Network and Information Systems Directive NIS2 Badge
The Ultimate Guide to

NIS2 Compliance: A Practical Guide to the NIS2 Directive

What is NIS2?

The Network and Information Security Directive 2 (NIS2) is the EU’s latest cybersecurity legislation aimed at improving the resilience of critical infrastructure and essential services across member states. If your organization is classified as an essential or important entity under NIS2 and operates within EU member states, understanding NIS2 is essential.

NIS2 (Directive (EU) 2022/2555) is the updated version of the EU’s original Network and Information Security Directive (NIS), which was introduced in 2016. NIS2 was officially adopted on January 16, 2023 with an implementation deadline of October 17, 2024 for member states. The NIS2 framework establishes a higher common level of cybersecurity across the EU, and is designed to ensure that essential and important entities take appropriate security measures and report significant incidents to national authorities.

NIS2 enhances the EU’s cybersecurity baseline by:

  1. Expanding the scope to more sectors and entities
  2. Imposing stricter risk management and incident reporting requirements
  3. Introducing stronger enforcement, including substantial fines and leadership accountability

Who does NIS2 apply to?

NIS2 applies to a wide range of organizations operating within the EU, including non-EU companies offering services in the EU. The directive distinguishes between essential entities and important entities.

Sectors covered under NIS2:

Essential entities (Annex I)

Essential entities provide services which are considered crucial for societal functions, economy, public health, and safety.  These entities are held to the highest level of scrutiny under NIS2.

  • Energy (electricity, oil, gas, district heating and cooling, hydrogen)
  • Transport (air, rail, water, road)
  • Banking
  • Financial market infrastructures
  • Healthcare (hospitals, healthcare providers, EU reference laboratories, pharmaceutical manufacturers, medical device manufacturers)
  • Drinking water and wastewater
  • Digital infrastructure (DNS, cloud computing, data centers, trust services, telecoms, and other digital service providers)
  • Public administration (central government)
  • Space (ground infrastructure)

Important entities (Annex II)

These sectors are also considered significant, but with slightly lower risk exposure. They must meet all NIS2 obligations, but are subject to ex post supervision that is triggered only when there is evidence of potential violations.

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Food production and processing
  • Manufacturing of critical products (including medical devices, computer/electronic/optical products, electrical equipment, and machinery)
  • Digital providers (e.g., online marketplaces, search engines, social platforms)
  • Research organizations
Size cap rule

In general, NIS2 applies to medium and large organizations (50+ employees or €10M+ turnover). However, some smaller organizations may also fall under the directive if they are deemed critical to society or the economy.

NIS2 cybersecurity requirements

You can read the official full text of the NIS2 Directive here:

NIS2 Directive (Directive (EU) 2022/2555) – EUR-Lex Official Source

The directive is available in all official EU languages and includes all articles and annexes that specify requirements, definitions, and enforcement mechanisms.

Under Article 21 of the NIS2 directive, all covered entities must implement technical, operational, and organizational cybersecurity risk management measures, including:

  1. Risk analysis and policies for information system security
  2. Incident handling and response procedures
  3. Business continuity and crisis management plans
  4. Supply chain security, including third-party risk assessments
  5. Security in network and information systems acquisition, development, and maintenance
  6. Vulnerability handling and disclosure procedures
  7. Policies and procedures for evaluating the effectiveness of cybersecurity measures
  8. Use of multi-factor authentication or continuous authentication solutions and policies and procedures regarding the use of cryptography and, where appropriate, encryption
  9. Training and awareness programs for employees
  10. Governance structures with clear roles and responsibilities

Entities must also maintain incident reporting capabilities, with specific timeframes:

  • 24 hours for early warning
  • 72 hours for incident notification
  • One month for final report (including root cause analysis and mitigation)

How do I become compliant with the NIS2 Directive?

To comply with NIS2, organizations need to adopt a proactive approach to cybersecurity. Entities are expected to take all the technical, operational, and organizational measures to manage the network and IT risks. 

Here are five specific lines of action that are central to achieving NIS2 compliance.

