The NIS2 Shift: Why This Directive Changes Everything

June 15, 2026 | Compliance

The NIS2 Shift: Why This Directive Changes Everything

Discover what NIS2 compliance requires, which sectors are affected, and how companies can prepare for stricter EU cybersecurity obligations.
This article explores NIS2, key compliance requirements, affected sectors, and the actions companies must take to meet the new EU cybersecurity rules.

The European Union is facing a rapidly escalating cyberthreat landscape. Attacks on organizations that provide essential or important services can disrupt entire societies.

To strengthen resilience, the EU introduced the first NIS Directive in 2016, and in 2022, followed with NIS2, a stricter and broader update that expands the sectors covered, increases fines, and assigns greater responsibility to company management in the event of serious incidents.

Who Must Comply With NIS2?

NIS2 applies to organizations that meet both of the following conditions:

To strengthen resilience, the EU introduced the first NIS Directive in 2016, and in 2022, followed with NIS2, a stricter and broader update that expands the sectors covered, increases fines, and assigns greater responsibility to company management in the event of serious incidents.

1. Size threshold

  • More than 50 employees, or
  • Annual turnover above €10 million

2. Sector classification

NIS2 distinguishes between Essential Entities (highly critical sectors) and Important Entities (critical sectors).

Essential Sectors.
Including: “Energy, transport, banking, healthcare, water, digital infrastructure (cloud services, data centers), ICT service management, and public administration.”
Important Sectors.
Including: “Postal services, waste management, manufacturing of chemicals and food, production of electronics and machinery, and digital providers (marketplaces and search engines).”

Important note for SMEs
Even if your company is smaller than the threshold, you may still be required to comply contractually if you supply an Essential Entity.



Implementation Status Across Europe

Because NIS2 is a directive, each Member State must transpose it into national law:

  • Already implemented (2024): Belgium, Croatia, Hungary, Lithuania, Latvia, Italy
  • Implemented (2025): Germany, Finland, Czech Republic
  • In progress: Spain
  • Planned for 2026: Netherlands
  • Expected in 2026: Austria, Ireland, France, Poland, Sweden

This staggered timeline means organizations operating in multiple EU countries must track country specific deadlines.



Who Enforces NIS2, and How Do You Demonstrate Compliance?

NIS2 enforcement is decentralized. Each Member State appoints: A National Competent Authority
One or more CSIRTs (Computer Security Incident Response Teams)
This regulation does not introduce its own certification process, like some well-known security standards. Instead, organizations must demonstrate compliance through:

  • Policies
  • Risk assessments
  • Incident response procedures
  • Supplier due-dilligence
  • Evidence of implemented controls

If you already comply with frameworks like PCI DSS or SWIFT, you have a head start.



The Most Important NIS2 Controls

NIS2 defines 10 mandatory cybersecurity risk management measures. Let’s highlight the most impactful ones:

1. Management Responsibility
Executives can be held legally liable for negligence. Cybersecurity becomes a board-level obligation, not just an IT concern.

2. Cybersecurity Risk Management
Including:

  • Security policies
  • Disaster recovery
  • Encryption
  • Continuous employee training

3. Supply Chain Security
Organizations must ensure suppliers meet security requirements. A major shift from NIS1.

4. Incident Notification
Significant incidents must be reported to the CSIRT within 24 hours.



Why NIS2 Is a Game Changer?

The NIS2 Directive represents a paradigm shift in European cybersecurity: it moves from a technical recommendation to a high-level corporate legal obligation.

This shift means:

  • Cybersecurity is now a core governance responsibility
  • Supply chain oversight becomes mandatory
  • Early adoption provides a competitive advantage
  • Non-compliance carries significant legal and financial risks


Want to know whether your company must comply?

Request a quick NIS2 impact scan. Contact us for a free consultation.
Or check out more information about our NIS2 compliance service.

.

Return to blog