Compliance NIS2 May 6, 2026 · 11 min read

NIS2 Compliance Guide 2026: What EU Businesses Must Do Now — or Face €10M Fines

NIS2 is fully enforced. Your organisation may already be in scope. Here is exactly what the directive requires, who it applies to, and the 5-step roadmap to achieve compliance before your next audit.

EF
Elena Fischer · Principal Security Analyst, WebGuard

The NIS2 Directive (Network and Information Systems Directive 2) has been transposed into national law across all EU member states. Unlike its predecessor NIS1, NIS2 dramatically expands scope — an estimated 160,000 additional organisations across Europe are now subject to binding cybersecurity obligations, many of them for the first time.

Non-compliance carries penalties of up to €10 million or 2% of global annual turnover — whichever is higher. More importantly, management can now be held personally liable for cybersecurity failures. This guide cuts through the regulatory noise and tells you precisely what to do.

Who is in scope for NIS2?

NIS2 distinguishes between Essential Entities and Important Entities. Both face mandatory obligations, but penalties differ.

Essential Entities

  • · Energy (electricity, gas, oil, hydrogen)
  • · Transport (aviation, rail, road, maritime)
  • · Banking and financial market infrastructure
  • · Health — hospitals, labs, pharma R&D
  • · Drinking water & wastewater
  • · Digital infrastructure (DNS, cloud, IXPs)
  • · Space

Fine: up to €10M or 2% global turnover

Important Entities

  • · Postal and courier services
  • · Waste management
  • · Chemicals manufacturing & distribution
  • · Food production and distribution
  • · Manufacturing (medical devices, electronics)
  • · Digital providers (marketplaces, search engines, social)
  • · Research organisations

Fine: up to €7M or 1.4% global turnover

Size thresholds: medium enterprises (50+ employees OR €10M+ revenue) and large enterprises are automatically in scope if they operate in the sectors above. Some smaller organisations in critical infrastructure are also in scope regardless of size.

The 10 mandatory NIS2 security measures

Article 21 of NIS2 mandates these minimum cybersecurity measures for all in-scope entities:

# Requirement Key action
01 Risk analysis & policies Documented risk assessment + approved ISMS policy
02 Incident handling IR plan, 24h notification to authority, 72h full report
03 Business continuity BCP + DRP tested annually with recovery time objectives
04 Supply chain security Vendor risk assessments + contractual security clauses
05 Secure development SSDLC policy, vulnerability disclosure process
06 Vulnerability management Regular scanning, patching SLA, CVE tracking
07 Cybersecurity training Annual security awareness + phishing simulations
08 Access control & MFA Zero-trust architecture, MFA on all privileged accounts
09 Cryptography Encryption at rest and in transit, key management policy
10 Asset management Complete hardware & software inventory, shadow IT controls

NIS2 Gap Assessment

Find out if your organisation is compliant — free audit in 24 hours

Our analysts map your current posture against all 10 NIS2 Article 21 requirements and deliver a prioritised remediation roadmap — at no cost, no commitment.

Request my free NIS2 audit →

Penalties and personal liability

NIS2 introduces a critical shift: management bodies can be held personally liable for non-compliance. This means CEOs and board members, not just the organisation, can face sanctions.

5-step NIS2 compliance roadmap

Step 1

Determine scope — are you in scope?

Map your organisation's sector, size, and services. Check against the NIS2 Annex I and II entity lists. Some sub-processors and critical suppliers are also in scope by association.

Step 2

Gap assessment against Article 21

Audit your current controls against each of the 10 mandatory measures. Document gaps with severity ratings and assign remediation owners. This is the foundation for your compliance roadmap.

Step 3

Implement technical and organisational measures

Deploy MFA, patch management, encryption, SIEM/SOC capability, and BCP documentation. Establish the incident response procedure with named contacts for 24h notification.

Step 4

Register with your national NIS2 authority

Most EU member states require in-scope entities to self-register. In France this is ANSSI, in Germany BSI, in Spain CCN-CERT. Deadlines vary — many have already passed.

Step 5

Ongoing monitoring and annual review

NIS2 is not a one-time checkbox. Conduct annual penetration tests, update risk assessments after significant changes, and retrain staff. Keep documented evidence for audits.

Frequently asked questions

Who does NIS2 apply to?

NIS2 applies to medium and large organisations in 18 critical sectors, including energy, transport, banking, health, digital infrastructure, and managed IT services. Companies with 50+ employees or €10M+ revenue in these sectors are in scope.

What are the NIS2 penalties?

Essential entities face fines up to €10 million or 2% of global annual turnover. Important entities face up to €7 million or 1.4% of turnover. Management can also be held personally liable.

What is the NIS2 incident reporting deadline?

NIS2 requires an initial notification within 24 hours of detecting a significant incident, a full report within 72 hours, and a final report within 1 month.

How long does NIS2 compliance take?

A thorough gap assessment and remediation roadmap takes 2–4 weeks. Full technical implementation typically takes 3–6 months depending on existing maturity.

Act before your next audit

Tell us your sector and size — get your NIS2 compliance roadmap today

Free gap assessment · Prioritised remediation plan · Response in 24 hours · No obligation

Start my free NIS2 audit →

Related articles

🛡️ Audit de sécurité gratuit — réponse en 24h, sans engagement

Obtenir mon audit gratuit →