NIS2 Directive
The Network and Information Security Directive
The NIS2 Directive (Directive (EU) 2022/2555) establishes a common cybersecurity framework across the European Union. It replaced the original NIS Directive and significantly expanded the number of sectors and organisations subject to cybersecurity risk management, incident reporting, governance, and supervisory requirements.
NIS2 covers entities across 18 critical sectors, including energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing, and other critical activities.
NIS2 is an EU directive rather than a single compliance law applied identically in every Member State. Each country must transpose it into national legislation, and Article 5 expressly allows Member States to adopt or maintain rules that provide a higher level of cybersecurity than the Directive itself. Organisations therefore need to understand both the EU framework and the national law that applies to them.
What is NIS2 and why is it important?
The objective of NIS2 is to achieve a high common level of cybersecurity across the EU. To do this, the Directive requires Member States to establish national cybersecurity strategies, competent authorities, single points of contact and CSIRTs, while imposing cybersecurity risk-management and incident-reporting obligations on essential and important entities.
It also introduces rules for supervision, enforcement, and cybersecurity information sharing.
NIS2 makes cybersecurity a management responsibility, not just an IT issue.
Under Article 20, management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation and receive cybersecurity training. Compliance therefore requires clear responsibilities and active management involvement.
Compared with its predecessor, NIS2 has a broader scope and applies to more sectors and organisations. The European Commission describes the framework as covering 18 critical sectors and, generally, medium-sized and large entities operating in those sectors. The Directive also contains exceptions that bring certain organisations into scope regardless of size.
Cybersecurity under NIS2 is not limited to the IT department. Article 20 requires the management bodies of essential and important entities to approve cybersecurity risk-management measures and oversee their implementation. Members of management bodies must also receive cybersecurity training, while Member States are required to encourage regular training for employees.
The enforcement framework is also significant. For infringements of Articles 21 or 23, Member States must ensure that essential entities can face maximum administrative fines of at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities, the maximum administrative fine must be at least €7 million or 1.4% of worldwide annual turnover, whichever is higher. The precise enforcement process is implemented through national law.
Member States were required to transpose NIS2 by 17 October 2024. Implementation has not progressed at exactly the same pace across the EU. On 8 July 2026, the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify full transposition at that time. This illustrates why organisations operating internationally should verify the current national position rather than relying only on the text of the Directive.
Does NIS2 apply to your organisation?
The first question is not simply whether your organisation “does cybersecurity”. Applicability depends on the type of activity, size of the entity, and specific exceptions or national rules.
Key requirements of NIS2
Management responsibility and training
Cybersecurity governance starts at management level. Management bodies of essential and important entities must approve cybersecurity risk-management measures and oversee their implementation. Members of management bodies must receive training so that they can understand cybersecurity risks and assess their possible impact on the organisation’s services.
Cybersecurity risk management
Article 21 requires essential and important entities to implement appropriate and proportionate technical, operational and organisational measures to manage risks affecting their network and information systems and to prevent or minimise the impact of incidents. Measures must reflect the organisation’s exposure to risk and the potential consequences of incidents.
Incident handling and business continuity
Risk-management measures must include incident handling as well as business continuity. The Directive specifically refers to backup management, disaster recovery, and crisis management. Organisations therefore need to define responsibilities, escalation procedures and recovery arrangements rather than relying only on preventive controls.
Supply chain security
NIS2 explicitly includes supply chain security, which covers cybersecurity aspects of relationships with direct suppliers and service providers. An organisation’s assessment should therefore extend beyond its internal environment to dependencies that could affect the security or continuity of its services.
Secure acquisition, development and vulnerability management
Article 21 also covers security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. This connects cybersecurity requirements with procurement, software development, maintenance, and vulnerability management processes.
Cyber hygiene, access control and authentication
The Directive requires measures covering basic cyber hygiene and cybersecurity training, policies and procedures regarding cryptography and encryption, human resources security, access control policies and asset management. It also includes the use of multi-factor authentication or continuous authentication solutions where appropriate.
