NIS2 compliance: what essential and important entities have to prove

NIS2 brings sectors that were never regulated before under EU cybersecurity rules and makes management personally accountable.

Check if NIS2 applies to you

Cybersecurity Risk Management

WHAT CHANGED WITH NIS2

DIRECTIVE (EU) 2022/2555

Replaced the original NIS Directive. The transposition deadline for member states was 17 October 2024.

WIDER SCOPE

NIS2 covers 18 sectors, up from 7 under the original NIS Directive, including:

Energy

Transport

Banking

Health

Water

Digital infrastructure

ICT service management

Public administration

Postal services

Waste

Chemicals

Food

Manufacturing

Digital providers

MANAGEMENT ACCOUNTABILITY

Management bodies must approve and oversee cybersecurity risk measures and can be held personally liable, up to temporary bans from management functions.

SUPPLY CHAIN SECURITY

Securing your suppliers is an explicit obligation, not a recommendation.

NIS2 SECURITY REQUIREMENTS

NIS2 sets out risk management measures that must be appropriate and proportionate, covering at minimum ten areas. Nearly every item requires evidence that it operates, not that it is written down.

01 Risk analysis and information system security policies

02 Incident handling

03 Business continuity and crisis management

04 Supply chain security

05 Security in acquisition, development and maintenance

06 Policies to assess whether the measures actually work

07 Cyber hygiene and training

08 Cryptography

09 Human resources security, access control and asset management

10 Multi-factor authentication and secured communications

Not sure whether you are essential or important?

Not sure whether you are essential or important?

We establish your category under your national law before anything else is built.

HOW WE HELP WITH NIS2

SCOPING AND CLASSIFICATION

We determine whether you are in scope and under which category, in each member state where you operate.

GAP ANALYSIS

We assess you against the NIS2 risk management measures, mapped to the ISO 27001 or NIST controls you already run.

SUPPLY CHAIN SECURITY

Supplier assessment criteria, contractual security requirements and a review cycle that works in practice.

INCIDENT REPORTING READINESS

We instrument awareness, define significance thresholds and rehearse the 24 and 72-hour workflow before it is needed.

GOVERNANCE AND MANAGEMENT ACCOUNTABILITY

The board-level approval process, the reporting line and the training that satisfy the management liability provisions, so the obligation sits with the people the directive holds responsible.

EVIDENCE PACK

Documented proof for supervisors and for customers who now audit you.

NIS2: KEY QUESTIONS

Is NIS2 a directive or a regulation, and why does it matter?

It is a directive, which means it does not apply to you directly: your national transposition law does. Member states implement it with differences in thresholds, registration procedures, supervisory regimes and penalties.

This has a practical consequence people underestimate. If you operate in several member states, you are not solving one compliance problem, you are solving several related ones. Any provider promising a single uniform NIS2 solution across the EU is simplifying something that is not simple.

Are you an essential or an important entity?

The distinction determines how you are supervised, not what you must do: the security obligations are largely the same.

Essential entities. Typically larger organisations in high-criticality sectors. Supervision is proactive, meaning audits and inspections can occur without cause. Penalty ceiling: up to 10 million euro or 2 percent of total worldwide annual turnover, whichever is higher.

Important entities. Typically medium-sized organisations, or organisations in the other listed sectors. Supervision is reactive, following evidence of non-compliance. Penalty ceiling: up to 7 million euro or 1.4 percent of total worldwide annual turnover, whichever is higher.

Sector and size determine the category, with exceptions where an entity is the sole provider of a critical service. The first step in any NIS2 project is establishing which category you fall into under your national law, because getting this wrong invalidates everything built on top of it.

How does incident reporting work?

NIS2 uses a staged reporting model for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month.

The hard part is not the deadlines. It is the phrase becoming aware, because most organisations cannot demonstrate when they became aware: detection and escalation are not instrumented. That is a technical gap, and it is the one we most often find first.

We are already ISO 27001 certified. Are we NIS2 compliant?

No, but you are a long way in. ISO 27001 covers most of the risk management measures. What it does not cover is the national registration obligation, the incident reporting timelines and thresholds, and the management liability requirements. We map your existing ISMS first and only propose work for the genuine gaps.

We are outside the EU. Does NIS2 affect us?

It can, in two ways. If you offer certain digital services in the EU (cloud, data centres, managed IT or security services, among others), you may be directly in scope and required to designate a representative there. And if you supply an in-scope entity, their supply chain security obligation becomes your contractual requirement.

What are the penalties?

They are set nationally, within ceilings defined by the directive, and are higher for essential entities. The more immediate commercial risk is usually different: in-scope customers begin requiring evidence from suppliers, and the ones who cannot provide it lose the contract.

Find out whether NIS2 applies to you, and where you stand.

Find out whether NIS2 applies to you, and where you stand.

Scoping, gap analysis and an evidence pack, mapped to the controls you already run.

Where to start?

For more information, reach out to us now.

Active Audit Agency provides extensive cybersecurity services for businesses, ensuring robust protection and compliance for organisations of various sizes.

footer-logo

You can copy our materials only after making sure that your services are safe.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.