Back to blog
EU & UK

NIS2 Directive: who it covers and what it demands

The EU NIS2 Directive widens cybersecurity obligations across sectors, adds strict incident reporting deadlines, and makes management personally accountable. What it requires and how to prepare.
GRC Copilot Team
NIS2 Directive: who it covers and what it demands

NIS2 is the European Union directive that raises baseline cybersecurity requirements across a much wider set of sectors than its predecessor, and holds senior management personally accountable for compliance. Because it is a directive rather than a regulation, it takes effect through each member state's national law - so exact obligations and penalties vary by country.

Who is in scope

NIS2 distinguishes two tiers, both subject to the same core security obligations but supervised differently:

  • Essential entities - sectors such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space.
  • Important entities - sectors including postal and courier services, waste management, chemicals, food, manufacturing of medical devices and other critical products, digital providers and research.

Size generally matters too - medium and large organisations in these sectors are typically captured, with some entities in scope regardless of size because of their criticality. Essential entities face proactive supervision; important entities are supervised reactively after an incident.

The core requirements

NIS2 requires appropriate and proportionate technical, operational and organisational measures, explicitly including:

  • Risk analysis and information system security policies
  • Incident handling
  • Business continuity, backup management and crisis management
  • Supply chain security, including relationships with direct suppliers and service providers
  • Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure
  • Policies to assess the effectiveness of the measures
  • Basic cyber hygiene and security training
  • Cryptography and encryption policies
  • Human resources security, access control and asset management
  • Multi-factor authentication and secured communications

Incident reporting: the tight clock

This is where NIS2 differs most sharply from ordinary practice. For significant incidents, a staged timeline applies:

  1. Within 24 hours - an early warning to the CSIRT or competent authority.
  2. Within 72 hours - an incident notification with an initial assessment, severity and impact.
  3. Within one month - a final report covering root cause, mitigation and cross-border impact.

Twenty-four hours is short. Meeting it requires a pre-agreed severity definition, a named decision-maker with authority to notify, and prepared templates - decided in advance, not during the incident.

Get NIS2-ready without starting from zero

GRC Copilot assesses you against NIS2, reuses the evidence from your existing ISO 27001 or SOC 2 work, and tracks the gaps - including supply chain and incident reporting readiness.

Management accountability

NIS2 makes management bodies responsible for approving and overseeing the cybersecurity risk management measures, and requires them to undergo training. National implementations may attach personal consequences for serious breaches of that duty. In practice this means cybersecurity must appear on the board agenda with documented decisions - not delegated silently to IT.

How to prepare

  1. Confirm whether you are in scope under the law of each member state where you operate - and remember you may be captured indirectly as a supplier to an in-scope entity.
  2. Run a gap assessment against the required measures.
  3. Fix incident reporting first - the 24-hour clock is the hardest obligation to retrofit under pressure.
  4. Address supply chain security - tier suppliers, add security clauses, and assess the critical ones.
  5. Brief and train the management body, and minute it.
  6. Reuse existing evidence - if you run ISO 27001, much of the substance is already in place.
NIS2 rewards organisations that already run a real management system. The obligations map closely onto ISO 27001, so the work is usually gap-closing and reporting readiness rather than a new programme.

Frequently asked questions

Does NIS2 apply to companies outside the EU?

It can. Entities established outside the EU that provide in-scope services within the EU may fall under it and can be required to designate an EU representative. Non-EU suppliers are also affected indirectly through customers' supply chain obligations.

What counts as a significant incident?

Broadly, one causing severe operational disruption or financial loss, or affecting others through considerable material or non-material damage. National guidance refines the thresholds - confirm them for your member state.

Does ISO 27001 certification satisfy NIS2?

Not automatically, but it covers much of the substance. The most common remaining gaps are the incident reporting timeline, supply chain specifics and documented management-body involvement.

What are the penalties?

Set by national law, with the directive establishing significant maximum administrative fines - higher for essential entities than important ones - plus supervisory measures. Check the implementing law in your jurisdiction.

Key takeaways

  • NIS2 widens scope across many sectors and applies through national law.
  • The 24-hour early warning is the hardest obligation to retrofit - prepare it now.
  • Supply chain security is an explicit, named requirement.
  • Management bodies must approve, oversee and be trained - and it must be documented.
#nis2 #eu #directive #incident-reporting #supply-chain