NIS2 Directive: A Practical Compliance Guide for EU Enterprises
The NIS2 Directive (EU 2022/2555) significantly expanded the EU's cybersecurity framework, bringing thousands of additional organisations under binding security obligations for the first time. If your organisation operates in the EU and hasn't assessed your NIS2 obligations, this guide provides a practical starting point.
Note: This article provides general guidance only. Your organisation should consult legal counsel and a qualified cybersecurity advisor to assess your specific NIS2 obligations.
What is NIS2?
NIS2 is the successor to the original NIS Directive (2016) and was adopted by the EU in December 2022. Member states were required to transpose it into national law by October 2024. It establishes minimum cybersecurity standards for organisations in critical and important sectors across the EU, with significantly stronger enforcement mechanisms than its predecessor — including personal liability for management and fines of up to €10 million or 2% of global annual turnover.
Who Does NIS2 Apply To?
NIS2 applies to medium and large organisations (50+ employees or €10M+ annual turnover) operating in sectors designated as "essential" or "important."
Essential Sectors
- Energy (electricity, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking and financial market infrastructure
- Health (hospitals, pharmaceutical, medical devices)
- Drinking water and wastewater
- Digital infrastructure (internet exchange points, DNS, TLD registries, cloud providers, data centres)
- ICT service management (managed service providers, managed security providers)
- Public administration
- Space
Important Sectors
- Postal and courier services
- Waste management
- Chemicals manufacture and distribution
- Food production and distribution
- Manufacturing (medical devices, computers, electronics, machinery, vehicles)
- Digital providers (online marketplaces, search engines, social networks)
- Research organisations
Key Technical Requirements
Article 21 of NIS2 requires organisations to implement "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risks. Specifically, this includes:
1. Risk Analysis and Information Security Policies
A formal risk management process and documented security policies covering all critical systems and data. Annual review is expected.
2. Incident Handling
Organisations must have documented incident response procedures and be capable of detecting, containing, and recovering from security incidents. NIS2 introduces strict notification timelines:
- 24 hours: Early warning to your national CSIRT for "significant" incidents
- 72 hours: Full incident notification with initial assessment
- 1 month: Final incident report with root cause analysis and remediation measures
3. Business Continuity
Backup management, disaster recovery planning, and crisis management procedures must be in place and tested regularly.
4. Supply Chain Security
Organisations must assess and manage security risks in their supply chains — including evaluating the cybersecurity practices of direct suppliers and service providers.
5. Network and Information System Security
This covers acquisition, development, and maintenance of secure systems, vulnerability management, and disclosure policies.
6. Cybersecurity Training
Management must receive cybersecurity training, and staff awareness programmes are required.
7. Cryptography and Encryption
Policies on the use of encryption and cryptographic controls for protecting data in transit and at rest.
8. Access Control and Asset Management
Multi-factor authentication, privileged access management, and a current inventory of all IT assets.
How Managed Security Services Help with NIS2
The most challenging aspect of NIS2 compliance for mid-sized organisations is not understanding what is required — it's having the capability to actually deliver it. Continuous network monitoring, 24/7 incident detection, SIEM-based log analysis, and vulnerability management all require ongoing operational commitment that most internal IT teams cannot absorb alongside their existing responsibilities.
A managed security provider addresses this by delivering the operational layer that NIS2 requires:
- 24/7 monitoring satisfies the continuous surveillance requirement
- Managed SIEM provides the log aggregation and threat detection capability required for incident identification
- Incident response procedures align with NIS2's notification timeline requirements
- Monthly reporting provides the audit trail regulators expect
- Vulnerability management addresses the network and information system security requirement
Next Steps
If you are unsure whether NIS2 applies to your organisation, or how your current security posture measures against its requirements, a gap assessment is the logical starting point. This typically takes 2–4 weeks and produces a prioritised remediation plan aligned with the specific requirements that apply to your sector.
NIS2 Gap Assessment
Our engineers work with EU enterprises to assess their NIS2 readiness and build a practical, cost-effective compliance programme. Get in touch to discuss your situation.
Request a NIS2 Assessment