NIS2 Without the Soft Focus: The Hard Requirements Your Organisation Must Meet
NIS2 · EU Cybersecurity · Incident Reporting · Supply Chain Security · Cyber Regulation Essential · Entities Management · Liability · GRC
Much has been written about NIS2 "raising the bar" for European cybersecurity. Less is said about what the Directive (EU) 2022/2555 actually mandates — the hard requirements with deadlines, thresholds, and penalties attached. The transposition deadline passed on 17 October 2024, national laws are in force across Member States, and supervisors are actively enforcing. Here is what is non-negotiable.
You may be in scope whether you like it or not
NIS2 abandons NIS1's opt-in feel. If you operate in an Annex I sector — energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, space — you are an essential entity. Annex II sectors — postal services, waste, chemicals, food, manufacturing of medical devices and electronics, digital providers, research — make you an important entity. The size cap is automatic: 50+ employees or €10 million+ turnover puts you in scope, and Member States can pull in smaller entities deemed critical. There is no certification to obtain and no exemption to apply for; scope is a matter of fact.
Ten mandatory security measures — not a menu
Article 21 lists ten cybersecurity risk-management measures every in-scope entity must implement: risk analysis and security policies; incident handling; business continuity, backups, and crisis management; supply chain security; secure acquisition, development, and vulnerability handling; effectiveness assessment of your own measures; cyber hygiene and training; cryptography and encryption policies; HR security, access control, and asset management; and multi-factor authentication with secured communications.
Two of these deserve emphasis because they trip up otherwise mature organisations. Supply chain security means you must assess the security of your suppliers — contractual clauses, due diligence, and monitoring of service providers are now regulatory obligations, not procurement niceties. And "policies to assess effectiveness" means you must be able to prove your controls work: audits, testing, and metrics, not shelfware documents.
The 24/72-hour incident reporting clock
Article 23 imposes the hardest deadline in the directive. When a significant incident occurs — one causing severe operational disruption, financial loss, or affecting others — three timers start:
- 24 hours: an early warning to your CSIRT or competent authority, indicating whether the incident is suspected to be malicious and whether it could have cross-border impact.
- 72 hours: a full incident notification with an initial assessment of severity, impact, and indicators of compromise.
- One month: a final report covering root cause, threat type, and applied mitigations.
Twenty-four hours is shorter than most organisations' internal escalation paths. Meeting it requires pre-drafted notification templates, a decision matrix for "significant," a named on-call role empowered to notify, and rehearsals. If your incident response plan has never been tested against this clock, you are not compliant — you are hopeful.
Management is personally on the hook
Article 20 is the provision that gets board attention. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and undergo cybersecurity training themselves. Member State transpositions attach personal liability to these duties — in serious cases, executives of essential entities can face temporary bans from management functions. Cybersecurity accountability can no longer be delegated to the CISO and forgotten; the paper trail must show the board approving, questioning, and reviewing.
Supervision and penalties with teeth
Essential entities face proactive supervision: on-site inspections, security audits, and targeted scans without any incident triggering them. Important entities face reactive, evidence-triggered supervision — a meaningful but often overstated difference, since a single reported incident can open the door. Fines reach €10 million or 2% of global annual turnover for essential entities and €7 million or 1.4% for important ones, alongside binding remediation orders.
Where to start
Three moves cover the most exposure fastest. First, formally classify your entity status and register with your national authority where required. Second, run a gap assessment of the ten Article 21 measures — if you hold ISO 27001:2022 certification, you have strong coverage of most measures, though certification alone does not discharge NIS2's reporting and governance duties. Third, build and rehearse the 24/72-hour reporting workflow, because it is the requirement you cannot retrofit during a crisis.
NIS2's hard requirements reward organisations that treat them as an operating model rather than a paperwork exercise. The ones who struggle will be those who discover, at hour 20 of an incident, that a legal deadline is not a guideline.