The NIS2 Directive explained — who is in scope and what it demands
TL;DR — NIS2 is the EU's directive on the security of network and information systems. It dramatically widens the number of organisations covered compared to the original NIS, splitting them into essential and important entities across 18 sectors. It mandates risk-management measures, incident reporting, and — critically — pushes security obligations down the supply chain. Even if NIS2 does not apply to you directly, your customers may require you to meet its expectations.
What is NIS2?
NIS2 (Directive (EU) 2022/2555) is the successor to the 2016 NIS Directive. It raises the baseline of cybersecurity across the EU by expanding which organisations are covered, harmonising requirements between member states, and strengthening supervision and enforcement.
Because it is a directive, NIS2 is transposed into national law by each member state — so the precise details vary by country, but the core obligations are common.
Who is in scope?
NIS2 covers medium and large organisations operating in 18 sectors, grouped into two tiers:
Essential entities — sectors of high criticality, such as energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space.
Important entities — other critical sectors, such as postal services, waste management, chemicals, food, manufacturing of certain products, digital providers, and research.
The practical test combines sector and size. Many organisations that were out of scope under the original NIS are now captured.
The supply-chain reach
This is the part that surprises many companies: NIS2 explicitly requires in-scope entities to manage the cybersecurity risk of their suppliers. That means an essential entity must assess and impose security expectations on the vendors in its supply chain.
The consequence: even a small software vendor that is not directly in scope may be required, contractually, to demonstrate a NIS2-aligned security posture because a customer is in scope. Supply-chain security flows downhill.
What does NIS2 require?
In-scope entities must implement risk-management measures covering at least:
- Risk analysis and information-system security policies
- Incident handling
- Business continuity and crisis management
- Supply-chain security
- Security in acquisition, development, and maintenance
- Policies to assess the effectiveness of measures
- Cyber hygiene and training
- Cryptography and encryption
- Access control and asset management
- Multi-factor authentication and secured communications
Management bodies are accountable — senior leadership can be held responsible for compliance failures.
Incident reporting
NIS2 sets a staged incident-reporting regime for significant incidents:
- An early warning without undue delay (within 24 hours)
- An incident notification within 72 hours
- A final report within one month
Having a tested internal detection-and-reporting workflow is essential to meet these timelines.
How NIS2 overlaps with the CRA
NIS2 (operational security of the entity) and the CRA (product security of what you sell) are complementary. A manufacturer may face the CRA for its products and NIS2 as an operator — or through supply-chain requirements imposed by NIS2-covered customers. The evidence overlaps: risk assessments, vulnerability handling, and supply-chain due diligence serve both.
Essential vs important — what differs
Both tiers carry the same core risk-management and reporting duties. The main difference is the supervisory regime:
| Essential entities | Important entities | |
|---|---|---|
| ▸ Risk-management duties | Full | Full |
| ▸ Incident reporting | Full | Full |
| ▸ Supervision | Proactive (ex-ante) | Reactive (ex-post) |
| ▸ Scrutiny posture | Regular oversight | Oversight on cause |
In practice: the obligations look similar; essential entities should expect closer, more proactive attention from authorities.
The incident-reporting clock
Significant incident detected
│
┌────────┼──────────────┬────────────────────┐
▼ ▼ ▼ ▼
Detect Early warning Incident notification Final report
≤ 24 hours ≤ 72 hours ≤ 1 month
Meeting these timelines is not about paperwork under pressure — it is about having a tested internal workflow so that detection flows to notification without scramble. Organisations that rehearse this cope; those that improvise miss deadlines.
Management accountability
A distinctive feature of NIS2 is that management bodies are accountable. Senior leaders must approve and oversee cybersecurity risk-management measures and can be held responsible for failures. Cybersecurity is elevated from an IT concern to a governance one — which is why board-level visibility of your posture matters.
Frequently asked questions
We're a small vendor — are we really affected? Possibly not directly, but very likely through the supply chain. NIS2-covered customers must impose security requirements on their suppliers, so expect questionnaires and contractual expectations regardless of your own size.
How is NIS2 different from GDPR? GDPR protects personal data; NIS2 protects the security and continuity of network and information systems. They can both apply, and both involve incident notification — but they address different risks.
Does NIS2 apply the same way in every EU country? No. As a directive, NIS2 is transposed into national law, so specifics vary by member state even though the core obligations are common.
What to do now
- Determine your status — directly in scope (essential/important), or exposed via a customer's supply chain?
- Map your measures against the required risk-management areas.
- Prepare for supplier questionnaires — even if not directly in scope, be ready to demonstrate posture.
- Stand up incident reporting aligned to the 24h/72h/1-month cadence.
A free scope review shows how NIS2 and adjacent frameworks apply to your situation.
→ Related: How EU compliance works
How does NexCyber help with NIS2 specifically? It maps your evidence against NIS2 risk-management and supply-chain requirements, surfaces gaps by obligation, and produces the readiness signals your customers and competent authorities increasingly expect — reused across the other frameworks you face.
Does NIS2 apply outside the EU? If you provide services to, or operate within, the EU in a covered sector, it can reach you regardless of where your organisation is headquartered. Non-EU suppliers are also commonly pulled in through their EU customers supply-chain security requirements.
NexCyber provides a readiness analysis, not legal advice. NIS2 is transposed nationally; its application to your organisation may require legal review.
Last reviewed 2026-07-10.