Action 1: Conduct a comprehensive risk assessment

A thorough risk assessment is the foundation of any effective cybersecurity strategy. In preparation for NIS2, organizations should:

A graphic outlining the three steps one must take to conduct a comprehensive risk assessment: identify critical assets, evaluate the threat landscape, and conduct an impact analysis.

1. Identify critical assets

Determine which systems, data, and services are essential to your operations and could be targeted by cyber threats.

2. Evaluate the threat landscape

Assess the potential threats and vulnerabilities specific to your organization and industry.

3. Conduct an impact analysis

Understand the potential impact of various cyber incidents on your operations, reputation, and regulatory compliance.

You should track your risk posture over time since your risk constantly evolves. Plus, you’ll not only want to register your own risks, but also evaluate your risks inherent to relationships with vendors. (See more about this in Action 3 below.)

Action 2: Develop and maintain an incident response plan

Incident handling is key because it is an NIS2 core risk management measure, and how you respond to an incident can affect any subsequent regulatory action against your organization. Here are four key components that make up an effective incident response plan:

The four essential components of an incident response plan: incident detection, implementing response procedures, creating a communication plan, and a post-incident review.

1. Incident detection

Implement monitoring tools and processes to detect security incidents in real-time, such as intrusion detection systems and log analysis tools to swiftly identify any unauthorized activities or anomalies within the network.

2. Response procedures

Establish clear procedures for responding to different types of incidents, including containment, eradication, and recovery steps. Outline roles and responsibilities of team members to ensure a coordinated effort during a crisis.

3. Communication plan

Develop a communication plan to inform stakeholders, including regulators, customers, and employees in the event of a cyber incident. Specify channels of communication, key messaging, and designated spokespersons to maintain transparency and trust.

4. Post-incident review

Conduct a thorough review after each incident to identify lessons learned and improve your incident response capabilities. This includes evaluating the effectiveness of response procedures, updating documentation, and implementing necessary adjustments to prevent similar incidents in the future.

Action 3: Enhance supply chain security

Increasingly, perpetrators compromise the security of an entity’s network and information systems by exploiting vulnerabilities affecting third-party products. Per NIS2, organizations should secure their supply chains through:

The three key areas to address when reviewing supply chain security: vendor risk management, contractual obligations, and continuous monitoring of controls.

Vendor risk management

Assess the cybersecurity posture of your vendors and third-party service providers. Require them to adhere to your security standards.

Contractual obligations

Include cybersecurity requirements in contracts with suppliers and partners to ensure they are accountable for their security practices.

Continuous monitoring

Regularly monitor and audit the security practices of your supply chain to identify and address potential vulnerabilities.

For most companies today, their SaaS portfolio is fairly large (or even massive) which means the risk is significant. The average small business with 500 or fewer employees has 162 apps in their stack; mid-market companies between 501 and 2,500 employees have 263 apps on average; and large and enterprise organizations have between 408 and 696 apps. 

Hyperproof helps you automate your vendor risk assessment with risk assessment templates. With continuous updates of your list of vendors, secure vendor questionnaires, vendor monitoring, and proof of vendor risk management, we can accelerate the process to achieve robust supply chain security. 

Vendor management in the Hyperproof platform

Action 4: Foster a culture of cybersecurity

According to the 2026 Verizon Data Breach Investigations Report (DBIR), 62% of all breaches include the human element, with people being involved either via error, privilege misuse, use of stolen credentials, or social engineering. That makes a strong case for good cyber hygiene. Creating a culture of cybersecurity awareness and accountability within your organization is essential. Steps to achieve this include:

Three essential things that build a culture of cybersecurity at a company: training and awareness, clear policies and procedures, and leadership buy-in.

Training and awareness programs

Conduct regular cybersecurity training sessions for all employees to ensure they understand the importance of cybersecurity and their role in maintaining it.

Clear policies and procedures

Develop and enforce clear cybersecurity policies and procedures that all employees must follow.

Leadership buy-in

Ensure that senior management is actively involved in cybersecurity governance and decision-making.

Action 5: Ensure compliance with reporting requirements

Compared to its predecessor, NIS2 introduces stricter reporting requirements for cybersecurity incidents. Organizations must comply with:

NIS2 reporting requirements: timely reporting, comprehensive documentation, and collaboration with authorities.

