June 15, 2026 | Compliance
Discover what NIS2 compliance requires, which sectors are affected, and how companies can prepare for stricter EU cybersecurity obligations.
This article explores NIS2, key compliance requirements, affected sectors, and the actions companies must take to meet the new EU cybersecurity rules.
The European Union is facing a rapidly escalating cyberthreat landscape. Attacks on organizations that provide essential or important services can disrupt entire societies.
To strengthen resilience, the EU introduced the first NIS Directive in 2016, and in 2022, followed with NIS2, a stricter and broader update that expands the sectors covered, increases fines, and assigns greater responsibility to company management in the event of serious incidents.
NIS2 applies to organizations that meet both of the following conditions:
To strengthen resilience, the EU introduced the first NIS Directive in 2016, and in 2022, followed with NIS2, a stricter and broader update that expands the sectors covered, increases fines, and assigns greater responsibility to company management in the event of serious incidents.
1. Size threshold
2. Sector classification
NIS2 distinguishes between Essential Entities (highly critical sectors) and Important Entities (critical sectors).
Essential Sectors.
Including: “Energy, transport, banking, healthcare, water, digital infrastructure (cloud services, data centers), ICT service management, and public administration.”
Important Sectors.
Including: “Postal services, waste management, manufacturing of chemicals and food, production of electronics and machinery, and digital providers (marketplaces and search engines).”
Important note for SMEs
Even if your company is smaller than the threshold, you may still be required to comply contractually if you supply an Essential Entity.
Because NIS2 is a directive, each Member State must transpose it into national law:
This staggered timeline means organizations operating in multiple EU countries must track country specific deadlines.
NIS2 enforcement is decentralized. Each Member State appoints:
A National Competent Authority
One or more CSIRTs (Computer Security Incident Response Teams)
This regulation does not introduce its own certification process, like some well-known security standards. Instead, organizations must demonstrate compliance through:
If you already comply with frameworks like PCI DSS or SWIFT, you have a head start.
NIS2 defines 10 mandatory cybersecurity risk management measures. Let’s highlight the most impactful ones:
1. Management Responsibility
Executives can be held legally liable for negligence. Cybersecurity becomes a board-level obligation, not just an IT concern.
2. Cybersecurity Risk Management
Including:
3. Supply Chain Security
Organizations must ensure suppliers meet security requirements. A major shift from NIS1.
4. Incident Notification
Significant incidents must be reported to the CSIRT within 24 hours.
The NIS2 Directive represents a paradigm shift in European cybersecurity: it moves from a technical recommendation to a high-level corporate legal obligation.
This shift means:
Request a quick NIS2 impact scan. Contact us for a free consultation.
Or check out more information about our NIS2 compliance service.
.
Return to blog