Skip to Content

NIS2 Explained: What Businesses Need to Know About Europe’s Cybersecurity Rules

7 September 2026 by
Anup Aundhakar, Anup Aundhakar

Cybersecurity failures can disrupt far more than the organisation where they begin. An attack on a cloud provider can interrupt thousands of businesses. A compromised supplier can expose its customers. An outage at a hospital or energy company can affect essential services.

The European Union’s NIS2 Directive addresses this interconnected risk. It establishes cybersecurity requirements for organisations across 18 critical sectors, combining security measures, management accountability, incident reporting and regulatory oversight. It expands and replaces the original Network and Information Systems Directive. European Commission overview

For businesses, the practical challenge is to turn these requirements into everyday operations: knowing what needs protection, assigning responsibility and proving that safeguards work.

Who does NIS2 apply to?

NIS2 generally covers medium-sized and large organisations carrying out specified activities in sectors such as energy, transport, healthcare, drinking water, digital infrastructure and manufacturing. It also includes managed IT services, certain online platforms, postal services and research organisations.

However, sector membership alone does not settle applicability. The assessment depends on the services provided, organisational size, group relationships and specific exceptions.

Covered organisations fall into two categories:

  • Essential entities, which generally include large organisations in highly critical sectors and certain specifically covered entities.
  • Important entities, which include other organisations within scope.

Both categories face cybersecurity obligations. The main distinction is how they are supervised: essential entities face proactive oversight, while supervision of important entities generally follows evidence of possible non-compliance. Some organisations, including DNS providers and qualified trust service providers, can be covered regardless of size. NCSC explanation of scope and classification

The first step is therefore a documented scope assessment. Businesses should identify which legal entities, services and countries are involved before building their compliance programme.

Cybersecurity becomes a management responsibility

One of NIS2’s central provisions is management accountability.

Under Article 20, management bodies must approve cybersecurity risk-management measures, oversee their implementation and undertake training. They can also be held liable for infringements under the applicable rules. NIS2, Article 20

In practice, this means management needs enough information to make informed decisions. A useful board discussion should address questions such as:

  • Which business services would be most affected by an outage?
  • What are the largest unresolved security risks?
  • Have recovery arrangements been tested?
  • Which suppliers create significant dependencies?
  • Who can authorise an urgent response?

A security dashboard becomes more useful when it connects technical findings to service disruption, financial exposure and recovery capability.

The ten security areas at the centre of NIS2

Article 21 establishes ten core areas for cybersecurity risk management:

  1. Risk analysis and information-system security policies.
  2. Incident handling.
  3. Business continuity, backups, disaster recovery and crisis management.
  4. Supply-chain security.
  5. Secure acquisition, development and maintenance, including vulnerability handling.
  6. Assessment of security-control effectiveness.
  7. Cyber hygiene and cybersecurity training.
  8. Cryptography and encryption where appropriate.
  9. Personnel security, access control and asset management.
  10. Strong authentication and secure communications where appropriate.

These measures must be appropriate and proportionate to the organisation’s risks. NCSC explanation of Article 21

The practical difference lies in implementation. A backup policy should lead to successful restoration tests. An access-control policy should produce timely removal of former employees’ accounts. An incident-response plan should help people act under pressure.

ENISA’s implementation guidance provides examples of evidence and mappings to established security practices for specified digital and ICT service providers. It offers a useful model for connecting requirements with demonstrable controls. ENISA technical implementation guidance

Incident reporting requires preparation

NIS2 introduces staged reporting for significant incidents:

StageGeneral deadline
Early warningWithin 24 hours of becoming aware
Incident notificationWithin 72 hours of becoming aware
Final reportWithin one month after the incident notification

Reports must be submitted without undue delay. Additional rules cover requested updates, ongoing incidents and trust service providers, whose incident-notification deadline is shorter. NIS2, Article 23

These deadlines make advance preparation valuable. During an incident, teams need a clear route for deciding whether reporting is required, identifying the responsible authority and approving the submission.

A practical reporting playbook should include named decision-makers, backup contacts, reporting templates and an escalation process that works outside business hours.

Suppliers belong inside the security programme

NIS2 explicitly includes supply-chain security among its requirements. This makes supplier relationships part of an organisation’s cybersecurity risk assessment. Commission explanation of supply-chain requirements

A useful starting point is to rank suppliers by dependency and access. Consider what would happen if a provider became unavailable, lost sensitive information or had its privileged access compromised.

That assessment can guide contract terms, incident-notification expectations, access restrictions and contingency arrangements. Higher-risk relationships deserve closer attention and more substantial evidence.

Some digital providers face more detailed requirements

For specified providers—including cloud services, data centres, managed services, DNS services and certain online platforms—Implementing Regulation (EU) 2024/2690 adds detailed security requirements and criteria for significant incidents. Implementing Regulation 2024/2690

ENISA has published supporting technical guidance. The guidance is non-binding and should be used alongside the applicable legislation and national authority requirements. ENISA guidance explanation

What happens when organisations fail to comply?

Authorities can inspect organisations, request evidence, require audits and order corrective action.

For breaches of security and reporting obligations, NIS2 requires national maximum fines to reach at least:

  • Essential entities: €10 million or 2% of worldwide annual turnover, whichever is higher.
  • Important entities: €7 million or 1.4% of worldwide annual turnover, whichever is higher.

These figures establish the required level of maximum penalties; they are not automatic fines for every infringement. European Commission enforcement explanation

Where should a business begin?

A manageable implementation programme starts with six steps:

  1. Confirm scope: identify covered entities, services and jurisdictions.
  2. Assign ownership: establish management oversight and operational responsibilities.
  3. Assess gaps: compare existing practices with applicable requirements.
  4. Prioritise improvements: address the risks most likely to disrupt critical services.
  5. Test capabilities: exercise recovery, incident response and reporting.
  6. Retain evidence: record what was implemented, tested and corrected.

NIS2 is implemented through national law, so local requirements remain essential. The European Commission’s January 2026 amendment proposals also need to be distinguished from enacted obligations. European Commission status overview

For each applicable requirement, a business should be able to identify an owner, an operating control and evidence that the control works. That gives management a concrete basis for deciding what needs attention next.

SMB1001 Cybersecurity Certification Guide | SS NovaTech