Timely reporting

Report significant cybersecurity incidents to the relevant national authorities within the required timeframe.

Comprehensive documentation

Maintain detailed records of all cybersecurity incidents, including the nature of the incident, the response measures taken, and the impact on your operations.

Collaboration with authorities

Cooperate with national authorities during incident investigations and follow their guidance on incident management and mitigation.

Organizations must notify the relevant national authorities within 24 hours of becoming aware of a significant incident. If the initial notification was incomplete, an intermediate report providing additional information must be submitted within 72 hours of the initial notification. A final report providing comprehensive information about the incident, including its impact and the remedial actions taken, should be submitted no later than one month after the initial notification.

Additional considerations for NIS2 compliance

Things to consider when preparing for NIS2 include international considerations and monitoring regulatory updates

International considerations

For multinational organizations, NIS2 compliance can be particularly challenging due to varying regulations across different countries. Some key ways to address cross-border issues include:

Harmonize compliance efforts

Develop a unified approach to compliance that aligns with NIS2 and other international cybersecurity standards, such as the General Data Protection Regulation (GDPR), the Cybersecurity Maturity Model Certification (CMMC), and ISO/IEC 27001. If you already have evidence for compliance with these schemes, it can accelerate your compliance with NIS2. By mapping controls across frameworks, you can satisfy requirements from multiple standards. This saves you time when implementing new frameworks, adapting to new regulations, and staying up to date with existing frameworks.

Cross-border incident response

Establish cross-border incident response protocols to ensure coordinated efforts in the event of a cyber incident that affects multiple jurisdictions.

NIS2 Directive frequently asked questions

NIS2 may apply to your non-EU company only if you are a specific type of entity listed in the directive (such as cloud computing, DNS, online marketplace, or social networking platform providers) and if you offer services within the EU. If both conditions apply, you must designate a representative in an EU Member State where you provide services. Simply having users in the EU or operating a digital platform that impacts EU users is not sufficient – you must be offering specific covered services within the Union and fall into one of the designated entity categories.

The NIS2 Directive is structured into nine chapters and three annexes

  • Chapter I: General Provisions (Articles 1–6) establishes the directive’s subject matter, defines which public and private entities fall under its scope based on size and sector, classifies organizations as “essential” or “important,” and provides 41 key legal and technical definitions to ensure uniform interpretation across the Union.
  • Chapter II: Coordinated Cybersecurity Frameworks (Articles 7–13) is the blueprint requiring each Member State to adopt a national cybersecurity strategy, designate competent regulatory authorities and single points of contact, establish a national cyber crisis management framework, and maintain well-resourced Computer Security Incident Response Teams (CSIRTs).
  • Chapter III: Cooperation at Union and International Level (Articles 14–19) establishes cross-border bodies—specifically the strategic Cooperation Group, the operational CSIRTs network, and the crisis-handling EU-CyCLONe—while outlining rules for international data agreements, Union-wide state of cybersecurity reporting, and a voluntary peer-review system.
  • Chapter IV: Cybersecurity Risk-Management Measures and Reporting Obligations (Articles 20–25) is the core compliance engine of the directive, placing ultimate cybersecurity oversight and liability on corporate management bodies, outlining a list of mandatory “all-hazards” technical security measures, and enforcing strict, multi-stage incident reporting timelines (including 24-hour early warnings) for significant incidents.
  • Chapter V: Jurisdiction and Registration (Articles 26–28) is the territorial boundary framework that clarifies which Member State holds jurisdiction over cross-border digital providers, mandates the establishment of a central registration database managed by ENISA, and requires domain name registries to maintain verified, accurate registrant databases.
  • Chapter VI: Information Sharing (Articles 29–30) is the cooperative enablement chapter that facilitates voluntary, secure cybersecurity information sharing between companies and their supply chains, while setting up a structured pathway for organizations to voluntarily submit threat and near-miss notifications to authorities without taking on extra legal liabilities.
  • Chapter VII: Supervision and Enforcement (Articles 31–37) is the regulatory enforcement mechanism that equips national competent authorities with proactive and ex-post supervisory powers (including inspections and independent audits), establishes severe administrative fines of up to €10 million or 2% of global turnover, defines executive liability rules, and outlines mutual enforcement assistance between Member States.
  • Chapter VIII: Delegated and Implementing Acts (Articles 38–39) establishes the precise conditions, limits, and committee procedures under which the European Commission is authorized to adopt supplementary technical and methodological rules to adapt the directive over time.
  • Chapter IX: Final Provisions (Articles 40–46) details the regular timeline for reviewing the directive’s societal impact, sets national transposition and implementation deadlines, repeals the previous NIS 1 Directive, and outlines the official entry into force.

