The NIS2 Directive (Network and Information Systems Directive 2) has been transposed into national law across all EU member states. Unlike its predecessor NIS1, NIS2 dramatically expands scope — an estimated 160,000 additional organisations across Europe are now subject to binding cybersecurity obligations, many of them for the first time.
Non-compliance carries penalties of up to €10 million or 2% of global annual turnover — whichever is higher. More importantly, management can now be held personally liable for cybersecurity failures. This guide cuts through the regulatory noise and tells you precisely what to do.
Who is in scope for NIS2?
NIS2 distinguishes between Essential Entities and Important Entities. Both face mandatory obligations, but penalties differ.
Essential Entities
- · Energy (electricity, gas, oil, hydrogen)
- · Transport (aviation, rail, road, maritime)
- · Banking and financial market infrastructure
- · Health — hospitals, labs, pharma R&D
- · Drinking water & wastewater
- · Digital infrastructure (DNS, cloud, IXPs)
- · Space
Fine: up to €10M or 2% global turnover
Important Entities
- · Postal and courier services
- · Waste management
- · Chemicals manufacturing & distribution
- · Food production and distribution
- · Manufacturing (medical devices, electronics)
- · Digital providers (marketplaces, search engines, social)
- · Research organisations
Fine: up to €7M or 1.4% global turnover
Size thresholds: medium enterprises (50+ employees OR €10M+ revenue) and large enterprises are automatically in scope if they operate in the sectors above. Some smaller organisations in critical infrastructure are also in scope regardless of size.
The 10 mandatory NIS2 security measures
Article 21 of NIS2 mandates these minimum cybersecurity measures for all in-scope entities:
| # | Requirement | Key action |
|---|---|---|
| 01 | Risk analysis & policies | Documented risk assessment + approved ISMS policy |
| 02 | Incident handling | IR plan, 24h notification to authority, 72h full report |
| 03 | Business continuity | BCP + DRP tested annually with recovery time objectives |
| 04 | Supply chain security | Vendor risk assessments + contractual security clauses |
| 05 | Secure development | SSDLC policy, vulnerability disclosure process |
| 06 | Vulnerability management | Regular scanning, patching SLA, CVE tracking |
| 07 | Cybersecurity training | Annual security awareness + phishing simulations |
| 08 | Access control & MFA | Zero-trust architecture, MFA on all privileged accounts |
| 09 | Cryptography | Encryption at rest and in transit, key management policy |
| 10 | Asset management | Complete hardware & software inventory, shadow IT controls |
NIS2 Gap Assessment
Find out if your organisation is compliant — free audit in 24 hours
Our analysts map your current posture against all 10 NIS2 Article 21 requirements and deliver a prioritised remediation roadmap — at no cost, no commitment.
Request my free NIS2 audit →Penalties and personal liability
NIS2 introduces a critical shift: management bodies can be held personally liable for non-compliance. This means CEOs and board members, not just the organisation, can face sanctions.
- ! Essential entities: fines up to €10M or 2% of global annual turnover — whichever is higher.
- ! Important entities: fines up to €7M or 1.4% of global annual turnover.
- ! Management liability: national authorities can ban executives from management roles and require public disclosure of violations.
- ! Incident reporting failure: failing to notify within 24 hours is itself a sanctionable offence, separate from the underlying incident.
5-step NIS2 compliance roadmap
Determine scope — are you in scope?
Map your organisation's sector, size, and services. Check against the NIS2 Annex I and II entity lists. Some sub-processors and critical suppliers are also in scope by association.
Gap assessment against Article 21
Audit your current controls against each of the 10 mandatory measures. Document gaps with severity ratings and assign remediation owners. This is the foundation for your compliance roadmap.
Implement technical and organisational measures
Deploy MFA, patch management, encryption, SIEM/SOC capability, and BCP documentation. Establish the incident response procedure with named contacts for 24h notification.
Register with your national NIS2 authority
Most EU member states require in-scope entities to self-register. In France this is ANSSI, in Germany BSI, in Spain CCN-CERT. Deadlines vary — many have already passed.
Ongoing monitoring and annual review
NIS2 is not a one-time checkbox. Conduct annual penetration tests, update risk assessments after significant changes, and retrain staff. Keep documented evidence for audits.
Frequently asked questions
Who does NIS2 apply to?
NIS2 applies to medium and large organisations in 18 critical sectors, including energy, transport, banking, health, digital infrastructure, and managed IT services. Companies with 50+ employees or €10M+ revenue in these sectors are in scope.
What are the NIS2 penalties?
Essential entities face fines up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4% of turnover. Management can also be held personally liable.
What is the NIS2 incident reporting deadline?
NIS2 requires an initial notification within 24 hours of detecting a significant incident, a full report within 72 hours, and a final report within 1 month.
How long does NIS2 compliance take?
A thorough gap assessment and remediation roadmap takes 2–4 weeks. Full technical implementation typically takes 3–6 months depending on existing maturity.
Act before your next audit
Tell us your sector and size — get your NIS2 compliance roadmap today
Free gap assessment · Prioritised remediation plan · Response in 24 hours · No obligation
Start my free NIS2 audit →