NIS2

NIS2: who is affected and what to do next

By CyberSec42 · Updated 2026

CyberSec42

NIS2 applies to medium and large companies across 18 sectors classified as important or essential, and in many cases to their suppliers as well. The EU directive widens the circle of regulated organisations considerably compared with the original NIS directive, and it requires demonstrable risk management, short reporting lines and accountability at management level. Checking now whether you fall within scope saves you time pressure and liability exposure later.

In short.

This article sets out the requirements in practical terms and is not legal advice. NIS2 is an EU directive, and the binding rules for any given company follow from the national transposition law, which varies between member states. The authoritative interpretation for your case belongs with your legal counsel.

What NIS2 actually is

NIS2 is the second version of the European directive on network and information security. It replaces the first NIS directive and raises the level of security required across the EU. As a directive, it does not apply directly but through each member state's national transposition law. In practice, what counts for a company is therefore the national law that gives effect to the NIS2 requirements, and the details can differ from one country to the next. The core stays the same everywhere: more sectors in scope, mandatory minimum measures, clear reporting duties and personal accountability at management level.

Who is affected by NIS2?

Scope comes down to two questions: does the company operate in a regulated sector, and does it reach the size threshold? The general rule is a size-based test starting at medium-sized companies, which typically means from 50 employees or from 10 million euro in annual turnover and balance sheet total. In addition, certain providers are treated as in scope regardless of size, for example parts of the digital infrastructure. Because thresholds and exact definitions are set by national law, the precise cut-off can vary between member states.

The regulated sectors

NIS2 distinguishes sectors of high criticality from other critical sectors. These include, among others:

Sectors of high criticalityOther critical sectors
Energy, transport, banking and financial market infrastructurePostal and courier services
Health, drinking water and waste waterWaste management
Digital infrastructure and ICT service managementManufacture and processing of chemicals
Public administration and spaceManufacturing, food and production of certain goods
Digital service providers and research

Two categories, similar obligations

NIS2 divides organisations in scope into essential and important entities. Both have to meet the same security requirements. The difference lies mainly in supervision: essential entities are supervised proactively, while important entities are supervised more on a reactive basis, for example after an incident. For your own preparation this means the technical and organisational work is comparable in both cases.

What obligations NIS2 triggers

The requirements fall into three blocks: risk management, reporting duties and governance.

Risk management with concrete measures

Entities in scope must take appropriate technical and organisational measures in line with the state of the art. These include, among others, policies for risk analysis and information security, incident handling, backup and business continuity, supply chain security, access control, vulnerability management, cryptography and multi-factor authentication. What matters is the evidence: the measures must be demonstrably in place and effective, not just written down on paper.

Staged reporting duties

Significant incidents have to be reported in stages. As a rule this means an early notification within 24 hours, a more detailed report within 72 hours and a final report no later than one month afterwards. The exact wording and deadlines are set by national law, so they can differ between member states. All of this depends on an incident being detected and escalated internally in good time, which in turn requires monitoring and clear responsibilities.

Management accountability

NIS2 puts obligations on the management level itself. Management must approve the risk measures, oversee their implementation and undertake training. Breaches can lead to supervisory action and fines, and the responsibility cannot be fully delegated. Cyber security thereby becomes a matter for the top of the organisation in a legal sense.

Timelines and state of transposition

The directive is in force at European level and had to be transposed into national law by 17 October 2024. In Germany, NIS2 is transposed through the BSI Act (BSIG) as amended by the NIS2 Implementation Act, with the BSI acting as the central registration and reporting authority. According to the BSI, the registration deadline for affected entities has already passed, so companies in scope that have not yet registered should do so without delay. You can check whether your organisation is in scope using the BSI's official NIS-2 scope assessment. In some other member states transposition slipped beyond the original deadline, so the exact start of the obligations depends on the relevant national law. The binding start date for your situation is something your legal counsel confirms against the current law.

What to do now, concretely

Preparation follows a clear order, independent of the exact date the national law takes effect.

  1. Determine whether you are in scope. Check sector and size, and additionally clarify whether customers are passing the requirements down through the supply chain.
  2. Anchor accountability. Name a responsible role, involve the management level and set reporting lines.
  3. Gap analysis. Compare the current state against the required measures and prioritise the gaps by risk and effort.
  4. Implement measures. Introduce or harden technical and organisational controls, from access control through backup to incident handling.
  5. Set up the reporting process. Build detection, escalation and reporting so that the 24 and 72 hour windows are realistically achievable.
  6. Collect evidence. Keep a record for every requirement, so the state can be examined at any time.

The most demanding part is rarely the individual measure, but the robust proof that all requirements together are met. This is exactly where a structured readiness comes in, one that maps every obligation to a concrete piece of evidence instead of leaving a list of intentions.

NIS2 readiness without guesswork

In a first conversation we assess whether and how you are in scope and show which obligations apply to you and what is still missing before you are examinable. The result is a clear plan with evidence, not just an assessment. More on our approach on our page about NIS2 readiness.

Request a conversation

CyberSec42 prepares, implements, collects evidence and accompanies you up to the accredited body. CyberSec42 is not itself an accredited certification body and does not provide legal advice.

Frequently asked questions about NIS2

Who is affected by NIS2?

In scope are generally medium and large companies operating in one of the regulated sectors, so broadly from 50 employees or 10 million euro in turnover. In addition, certain critical providers are treated as in scope regardless of size, for example parts of the digital infrastructure. The exact thresholds are set by national transposition law and can vary between member states.

When does NIS2 apply?

The EU transposition deadline was 17 October 2024. In Germany, NIS2 applies through the BSI Act as amended by the NIS2 Implementation Act; the BSI is the registration and reporting authority and, according to the BSI, the registration deadline for affected entities has already passed, so companies in scope should register without delay. In some other member states the exact start depends on the national law. Your legal counsel confirms the binding date for your case.

What obligations does NIS2 bring?

The three core blocks are risk management with technical and organisational minimum measures, staged reporting duties for significant incidents within 24 and 72 hours plus a final report, and the personal accountability of management for implementation. The precise deadlines and details follow from the national law.

What happens if you breach NIS2?

National law provides for supervisory measures and fines, and management carries a personal responsibility that cannot be fully delegated. The exact level and form follow from the relevant national transposition law and can differ between member states.

Am I affected if I supply a company that is in scope?

Possibly yes, even without falling directly within scope yourself. NIS2 requires entities in scope to manage the security of their supply chain. In practice many customers pass the requirements on to their service providers and suppliers through contractual clauses.

What is the first step toward NIS2 readiness?

First clarify whether you are in scope, then run a gap analysis against the required measures. This makes clear which gaps exist and in what order they need to be closed, before measures and evidence follow.