All articles

RegulationsSeptember 2, 20263 min read

NIS2: what it requires of companies and where to start

The NIS2 directive explained in practical terms: who is in scope, which obligations apply, what the penalties are and the first steps toward compliance.

European Union flag next to a notebook labeled EU Regulations

For years cybersecurity was considered a technical matter, best left to the IT department. With the NIS2 directive that is no longer the case: it becomes a responsibility of company management, with precise obligations, inspections and penalties.

NIS2 is EU Directive 2022/2555. Each member state has transposed it into its own national law and designated a competent national authority, which supervises the organizations in scope and receives incident notifications.

Who is in scope

NIS2 greatly widens the scope compared with the first NIS directive of 2016. In general terms it covers medium and large companies operating in a long list of sectors, divided into two groups:

  • sectors of high criticality: energy, transport, banking and financial market infrastructure, health, water, digital infrastructure, managed ICT services, public administration, space;
  • other critical sectors: postal services, waste management, chemicals, food, manufacturing of critical products (for example medical devices, electronics, machinery, vehicles), digital providers such as marketplaces and search engines, research.

Organizations in scope are classified as essential entities or important entities, with similar obligations but different supervision and penalties. In some cases smaller organizations are also included, for example when they are the sole provider of a critical service.

There is also an often underestimated effect: even companies not directly covered by NIS2 can be affected as suppliers. Organizations in scope must assess the security of their supply chain and will ask their partners for guarantees too.

The main obligations

  1. Registration: the organizations concerned must register with the competent national authority and keep their information up to date.
  2. Risk management: security policies, incident handling, business continuity and backup, supply chain security, access control, multi-factor authentication, encryption, staff training.
  3. Reporting significant incidents: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
  4. Management accountability: management bodies approve the security measures, are accountable for them and must follow specific training.

Penalties

Administrative fines can reach €10 million or 2% of total worldwide annual turnover for essential entities, and €7 million or 1.4% for important entities, whichever is higher. Measures against senior management may also apply.

Where to start: five concrete steps

  1. Check whether you are in scope, directly or as a supplier to organizations that are.
  2. Take an inventory of systems, data, cloud services and suppliers: you cannot protect what you do not know.
  3. Assess the risks and compare the current situation with the required measures.
  4. Cover the basic measures right away: multi-factor authentication, immutable and verified backups, updates, monitoring, an incident response plan.
  5. Train your people, starting with management.

How we can help

Many of the measures required by NIS2 match services you can activate right away: EagleSafe for Zero Trust access and multi-factor authentication, ARXDOME for continuous monitoring and incident response with a 24/7 SOC, 7dBackup for encrypted, immutable backups and 7dCloud for sovereign infrastructure in certified data centers.

For risk analysis, documentation and training you can rely on the consulting services of Blue Eagle Technology.

This article is for information purposes only and is not a substitute for legal advice on your specific case.

Want to talk it through?

Tell us about the needs of your company or your customers: we will propose the right solution, with no obligation.

Contact us

Related articles