Demo: this is how the NIS2 tool looks embedded in a law firm's own article page. The tool is live: every analysis you complete lands in the firm's lead inbox.
Home / Insights / Technology & Regulatory / NIS2: who is in scope, and who is accountable?
NIS2 and management accountability

NIS2: who is in scope, and who is accountable?

The NIS2 Directive raises the cybersecurity bar across the sectors the EU treats as critical, and reaches well beyond them through the supply chain. The obligations are documented ones, and under art. 20 they land on the management body personally.

Check where you stand, in about three minutes

Establish whether your organisation is in scope, work through the requirements in art. 20 and 21, and get a prioritised action list back, with a policy draft for every gap.

Your Firm LLP
Powered by Avaris · Fyrna
1. Scope 2. Gap analysis 3. Results 4. Policy draft
Is your organisation in scope for NIS2?
Three questions on sector, size and supply relationships. The assessment is indicative and does not replace legal advice.
Completed the analysis before?
1 · Sector
2 · Size
3 · Supply chain
Is your organisation ready for NIS2?
A short gap analysis against the security requirements in NIS2 art. 21 and the management obligations in art. 20. You get a prioritised action list and a policy draft.
Requirement 1 of 11
Gap analysis: summary
Based on your answers. This is a working basis, not a legal assessment.
0
Critical gaps
0
Partly met
0
Met
Get the full gap report
Enter your details to continue. The next step opens the full report and the policy documents.
Data is stored in the EEA and is not shared with anyone else. How your data is handled
Takes about 2 seconds.
Unlock the full report
Your analysis is saved. One payment opens the report and the documents that close the gaps.
Prioritised action list, worst gap firstIncluded
A policy document for every gap that needs oneIncluded
Your own page, to return to and share internallyIncluded
Total Price set by the firm
Demo: nothing is charged and no card details are collected.
Want help closing the gaps?
We send your results straight to the firm, and one of our lawyers will be in touch shortly.
Your analysis is saved
You can come back to it at any time. We email you a link. No password needed.
Open my analysis →
Prioritised action list
This is a working basis built from your answers, not a legal assessment of compliance status. The final assessment should be made by a lawyer or a certified security adviser.
Policy draft
The draft is built from your answers and the requirements. You approve it before it is saved.
Automatically generated draft · Based on your answers and NIS2 art. 20/21 · Must be reviewed and approved by a responsible person · Does not replace legal advice
Generating draft…
Approval required
By approving you confirm that you have read the draft and take responsibility for its content. The document is stored with your signature and a timestamp.

A general cybersecurity regime, not a sector rule

NIS2 (Directive (EU) 2022/2555) widens the scope of its predecessor so far that it is best read as the first general body of law on how organisations must manage cybersecurity. The obligations cover risk management, access control, continuity planning and the measures needed to prevent and handle security breaches. In practice that means documented systems and procedures, not intentions.

The directive also tightens incident reporting, with fixed deadlines for notifying the national authority: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.

Who is in scope?

The sectors listed in Annexes I and II go well beyond the 2016 NIS Directive. They include

  • energy,
  • health,
  • transport,
  • banking and financial market infrastructure,
  • drinking water, waste water and digital infrastructure such as cloud services, data centres and DNS

and also district heating, hydrogen, pharmaceuticals, medical device manufacturing, waste management, managed IT and OT service providers, postal and courier services, food production and distribution, public administration, research and space.

The main rule is size-based: at least 50 staff and an annual turnover or balance sheet of at least EUR 10 million. But there are exceptions in both directions. Some providers are covered regardless of size, and an organisation outside the direct scope is routinely pulled in by contract, because entities that are covered must pass security requirements down their supply chain.

What it means in practice

For most organisations NIS2 starts as a cost. It takes investment in technology, competence and internal process. It also becomes something to show: customers, insurers and procurement functions increasingly ask for documented security before they sign, and an organisation that can answer has an advantage over one that cannot.

What happens if we do not comply?

The first risk is the damage an attack does to the organisation and its customers. Beyond that, NIS2 carries sanctions that reach the people at the top: fines of up to EUR 10 million or 2% of global turnover for essential entities, temporary bans on management responsibilities, and personal liability for members of the management body who fail to act.

How can we help?

Need legal advice on NIS2? Book a call or send us a note. No obligation.

Practice areas

Corporate & M&A
Technology & Regulatory
Tax
Dispute resolution
Employment
Data protection & GDPR
Real estate & construction
Energy & natural resources
Competition