NIS2 compliance: what essential and important entities have to prove
NIS2 brings sectors that were never regulated before under EU cybersecurity rules and makes management personally accountable.
Check if NIS2 applies to you
WHAT CHANGED WITH NIS2

DIRECTIVE (EU) 2022/2555
Replaced the original NIS Directive. The transposition deadline for member states was 17 October 2024.

WIDER SCOPE
NIS2 covers 18 sectors, up from 7 under the original NIS Directive, including:
Energy
Transport
Banking
Health
Water
Digital infrastructure
ICT service management
Public administration
Postal services
Waste
Chemicals
Food
Manufacturing
Digital providers

MANAGEMENT ACCOUNTABILITY
Management bodies must approve and oversee cybersecurity risk measures and can be held personally liable, up to temporary bans from management functions.

SUPPLY CHAIN SECURITY
Securing your suppliers is an explicit obligation, not a recommendation.
NIS2 SECURITY REQUIREMENTS
NIS2 sets out risk management measures that must be appropriate and proportionate, covering at minimum ten areas. Nearly every item requires evidence that it operates, not that it is written down.
01 Risk analysis and information system security policies
02 Incident handling
03 Business continuity and crisis management
04 Supply chain security
05 Security in acquisition, development and maintenance
06 Policies to assess whether the measures actually work
07 Cyber hygiene and training
08 Cryptography
09 Human resources security, access control and asset management
10 Multi-factor authentication and secured communications
We establish your category under your national law before anything else is built.
HOW WE HELP WITH NIS2

SCOPING AND CLASSIFICATION
We determine whether you are in scope and under which category, in each member state where you operate.

GAP ANALYSIS
We assess you against the NIS2 risk management measures, mapped to the ISO 27001 or NIST controls you already run.

SUPPLY CHAIN SECURITY
Supplier assessment criteria, contractual security requirements and a review cycle that works in practice.

INCIDENT REPORTING READINESS
We instrument awareness, define significance thresholds and rehearse the 24 and 72-hour workflow before it is needed.

GOVERNANCE AND MANAGEMENT ACCOUNTABILITY
The board-level approval process, the reporting line and the training that satisfy the management liability provisions, so the obligation sits with the people the directive holds responsible.

EVIDENCE PACK
Documented proof for supervisors and for customers who now audit you.
NIS2: KEY QUESTIONS
Is NIS2 a directive or a regulation, and why does it matter?
It is a directive, which means it does not apply to you directly: your national transposition law does. Member states implement it with differences in thresholds, registration procedures, supervisory regimes and penalties.
This has a practical consequence people underestimate. If you operate in several member states, you are not solving one compliance problem, you are solving several related ones. Any provider promising a single uniform NIS2 solution across the EU is simplifying something that is not simple.
Are you an essential or an important entity?
The distinction determines how you are supervised, not what you must do: the security obligations are largely the same.
Essential entities. Typically larger organisations in high-criticality sectors. Supervision is proactive, meaning audits and inspections can occur without cause. Penalty ceiling: up to 10 million euro or 2 percent of total worldwide annual turnover, whichever is higher.
Important entities. Typically medium-sized organisations, or organisations in the other listed sectors. Supervision is reactive, following evidence of non-compliance. Penalty ceiling: up to 7 million euro or 1.4 percent of total worldwide annual turnover, whichever is higher.
Sector and size determine the category, with exceptions where an entity is the sole provider of a critical service. The first step in any NIS2 project is establishing which category you fall into under your national law, because getting this wrong invalidates everything built on top of it.
How does incident reporting work?
NIS2 uses a staged reporting model for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month.
The hard part is not the deadlines. It is the phrase becoming aware, because most organisations cannot demonstrate when they became aware: detection and escalation are not instrumented. That is a technical gap, and it is the one we most often find first.
We are already ISO 27001 certified. Are we NIS2 compliant?
No, but you are a long way in. ISO 27001 covers most of the risk management measures. What it does not cover is the national registration obligation, the incident reporting timelines and thresholds, and the management liability requirements. We map your existing ISMS first and only propose work for the genuine gaps.
We are outside the EU. Does NIS2 affect us?
It can, in two ways. If you offer certain digital services in the EU (cloud, data centres, managed IT or security services, among others), you may be directly in scope and required to designate a representative there. And if you supply an in-scope entity, their supply chain security obligation becomes your contractual requirement.
What are the penalties?
They are set nationally, within ceilings defined by the directive, and are higher for essential entities. The more immediate commercial risk is usually different: in-scope customers begin requiring evidence from suppliers, and the ones who cannot provide it lose the contract.
Scoping, gap analysis and an evidence pack, mapped to the controls you already run.
Where to start?
Active Audit Agency provides extensive cybersecurity services for businesses, ensuring robust protection and compliance for organisations of various sizes.
You can copy our materials only after making sure that your services are safe.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.




