← Back to Blog

ComplianceNIS2

NIS2 Directive: A Practical Compliance Guide for EU Enterprises

By NOC Services  |  April 2026  |  10 min read

The NIS2 Directive (EU 2022/2555) significantly expanded the EU's cybersecurity framework, bringing thousands of additional organisations under binding security obligations for the first time. If your organisation operates in the EU and hasn't assessed your NIS2 obligations, this guide provides a practical starting point.

Note: This article provides general guidance only. Your organisation should consult legal counsel and a qualified cybersecurity advisor to assess your specific NIS2 obligations.

What is NIS2?

NIS2 is the successor to the original NIS Directive (2016) and was adopted by the EU in December 2022. Member states were required to transpose it into national law by October 2024. It establishes minimum cybersecurity standards for organisations in critical and important sectors across the EU, with significantly stronger enforcement mechanisms than its predecessor — including personal liability for management and fines of up to €10 million or 2% of global annual turnover.

Who Does NIS2 Apply To?

NIS2 applies to medium and large organisations (50+ employees or €10M+ annual turnover) operating in sectors designated as "essential" or "important."

Essential Sectors

Important Sectors

Key Technical Requirements

Article 21 of NIS2 requires organisations to implement "appropriate and proportionate technical, operational and organisational measures" to manage cybersecurity risks. Specifically, this includes:

1. Risk Analysis and Information Security Policies

A formal risk management process and documented security policies covering all critical systems and data. Annual review is expected.

2. Incident Handling

Organisations must have documented incident response procedures and be capable of detecting, containing, and recovering from security incidents. NIS2 introduces strict notification timelines:

3. Business Continuity

Backup management, disaster recovery planning, and crisis management procedures must be in place and tested regularly.

4. Supply Chain Security

Organisations must assess and manage security risks in their supply chains — including evaluating the cybersecurity practices of direct suppliers and service providers.

5. Network and Information System Security

This covers acquisition, development, and maintenance of secure systems, vulnerability management, and disclosure policies.

6. Cybersecurity Training

Management must receive cybersecurity training, and staff awareness programmes are required.

7. Cryptography and Encryption

Policies on the use of encryption and cryptographic controls for protecting data in transit and at rest.

8. Access Control and Asset Management

Multi-factor authentication, privileged access management, and a current inventory of all IT assets.

How Managed Security Services Help with NIS2

The most challenging aspect of NIS2 compliance for mid-sized organisations is not understanding what is required — it's having the capability to actually deliver it. Continuous network monitoring, 24/7 incident detection, SIEM-based log analysis, and vulnerability management all require ongoing operational commitment that most internal IT teams cannot absorb alongside their existing responsibilities.

A managed security provider addresses this by delivering the operational layer that NIS2 requires:

Next Steps

If you are unsure whether NIS2 applies to your organisation, or how your current security posture measures against its requirements, a gap assessment is the logical starting point. This typically takes 2–4 weeks and produces a prioritised remediation plan aligned with the specific requirements that apply to your sector.

NIS2 Gap Assessment

Our engineers work with EU enterprises to assess their NIS2 readiness and build a practical, cost-effective compliance programme. Get in touch to discuss your situation.

Request a NIS2 Assessment