NIS2 is here, and it applies to more companies than owners think

Image Source: depositphotos.com

If your company has 50 or more staff, or turns over more than €10 million, and it works in one of the 18 sectors listed in the EU's NIS2 directive, you are almost certainly in scope. National transposition deadlines passed in October 2024, and enforcement has been building since.

Checking where you stand takes under an hour. Here is that hour, and a first week that does not begin with a purchase order.

Why this suddenly matters to you

NIS2, formally Directive (EU) 2022/2555, replaced the 2016 network and information security directive and widened it sharply. Where the old version covered a few hundred designated operators per country, each told individually, the new one applies automatically, by size and sector, to tens of thousands of companies.

Which is where the confusion starts. There is no letter. You establish your own status and, in most member states, register yourself.

The scope check: two numbers and one list

Two questions settle it. Does the company have 50 or more employees, or an annual turnover or balance sheet total above €10 million? And does it operate in a sector listed in Annex I or Annex II? Two yeses put you in scope.

Read the size test carefully: it is “or”, not “and”. A 38-person software firm with €14 million of turnover clears it on money alone. A further set of entities is in scope at any size: DNS providers, domain registries, qualified trust service providers, central government bodies. “We are only twenty people” is not by itself a defence.

None of this needs a consultant, only half an hour and last year's accounts. Outside help matters later, when you have to show what you do about the risks you listed. Teams that run the exercise often, Senseti Group among them, an international IT integrator working across Ukraine and Europe, start from the org chart and the contract register rather than the network diagram.

The sectors that catch owners by surprise

Eleven sectors sit in Annex I, described as sectors of high criticality, and seven more in Annex II. Energy, transport, banking, health and water are the ones everyone expects. The rest are not. Annex I also lists ICT service management on a business-to-business basis, putting managed service providers alongside hospitals. Annex II picks up food production and distribution, waste management, chemicals, postal and courier services, research organisations, online marketplaces, and the manufacture of electronics, electrical equipment, machinery, motor vehicles and medical devices.

“Manufacturing” in Annex II is not all manufacturing: it points to specific industrial classifications. Plastic garden furniture falls outside it. Electric motors fall inside. Read the annexes rather than trusting anyone's summary, this one included: two tables at the back of Directive (EU) 2022/2555.

Essential or important, and what the label really changes

In-scope companies split into two classes. Essential entities are the large ones in Annex I sectors: 250 or more staff, or turnover above €50 million with a balance sheet total above €43 million. Important entities are everyone else in scope.

The obligations are effectively the same for both. Supervision is not. Essential entities can be audited and inspected on site whether or not anything has gone wrong; important entities only once there is evidence or indication of a problem. The label tells you whether the regulator can turn up uninvited.

What the law actually asks you to do

Article 21 requires risk-management measures in ten areas:

  • risk analysis and security policies;
  • incident handling;
  • business continuity, backups and crisis management;
  • supply chain security, including direct suppliers;
  • secure acquisition and development, with vulnerability handling;
  • procedures to check the measures work;
  • cyber hygiene and staff training;
  • cryptography and encryption policy;
  • HR security, access control and asset management;
  • multi-factor authentication and secured communications.

All of it is judged as “appropriate and proportionate”, weighed against the state of the art, cost, and your size and exposure. A 60-person manufacturer is not expected to build what a bank builds, and nobody accepts “we bought a firewall” either. What gets tested is whether you can show a decision and how you know it works.

ENISA's technical implementation guidance breaks these areas into checkable steps. It was written for the digital categories covered by the NIS2 implementing regulation, so parts will not apply to a food producer, but it is the clearest free account of what an auditor expects to find.

The clock you cannot negotiate

Significant incidents are reported in three stages: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within a month of that notification. The early warning goes to your national CSIRT or competent authority and can be thin; the 72-hour notification adds severity, impact and any indicators of compromise.

Two traps. Where personal data is involved, GDPR runs its own 72-hour clock to a different authority, so one incident means two regulators. And the 24 hours start when you become aware, which means somebody decides at three in the morning that odd behaviour has become a reportable event. Where that decision has no named owner, the deadline is gone before anyone opens the legislation.

