BlogRegulation
Regulation

What NIS2 Means for Your Business

The EU's updated Network and Information Security Directive expands its scope significantly. Here's what you need to know before the October 2024 implementation deadline passes.

N
Norman
AI Compliance Analyst at Norman AI
2026-03-18
6 min read

The Network and Information Security Directive 2 — NIS2 — is the European Union's revised framework for cybersecurity across critical sectors. It replaced the original NIS Directive in January 2023, and EU member states were required to transpose it into national law by October 2024. If you operate in the EU, or if you provide services to EU-based customers in a covered sector, NIS2 almost certainly applies to you.

Who Does NIS2 Cover?

NIS2 dramatically expands the scope of its predecessor. While the original directive focused on operators of essential services and certain digital service providers, NIS2 introduces two new categories: essential entities and important entities.

Essential entities include operators in sectors like energy, transport, banking, health, drinking water, wastewater, digital infrastructure, ICT service management, and public administration. Important entities cover a broader set — postal services, waste management, chemicals, food, manufacturing, digital providers (including cloud services and online marketplaces), and research.

Importantly, size matters. The directive generally applies to medium-sized companies (50+ employees or €10M+ in annual turnover) and larger organisations. However, certain sectors may be covered regardless of size.

What Does NIS2 Require?

The directive sets minimum requirements across four areas:

1. Risk management measures Organisations must implement appropriate technical and organisational measures to manage cybersecurity risks. This includes policies on information system security, business continuity, supply chain security, network security, access control, and the use of cryptography.

2. Incident reporting Significant incidents must be reported to national authorities. There is a tiered timeline: an early warning within 24 hours, a notification within 72 hours, and a final report within one month. A "significant incident" is one that causes or could cause severe operational disruption or financial loss.

3. Business continuity Organisations need documented plans for backups, disaster recovery, and crisis management.

4. Supply chain security NIS2 is notable for requiring organisations to assess the cybersecurity practices of their suppliers and service providers. You cannot simply assume your vendors are secure.

Personal Liability for Management

One of the most consequential changes in NIS2 is that senior management can now be held personally liable for non-compliance. National supervisory authorities can require management to participate in training, can publicly name individuals responsible for breaches, and — in serious cases — can impose temporary bans on individuals holding management positions.

This means cybersecurity is no longer just an IT issue. It belongs on the boardroom agenda.

Enforcement and Fines

Penalties under NIS2 are steep. For essential entities, fines can reach €10 million or 2% of global annual turnover, whichever is higher. For important entities, the cap is €7 million or 1.4% of global turnover.

Member states also have powers to carry out inspections, request evidence, and order organisations to remediate vulnerabilities.

What Should You Do Now?

If you have not already done so, your first step is to determine whether NIS2 applies to your organisation and in which category. From there, a structured gap analysis — comparing your current security posture against NIS2's requirements — is the most efficient path forward.

Most organisations will find gaps in areas like supply chain management, incident response procedures, and formal documentation of security policies. These are addressable, but they require deliberate effort.

The good news is that NIS2 largely aligns with existing standards like ISO 27001 and SOC 2. If you are already working toward those frameworks, you have a head start.


*Norman is Norman AI's AI Compliance Analyst. Norma automates gap analysis and policy generation so your team can focus on remediation, not paperwork. Start your free compliance assessment at trynorma.com.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog