Regulatory Framework
NIS2 Directive
EU Network and Information Security
NIS2 is the European Union’s mandatory cybersecurity directive for essential and important entities across critical infrastructure sectors. It establishes binding security measures, 24-hour incident reporting obligations, and personal liability for management bodies. It has been enforceable since October 2024, requiring stronger governance, risk management, supply chain security, and documented cybersecurity controls.
Regulation Overview
Type
EU Mandatory Compliance Directive
Certificate
No – compliance evidenced through audit
Enforcement Status
Active – transposition deadline October 2024
Applicable To
Essential and important entities in 18 sectors
Max Penalty – Essential
10 million EUR or 2% global turnover
Max Penalty – Important
7 million EUR or 1.4% global turnover
Enforcement Active
NIS2 transposition deadline was October 2024. National competent authorities across EU member states are actively supervising essential entities. Non-compliance is not a future risk. It is a current exposure.
What It Is
Understanding
the NIS2 Directive
The Network and Information Security Directive 2 (NIS2/EU 2022/2555) replaced the original NIS Directive in January 2023 and required transposition into national law across EU member states by October 2024. It significantly expands the scope of mandatory cybersecurity obligations in the EU.
NIS2 applies to essential entities and important entities across eighteen critical sectors. Essential entities face stricter supervision and higher maximum penalties. Important entities face reactive supervision. The classification depends on the sector and size thresholds defined in the directive.
More About
NIS2 Directive
The most significant change from NIS1 is the introduction of management body accountability. Under NIS2, the management bodies of essential and important entities are personally responsible for approving cybersecurity risk management measures. They can be held personally liable for non-compliance, and national competent authorities can temporarily prohibit individuals from exercising management functions.
NIS2 is not a certification standard. No certificate is issued. Compliance is demonstrated through evidence of implemented measures when audited by a national competent authority. The standard of evidence required is proportionate to the risk and the size of the organisation.
SUMMARY
Type
EU Mandatory Compliance Directive
Certificate
No – compliance evidenced through audit
Enforcement Status
Active – transposition deadline October 2024
Applicable To
Essential and important entities in 18 sectors
Max Penalty – Essential
10 million EUR or 2% global turnover
Max Penalty – Important
7 million EUR or 1.4% global turnover
Who is affected
NIS2 applies across eighteen critical sectors. Essential entities face proactive supervision and higher penalties. Important entities face reactive supervision. Supply chain partners face downstream obligations.
Essential Entities
Energy, Transport, Water, Health, Digital Infrastructure
Large organisations in energy, transport, water, wastewater, health, digital infrastructure, public administration, and banking sectors face the highest obligations and strictest supervision.
Important Entities
Postal, Waste, Chemicals, Food, Manufacturing
Mid-size organisations in postal services, waste management, chemicals, food production, manufacturing, and digital providers face NIS2 obligations with reactive rather than proactive supervision.
Supply Chain
Suppliers to Essential and Important Entities
Organisations that are not directly classified under NIS2 but supply services or products to essential entities face NIS2 Article 21(d) supply chain requirements passed down through contracts.
Key requirements
NIS2 Article 21 defines ten categories of mandatory security measures. All must be implemented on a risk-proportionate basis. These are not optional controls. They are binding obligations.
Art.21(2)(a)
Risk Analysis and Information System Security Policies
Documented policies for risk analysis and information system security. Management body must approve these policies.
Mandatory
Art.21(2)(b)
Incident Handling
Procedures for detecting, responding to, and recovering from incidents. Must support the reporting timelines in Article 23.
Mandatory
Art.21(2)(c)
Business Continuity and Crisis Management
Backup management, disaster recovery, and crisis management procedures to maintain operations during and after significant incidents.
Mandatory
Art.21(2)(d)
Supply Chain Security
Risk management measures for the security of the supply chain including relationships with direct suppliers and service providers.
Mandatory
Art.21(2)(e)
Security in Network and Information Systems Acquisition
Security in the acquisition, development, and maintenance of network and information systems including vulnerability handling and disclosure.
Mandatory
Art.21(2)(f)
Policies and Procedures to Assess Security Measures
Assessment of the effectiveness of cybersecurity risk management measures including internal audits.
Mandatory
Art.21(2)(g)
Cybersecurity Training
Basic cybersecurity hygiene practices and training for all personnel. Management body training is specifically required.
Mandatory
Art.21(2)(h)
Cryptography and Encryption
Policies and procedures on the use of cryptography and where appropriate encryption.
Mandatory
Art.21(2)(i)
Human Resources Security and Access Control
Personnel security measures, access control policies, and asset management procedures.
Mandatory
Art.21(2)(j)
Multi-Factor Authentication
Use of multi-factor authentication or continuous authentication solutions and secured voice, video, and text communications.
Mandatory
10M EUR
Maximum Penalty for Essential Entities – Plus Personal Liability
NIS2 sets maximum financial penalties of 10 million EUR or 2 percent of global annual turnover for essential entities, whichever is higher. For important entities the maximum is 7 million EUR or 1.4 percent of global turnover. Beyond financial penalties, national competent authorities can hold individual managers personally liable and temporarily prohibit them from exercising management functions.
How we deliver NIS2 engagements
We help essential and important entities implement the ten NIS2 Article 21 measures, build the evidence base for competent authority audit, and integrate NIS2 compliance into their broader security programmes.
Step 1 – Scope
NIS2 Entity Classification and Obligation Scoping
We confirm your NIS2 classification as essential or important, identify which national transposition law applies to your operations, and scope the full set of Article 21 obligations relevant to your sector and size.
Output: NIS2 classification confirmation and obligation scope definition
Step 2 – Gap Assessment
Article 21 Measures Gap Analysis
We assess your current state against all ten Article 21 measure categories and produce a prioritised gap register with remediation sequencing.
Output: NIS2 Article 21 gap report with prioritised finding register
Step 3 – Implement
Article 21 Measures Implementation
We implement the required measures alongside your team. Policies written, controls deployed, management training delivered, incident response procedures built to meet Article 23 reporting timelines.
Output: Implemented Article 21 measures with evidence collection
Step 4 – Evidence
Competent Authority Audit Readiness
We assemble the NIS2 compliance evidence pack in the format national competent authorities expect, and prepare your leadership team for management body accountability requirements.
Output: NIS2 Article 21 evidence pack ready for competent authority review
Related
Connected frameworks
and services
Service
EU Digital Regulation Programme
Explore →
Service
OT Security and IEC 62443
Explore →
Regulation
EU Cyber Resilience Act
Explore →
Is your organisation NIS2 compliant?
Book a 30-minute discovery call. We will confirm your NIS2 classification, scope your Article 21 obligations, and identify your highest-risk gaps.
You leave with:
- Your NIS2 classification
- Your Article 21 obligation scope
- Your top three remediation priorities