These two regulations, while having significant overlaps, have several distinctions. For an in-depth guide on their specifics, check out our guide, Understanding the Relationship Between NIS2 and the EU Cyber Resilience Act.

Fines vary based on entity classification: Essential entities face fines up to €10 million or 2% of global annual revenue (whichever is higher), while Important entities face fines up to €7 million or 1.4% of global annual revenue (whichever is higher). Authorities may also impose corrective actions, suspend activities, or hold executives personally liable.

While each member state is responsible for national enforcement, NIS2 introduces stronger coordination through EU-wide cooperation groups, mandatory incident reporting, and harmonized supervisory practices.

Not exactly. NIS2 uses a size-cap rule where medium-sized enterprises and larger entities generally fall within scope. However, small enterprises and microenterprises may still be included if they: 

  • Provide certain critical services (like public electronic communications networks or trust services) regardless of size
  • Are the sole provider of an essential service in a Member State
  • Have service disruptions that could significantly impact public safety/security/health
  • Could cause significant systemic risk with cross-border impact
  • Have specific national/regional importance for particular sectors

NIS2 includes supply chain security requirements, meaning your third-party vendors must also meet appropriate security standards. Vendor risk management is no longer optional.

While there is no single universal certification, NIS2 does include certification requirements. Member States may require entities to use ICT products, services, and processes certified under European cybersecurity certification schemes, and the Commission can mandate specific certifications where cybersecurity levels are insufficient. Compliance is demonstrated through mandatory security audits (regular audits for essential entities, targeted audits for important entities), documented risk management practices, and adherence to incident response protocols.

NIS1 was implemented in 2016 to lay the foundation for EU-wide cybersecurity regulation. This legislation was replaced by NIS2 in 2023 to expand the scope of coverage to additional sectors, improve enforcement mechanisms, and harmonize implementation across EU member states. You can see a full breakdown of differences between NIS1 and NIS2 in this guide.

How Hyperproof helps with NIS2 compliance

With real-time risk monitoring, incident response tracking, and automated workflows, Hyperproof simplifies meeting NIS2 obligations, reducing the burden of compliance and enhancing overall cybersecurity resilience.

Network and Information Systems Directive NIS2 Badge

Get an out-of-the-box NIS2 framework template

Jumpstart your NIS2 compliance journey with a pre-built framework template, including optional ISO 27001 and 27002 illustrative controls.

Gather and monitor all your risks in one place

Collect, manage, and monitor your risks and ensure risk mitigation work is prioritized and completed based on customizable inherent impact and tolerance.

Map controls across multiple frameworks

Crosswalk controls between programs to speed up NIS2 implementation. Avoid duplicative work and adhere to other frameworks, like the EU CRA, NIST CSF, GDPR, DORA, ISO 27001, and more.

Understand your NIS2 compliance posture at a glance

Get clear insights into your team’s progress on assessment requests with our dashboards and reports, designed for easy sharing with key stakeholders.

Ensure tasks are completed to meet your NIS2 timeline

Automatically assign tasks to meet NIS2 directive requirements and streamline workflows to boost efficiency, ensuring you never face delays.

Automatically gather evidence to meet NIS2 requirements

Leverage Hyperproof’s powerful integrations, including AWS, Azure, Github, Jira, and more to automate evidence collection and reuse that evidence across multiple controls.

Ready to see
Hyperproof in action?

G2Crowd Leader Enterprise
G2Crowd Leader Mid-Market
G2Crowd High Performer Enteprise
G2Crowd Momentum Leader
G2Crowd Users Love Us