Significant incident reporting
NIS2 does not require the full regulatory reporting process for every minor security event. Under Article 23, an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or if it has affected or could affect other persons by causing considerable material or non-material damage.
For a significant incident, the Directive establishes a staged process: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Intermediate reports may also be requested.
Additional requirements for certain digital entities
For certain digital infrastructure, ICT service management and digital provider entities, Commission Implementing Regulation (EU) 2024/2690 provides more detailed technical and methodological requirements and further criteria for determining when an incident is significant.
Path to compliance
A practical implementation programme can follow eight steps.
Determine scope and applicable national law
Identify the relevant legal entity, sector and services, assess size and special exceptions, and determine whether the entity is essential or important. Then identify the national legislation implementing NIS2 and the competent authority.
Establish governance and ownership
Define which management body approves cybersecurity measures, who owns individual risks and controls, and who is responsible for regulatory and incident reporting.
Map assets, services, and dependencies
Identify the systems, information, applications, infrastructure, business processes and external providers required to deliver in-scope services.
Perform risk and business impact assessments
Assess threats, vulnerabilities, potential disruption, and dependencies. Use the results to prioritise controls and continuity requirements rather than treating every system identically.
Assess controls against Article 21
Review existing practices for incident management, business continuity, backups, supply chain security, vulnerability management, access control, cryptography, training, and other required areas. Article 21 requires measures to be appropriate and proportionate to risk.
Establish the incident-reporting process
Organisations should know who decides whether an incident is significant, who contacts the relevant CSIRT or authority, which information must be collected and how the 24-hour and 72-hour deadlines will be met.
Test continuity and response
Plans should be tested so that backups, recovery, crisis roles, and internal and external communication procedures work in practice.
Review effectiveness and retain evidence
Maintain risk assessments, decisions, assigned responsibilities, completed actions, tests, training records, and other evidence that demonstrates how cybersecurity measures are managed.
For entities covered by Implementing Regulation 2024/2690, ENISA’s NIS2 Technical Implementation Guidance provides additional practical support, including examples of evidence and mappings to relevant standards and frameworks. ENISA published the guidance in June 2025.
How can Blue Octopus help?
Blue Octopus does not replace technical cybersecurity controls, a legal assessment, a competent authority, or an independent audit. Its role is in helping organisations structure the management layer around risks, analyses, responsibilities, and supporting documentation.
Using a management platform does not demonstrate NIS2 compliance. The underlying risk assessments, cybersecurity measures, procedures and evidence still need to satisfy the applicable EU and national requirements.
Frequently asked questions
Short answers to the most common questions about the scope and requirements of NIS2.
No. Medium-sized and larger organisations in covered sectors form the general scope, but Article 2 includes several situations in which entities can be covered regardless of size.
Both are subject to core NIS2 requirements, but the Directive distinguishes them for classification, supervision and enforcement. Article 3 sets out the detailed classification rules.
Not by itself. ISO/IEC 27001 can provide a useful framework for an information security management system (ISMS), but NIS2 contains specific legal obligations relating to governance, risk-management measures, reporting, and supervision. Compliance must therefore be assessed against the applicable NIS2 requirements and national law.
A supplier may or may not independently fall within NIS2. However, in-scope organisations must address supply chain security and their relationships with direct suppliers and service providers, so cybersecurity requirements can also affect suppliers contractually.
No. The staged Article 23 reporting process applies to significant incidents. The Directive defines the general significance criteria, while Implementing Regulation 2024/2690 provides more detailed criteria for specified categories of digital entities.
No. NIS2 is a minimum-harmonisation directive. Member States may impose a higher level of cybersecurity and implement national procedures, authorities, and enforcement arrangements. Organisations should therefore verify the applicable national transposition law.
Official sources
Next step
NIS2 readiness requires more than a cybersecurity policy. Organisations need a repeatable process that connects risks, critical services, responsible owners, suppliers, controls, incident response and evidence of implementation.
Blue Octopus can help organisations structure risks, analyses, responsibilities and supporting documentation in one place, providing a clearer management view of what needs to be addressed and who is responsible.