The Plain English Version

NIS2 is the EU directive that sets minimum cybersecurity rules for the organisations Europe depends on: energy, transport, health, water, digital infrastructure, manufacturing, food, and many more. It replaces the original NIS Directive and dramatically widens who is in scope.

Think of it as the EU saying: "If society needs you running, we need proof you take cyber risk seriously, and your management is personally on the hook for it."

Who Does NIS2 Apply To?

Medium and large organisations in eighteen sectors, split into essential entities (energy, transport, banking, health, water, digital infrastructure and others) and important entities (manufacturing, food, chemicals, postal services, digital providers and others). Classification determines your supervisory regime and fine ceiling. Some entities are in scope regardless of size, such as parts of digital infrastructure.

What NIS2 Requires

  • Risk management measures - Policies covering risk analysis, incident handling, business continuity, supply chain security, secure development, cryptography, access control and MFA
  • Incident reporting - An early warning within 24 hours of becoming aware of a significant incident, a notification within 72 hours, and a final report within one month of the notification
  • Management accountability - Boards must approve and oversee the measures, undergo training, and can be held personally liable for failures
  • Supply chain security - You must assess the security of your direct suppliers and service providers

Why This Matters for SMEs

Size exemptions do not stop the supply chain effect. If you supply an essential or important entity, expect their NIS2 obligations to flow down to you through due diligence questionnaires, security requirements in contracts, and audits.

Fines are substantial: up to EUR 10 million or 2 percent of worldwide turnover for essential entities, and up to EUR 7 million or 1.4 percent for important entities, whichever is higher.

Getting Prepared

Start with classification: work out whether you are an essential entity, an important entity, or a supplier to either. Then map your current controls against the NIS2 risk management measures, establish an incident response process that can hit the 24-hour early warning, and document everything. Member states transposed NIS2 into national law from October 2024, so enforcement is live and varies by country.