Home NIS2

NIS2

Network and Information Security Directive - obligations for essential/important entities.
By Eliseo Thrope
2 articles

The NIS2 Directive explained — who is in scope and what it demands

The NIS2 Directive explained — who is in scope and what it demands TL;DR — NIS2 is the EU's directive on the security of network and information systems. It dramatically widens the number of organisations covered compared to the original NIS, splitting them into essential and important entities across 18 sectors. It mandates risk-management measures, incident reporting, and — critically — pushes security obligations down the supply chain. Even if NIS2 does not apply to you directly, your customers may require you to meet its expectations. What is NIS2? NIS2 (Directive (EU) 2022/2555) is the successor to the 2016 NIS Directive. It raises the baseline of cybersecurity across the EU by expanding which organisations are covered, harmonising requirements between member states, and strengthening supervision and enforcement. Because it is a directive, NIS2 is transposed into national law by each member state — so the precise details vary by country, but the core obligations are common. Who is in scope? NIS2 covers medium and large organisations operating in 18 sectors, grouped into two tiers: Essential entities — sectors of high criticality, such as energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, and space. Important entities — other critical sectors, such as postal services, waste management, chemicals, food, manufacturing of certain products, digital providers, and research. The practical test combines sector and size. Many organisations that were out of scope under the original NIS are now captured. The supply-chain reach This is the part that surprises many companies: NIS2 explicitly requires in-scope entities to manage the cybersecurity risk of their suppliers. That means an essential entity must assess and impose security expectations on the vendors in its supply chain. The consequence: even a small software vendor that is not directly in scope may be required, contractually, to demonstrate a NIS2-aligned security posture because a customer is in scope. Supply-chain security flows downhill. What does NIS2 require? In-scope entities must implement risk-management measures covering at least: - Risk analysis and information-system security policies - Incident handling - Business continuity and crisis management - Supply-chain security - Security in acquisition, development, and maintenance - Policies to assess the effectiveness of measures - Cyber hygiene and training - Cryptography and encryption - Access control and asset management - Multi-factor authentication and secured communications Management bodies are accountable — senior leadership can be held responsible for compliance failures. Incident reporting NIS2 sets a staged incident-reporting regime for significant incidents: - An early warning without undue delay (within 24 hours) - An incident notification within 72 hours - A final report within one month Having a tested internal detection-and-reporting workflow is essential to meet these timelines. How NIS2 overlaps with the CRA NIS2 (operational security of the entity) and the CRA (product security of what you sell) are complementary. A manufacturer may face the CRA for its products and NIS2 as an operator — or through supply-chain requirements imposed by NIS2-covered customers. The evidence overlaps: risk assessments, vulnerability handling, and supply-chain due diligence serve both. → CRA vs NIS2 overlap Essential vs important — what differs Both tiers carry the same core risk-management and reporting duties. The main difference is the supervisory regime: | | Essential entities | Important entities | |---|---|---| | ▸ Risk-management duties | Full | Full | | ▸ Incident reporting | Full | Full | | ▸ Supervision | Proactive (ex-ante) | Reactive (ex-post) | | ▸ Scrutiny posture | Regular oversight | Oversight on cause | In practice: the obligations look similar; essential entities should expect closer, more proactive attention from authorities. The incident-reporting clock Significant incident detected │ ┌────────┼──────────────┬────────────────────┐ ▼ ▼ ▼ ▼ Detect Early warning Incident notification Final report ≤ 24 hours ≤ 72 hours ≤ 1 month Meeting these timelines is not about paperwork under pressure — it is about having a tested internal workflow so that detection flows to notification without scramble. Organisations that rehearse this cope; those that improvise miss deadlines. Management accountability A distinctive feature of NIS2 is that management bodies are accountable. Senior leaders must approve and oversee cybersecurity risk-management measures and can be held responsible for failures. Cybersecurity is elevated from an IT concern to a governance one — which is why board-level visibility of your posture matters. Frequently asked questions We're a small vendor — are we really affected? Possibly not directly, but very likely through the supply chain. NIS2-covered customers must impose security requirements on their suppliers, so expect questionnaires and contractual expectations regardless of your own size. How is NIS2 different from GDPR? GDPR protects personal data; NIS2 protects the security and continuity of network and information systems. They can both apply, and both involve incident notification — but they address different risks. Does NIS2 apply the same way in every EU country? No. As a directive, NIS2 is transposed into national law, so specifics vary by member state even though the core obligations are common. What to do now 1. Determine your status — directly in scope (essential/important), or exposed via a customer's supply chain? 2. Map your measures against the required risk-management areas. 3. Prepare for supplier questionnaires — even if not directly in scope, be ready to demonstrate posture. 4. Stand up incident reporting aligned to the 24h/72h/1-month cadence. A free scope review shows how NIS2 and adjacent frameworks apply to your situation. → Related: How EU compliance works How does NexCyber help with NIS2 specifically? It maps your evidence against NIS2 risk-management and supply-chain requirements, surfaces gaps by obligation, and produces the readiness signals your customers and competent authorities increasingly expect — reused across the other frameworks you face. Does NIS2 apply outside the EU? If you provide services to, or operate within, the EU in a covered sector, it can reach you regardless of where your organisation is headquartered. Non-EU suppliers are also commonly pulled in through their EU customers supply-chain security requirements. NexCyber provides a readiness analysis, not legal advice. NIS2 is transposed nationally; its application to your organisation may require legal review. Last reviewed 2026-07-10.

