2 Article 21(d) supply chain requirements passed down through contracts.

Key requirements

NIS2 Article 21 defines ten categories of mandatory security measures. All must be implemented on a risk-proportionate basis. These are not optional controls. They are binding obligations.

Art.21(2)(a)

Risk Analysis and Information System Security Policies

Documented policies for risk analysis and information system security. Management body must approve these policies.

Mandatory

Art.21(2)(b)

Incident Handling

Procedures for detecting, responding to, and recovering from incidents. Must support the reporting timelines in Article 23.

Mandatory

Art.21(2)(c)

Business Continuity and Crisis Management

Backup management, disaster recovery, and crisis management procedures to maintain operations during and after significant incidents.

Mandatory

Art.21(2)(d)

Supply Chain Security

Risk management measures for the security of the supply chain including relationships with direct suppliers and service providers.

Mandatory

Art.21(2)(e)

Security in Network and Information Systems Acquisition

Security in the acquisition, development, and maintenance of network and information systems including vulnerability handling and disclosure.

Mandatory

Art.21(2)(f)

Policies and Procedures to Assess Security Measures

Assessment of the effectiveness of cybersecurity risk management measures including internal audits.

Mandatory

Art.21(2)(g)

Cybersecurity Training

Basic cybersecurity hygiene practices and training for all personnel. Management body training is specifically required.

Mandatory

Art.21(2)(h)

Cryptography and Encryption

Policies and procedures on the use of cryptography and where appropriate encryption.

Mandatory

Art.21(2)(i)

Human Resources Security and Access Control

Personnel security measures, access control policies, and asset management procedures.

Mandatory

Art.21(2)(j)

Multi-Factor Authentication

Use of multi-factor authentication or continuous authentication solutions and secured voice, video, and text communications.

Mandatory

10M EUR

Maximum Penalty for Essential Entities – Plus Personal Liability

NIS2 sets maximum financial penalties of 10 million EUR or 2 percent of global annual turnover for essential entities, whichever is higher. For important entities the maximum is 7 million EUR or 1.4 percent of global turnover. Beyond financial penalties, national competent authorities can hold individual managers personally liable and temporarily prohibit them from exercising management functions.

How we deliver NIS2 engagements

We help essential and important entities implement the ten NIS2 Article 21 measures, build the evidence base for competent authority audit, and integrate NIS2 compliance into their broader security programmes.

Step 1 – Scope

NIS2 Entity Classification and Obligation Scoping

We confirm your NIS2 classification as essential or important, identify which national transposition law applies to your operations, and scope the full set of Article 21 obligations relevant to your sector and size.

Output: NIS2 classification confirmation and obligation scope definition

Step 2 – Gap Assessment

Article 21 Measures Gap Analysis

We assess your current state against all ten Article 21 measure categories and produce a prioritised gap register with remediation sequencing.

Output: NIS2 Article 21 gap report with prioritised finding register

Step 3 – Implement

Article 21 Measures Implementation

We implement the required measures alongside your team. Policies written, controls deployed, management training delivered, incident response procedures built to meet Article 23 reporting timelines.

Output: Implemented Article 21 measures with evidence collection

Step 4 – Evidence

Competent Authority Audit Readiness

We assemble the NIS2 compliance evidence pack in the format national competent authorities expect, and prepare your leadership team for management body accountability requirements.

Output: NIS2 Article 21 evidence pack ready for competent authority review

Related

Connected frameworks
and services

Service

EU Digital Regulation Programme

Explore →

Service

OT Security and IEC 62443

Explore →

Regulation

EU Cyber Resilience Act

Explore →

Is your organisation NIS2 compliant?

Book a 30-minute discovery call. We will confirm your NIS2 classification, scope your Article 21 obligations, and identify your highest-risk gaps.

You leave with:

  • Your NIS2 classification
  • Your Article 21 obligation scope
  • Your top three remediation priorities
Scroll to Top