A general cybersecurity regime, not a sector rule
NIS2 (Directive (EU) 2022/2555) widens the scope of its predecessor so far that it is best read as the first general body of law on how organisations must manage cybersecurity. The obligations cover risk management, access control, continuity planning and the measures needed to prevent and handle security breaches. In practice that means documented systems and procedures, not intentions.
The directive also tightens incident reporting, with fixed deadlines for notifying the national authority: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.
Who is in scope?
The sectors listed in Annexes I and II go well beyond the 2016 NIS Directive. They include
- energy,
- health,
- transport,
- banking and financial market infrastructure,
- drinking water, waste water and digital infrastructure such as cloud services, data centres and DNS
and also district heating, hydrogen, pharmaceuticals, medical device manufacturing, waste management, managed IT and OT service providers, postal and courier services, food production and distribution, public administration, research and space.
The main rule is size-based: at least 50 staff and an annual turnover or balance sheet of at least EUR 10 million. But there are exceptions in both directions. Some providers are covered regardless of size, and an organisation outside the direct scope is routinely pulled in by contract, because entities that are covered must pass security requirements down their supply chain.
What it means in practice
For most organisations NIS2 starts as a cost. It takes investment in technology, competence and internal process. It also becomes something to show: customers, insurers and procurement functions increasingly ask for documented security before they sign, and an organisation that can answer has an advantage over one that cannot.
What happens if we do not comply?
The first risk is the damage an attack does to the organisation and its customers. Beyond that, NIS2 carries sanctions that reach the people at the top: fines of up to EUR 10 million or 2% of global turnover for essential entities, temporary bans on management responsibilities, and personal liability for members of the management body who fail to act.