Last updated on Jul 13, 2026

NIS2 — Article 21 ten cybersecurity risk-management measures, deep dive

What this article covers NIS2 Article 21 lists ten cybersecurity risk-management measures that essential and important entities must implement. The text is short; the practice is substantial. This article walks each measure plainly and tells you what NexCyber tracks for it. Article 21 in plain language Essential and important entities must take "appropriate and proportionate technical, operational, and organisational measures" to manage cybersecurity risks. The measures shall include at least the following ten. 1. Policies on risk analysis and information system security A documented risk management approach for cybersecurity, including how risks are identified, evaluated, treated, accepted, monitored, and communicated. NexCyber tracks: written policy, owner, last review, scope statement, link to risk register. 2. Incident handling A documented incident handling process across detection, triage, containment, eradication, recovery, and lessons learned. NexCyber tracks: incident response policy, on-call rota, runbooks, sample post-mortems, training records. 3. Business continuity Backup, disaster recovery, crisis management. Continuity is not only about data; it is about people, processes, suppliers, and dependencies. NexCyber tracks: BC policy, recovery time / point objectives (RTO / RPO), test reports, lessons learned from exercises. 4. Supply chain security Security across the supply chain, including aspects related to the security of direct suppliers and service providers. NexCyber tracks: supplier inventory, security attestations per critical supplier, contract clauses on incident notification, SBOM coverage where applicable. 5. Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure Security-by-design, secure development lifecycle, vulnerability disclosure. NexCyber tracks: SDLC policy, security testing evidence, vulnerability disclosure policy (and security.txt where exposed), patch management records. 6. Policies and procedures to assess the effectiveness of cybersecurity risk-management measures You must measure whether your measures actually work. Metrics and assurance cycles. NexCyber tracks: assurance plan, metrics, recent test results, internal audit reports. 7. Basic cyber hygiene and cybersecurity training The everyday practices: password hygiene, MFA, patch discipline, phishing awareness, training. NexCyber tracks: hygiene policy, training plan, training completion rates, phishing simulation outcomes. 8. Policies and procedures regarding the use of cryptography and, where appropriate, encryption A decision framework for cryptography, with a key management lifecycle. NexCyber tracks: cryptography policy, key management process, inventory of cryptographic protections in transit and at rest, post-quantum readiness considerations. 9. Human resources security, access control policies, and asset management The people side of security: starters / movers / leavers, role-based access, asset inventory. NexCyber tracks: HR security policy, joiner-mover-leaver playbook, RBAC matrix, asset inventory. 10. The use of multi-factor authentication or continuous authentication solutions, secured voice / video / text, and secured emergency communication systems The high-assurance authentication and communication tier, especially for sensitive workflows and crisis communication. NexCyber tracks: MFA enforcement scope, secure communications inventory, emergency communications playbook. Proportionality NIS2 is explicit on proportionality. The measures must be appropriate and proportionate to the entity's exposure, size, likelihood of incidents, and severity if incidents occur. NexCyber lets you tag obligations by proportionality rationale; auditors generally appreciate explicit, defensible proportionality reasoning. How NexCyber composes the ten into a readiness score Each measure carries a weight; the weight reflects regulatory expectations and your sector. The composite score is shown on the NIS2 assessment dashboard, with the breakdown per measure visible at one click. Incident reporting — the timelines Article 23 sets the reporting timelines on top of Article 21 measures: - Early warning within 24 hours of becoming aware. - Incident notification within 72 hours. - Final report within one month. - Intermediate updates at the request of the competent authority. NexCyber does not file reports for you; it offers the playbook scaffold and the timer once an incident is open. Governance angle Article 20 of NIS2 puts cybersecurity at the management body's level: governance bodies are responsible for compliance with Article 21 measures, and members of those bodies must be trained. NexCyber tracks: management training records, named accountability per measure, board-level review cadence. Coordination with adjacent regulations If you are also in scope of: - CRA — vulnerability handling, SBOM, and SDLC evidence overlaps with Article 21(5). - DORA — ICT third-party register and resilience testing overlap with Article 21(4) and Article 21(3). - AI Act — risk management and data governance overlap with Article 21(1), Article 21(8), and Article 21(9). NexCyber maps a single evidence item to all applicable obligations; you upload once. What NexCyber does NOT do - It does not declare you compliant. It produces a readiness picture, with proportionality reasoning surfaced. - It does not file authority reports. The playbook scaffolds the decision; the filing remains yours. - It does not perform the measures (e.g., it is not your IAM system). It records evidence about them. Common gaps we see at first assessment - Policies that exist but are not signed off or scoped. - Supply chain security limited to a security questionnaire — no living inventory. - Incident handling with no exercise record. - MFA partially deployed without a clear exception register. - Cryptography policy that does not include key rotation cadence. These are common and addressable. Plug them and the score moves. Related articles - NIS2 basics — wider picture. - Supplier evidence basics — measure 4 detail. - What evidence should I prepare? — cross-regulation evidence list. Next step Open the NIS2 assessment in your workspace, drill into the weakest measure first, and attach the recommended evidence.

Last updated on Jun 03, 2026