What it costs, and who personally carries it

Article 20 puts approval of the risk-management measures on the management body, requires it to oversee implementation, and says it can be held liable for the company's failures. Members of management bodies must also undergo training. You can outsource the work; you cannot outsource the approval, and “our provider handles security” is not a position the directive recognises.

Essential entities face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities the ceiling is €7 million or 1.4%. The turnover counted is that of the undertaking the entity belongs to, so a modest national subsidiary can be priced against its group's revenue, and these are minimums for the maximum: national law may go higher.

For essential entities there is a sharper edge still. Where other enforcement has failed, authorities can seek a temporary ban stopping a named individual at chief executive level from exercising managerial functions. For most mid-size companies, though, the fine is not the expensive outcome. Losing a framework contract because nobody could answer a security annex is.

The part most articles skip: your customers get there before the regulator

The most common way NIS2 changes a company's life has nothing to do with being in scope. It arrives as a clause in a contract from a customer who is.

In-scope entities must manage supply chain security, including relationships with their direct suppliers. The directive gives them no way to pass that duty down the chain, so they push it through procurement: questionnaires, security annexes on framework agreements, evidence at renewal, and notification windows shorter than the law gives your customer, who needs slack inside their own 24 hours.

So a 20-person engineering firm, comfortably out of scope, finds its largest contract depends on documented access control, tested restores, multi-factor authentication and a named incident contact. The uncomfortable part: being out of scope removes your protections, not your obligations. There is no regulator to appeal to and no proportionality test to lean on. Your customer's risk appetite is the standard, and their auditors set it.

It runs upward too: your own supplier list becomes evidence, and the hard conversations are with the small and irreplaceable, like the machine supplier whose remote support tunnel nobody has checked since installation. Answer questionnaires honestly. “Not yet, planned for the second quarter” survives an audit; a tick that proves untrue does not.

Where the rules genuinely differ between countries

NIS2 is a directive, not a regulation, so it lands through separate national laws that are not identical. What varies: how and when you register, which authority you report to, penalty ceilings above the EU minimums, how group structures are counted for the size test, and how far enforcement has progressed. Transposition was widely late, and the Commission opened infringement proceedings against member states over it.

So a pan-European summary, this one included, gets you to the right question and no further. Country-specific dates are deliberately absent here: they moved repeatedly, and any table would be stale by the time you read it.

A first week that does not start with a purchase order

Nothing below costs money or needs a vendor.

  1. Settle scope in writing. One page: headcount, turnover, balance sheet total, sector, the annex entry you match, and the date. That page is your answer when someone asks in two years.
  2. Find your national authority and check registration. In several countries this deadline arrives before any security obligation bites, and missing it is itself a breach.
  3. Name a person, not a department. Someone who decides whether an event is reportable, with a deputy and a number answered at the weekend.
  4. Write your ten biggest risks in plain language. Not a framework, not a matrix. Ten sentences about what would genuinely hurt the business.
  5. Read your contracts in both directions. Most companies promised customers more than they ever required of their own suppliers.
  6. Restore one file. Take a real document from last week and watch someone restore it. Confidence about backups usually ends here.

Only then does spending make sense.

Questions owners ask first

We have fewer than 50 staff. Are we safe?
Not automatically. The test is passed on headcount or on money, and a few categories are in scope at any size. Even a genuine “no” is often overridden by your largest customer's next contract.

We hold ISO 27001. Does that cover it?
It puts you well ahead, because most of Article 21 maps onto controls you already run. It is not a legal substitute: reporting deadlines, registration and management-body approval are obligations no certificate creates.

We are outside the EU but sell into it.
Jurisdiction generally follows where you are established, so many non-EU suppliers are not directly caught, though certain digital service categories must designate a representative in a member state. If your EU customers are in scope, their supply chain obligations reach you through the contract anyway.

Waiting for a letter is the one option with no upside. In most of the EU there will not be one, and the first person to ask will be a customer, not a regulator.