
The Ultimate Guide to
NIS2 Compliance: A Practical Guide to the NIS2 Directive
What is NIS2?
The Network and Information Security Directive 2 (NIS2) is the EUās latest cybersecurity legislation aimed at improving the resilience of critical infrastructure and essential services across member states. If your organization is classified as an essential or important entity under NIS2 and operates within EU member states, understanding NIS2 is essential.
NIS2 (Directive (EU) 2022/2555) is the updated version of the EUās original Network and Information Security Directive (NIS), which was introduced in 2016. NIS2 was officially adopted on January 16, 2023 with an implementation deadline of October 17, 2024 for member states. The NIS2 framework establishes a higher common level of cybersecurity across the EU, and is designed to ensure that essential and important entities take appropriate security measures and report significant incidents to national authorities.
NIS2 enhances the EUās cybersecurity baseline by:
- Expanding the scope to more sectors and entities
- Imposing stricter risk management and incident reporting requirements
- Introducing stronger enforcement, including substantial fines and leadership accountability
Who does NIS2 apply to?
NIS2 applies to a wide range of organizations operating within the EU, including non-EU companies offering services in the EU. The directive distinguishes between essential entities and important entities.
Sectors covered under NIS2:
Essential entities (Annex I)
Essential entities provide services which are considered crucial for societal functions, economy, public health, and safety. These entities are held to the highest level of scrutiny under NIS2.
Important entities (Annex II)
These sectors are also considered significant, but with slightly lower risk exposure. They must meet all NIS2 obligations, but are subject to ex post supervision that is triggered only when there is evidence of potential violations.
Size cap rule
In general, NIS2 applies to medium and large organizations (50+ employees or ā¬10M+ turnover). However, some smaller organizations may also fall under the directive if they are deemed critical to society or the economy.
NIS2 cybersecurity requirements
You can read the official full text of the NIS2 Directive here:
NIS2 Directive (Directive (EU) 2022/2555) ā EUR-Lex Official Source
The directive is available in all official EU languages and includes all articles and annexes that specify requirements, definitions, and enforcement mechanisms.
Under Article 21 of the NIS2 directive, all covered entities must implement technical, operational, and organizational cybersecurity risk management measures, including:
- Risk analysis and policies for information system security
- Incident handling and response procedures
- Business continuity and crisis management plans
- Supply chain security, including third-party risk assessments
- Security in network and information systems acquisition, development, and maintenance
- Vulnerability handling and disclosure procedures
- Policies and procedures for evaluating the effectiveness of cybersecurity measures
- Use of multi-factor authentication or continuous authentication solutions and policies and procedures regarding the use of cryptography and, where appropriate, encryption
- Training and awareness programs for employees
- Governance structures with clear roles and responsibilities
Entities must also maintain incident reporting capabilities, with specific timeframes:
How do I become compliant with the NIS2 Directive?
To comply with NIS2, organizations need to adopt a proactive approach to cybersecurity. Entities are expected to take all the technical, operational, and organizational measures to manage the network and IT risks.
Here are five specific lines of action that are central to achieving NIS2 compliance.
Action 1: Conduct a comprehensive risk assessment
A thorough risk assessment is the foundation of any effective cybersecurity strategy. In preparation for NIS2, organizations should:

1. Identify critical assets
Determine which systems, data, and services are essential to your operations and could be targeted by cyber threats.
2. Evaluate the threat landscape
Assess the potential threats and vulnerabilities specific to your organization and industry.
3. Conduct an impact analysis
Understand the potential impact of various cyber incidents on your operations, reputation, and regulatory compliance.
You should track your risk posture over time since your risk constantly evolves. Plus, youāll not only want to register your own risks, but also evaluate your risks inherent to relationships with vendors. (See more about this in Action 3 below.)
Action 2: Develop and maintain an incident response plan
Incident handling is key because it is an NIS2 core risk management measure, and how you respond to an incident can affect any subsequent regulatory action against your organization. Here are four key components that make up an effective incident response plan:

1. Incident detection
Implement monitoring tools and processes to detect security incidents in real-time, such as intrusion detection systems and log analysis tools to swiftly identify any unauthorized activities or anomalies within the network.
2. Response procedures
Establish clear procedures for responding to different types of incidents, including containment, eradication, and recovery steps. Outline roles and responsibilities of team members to ensure a coordinated effort during a crisis.
3. Communication plan
Develop a communication plan to inform stakeholders, including regulators, customers, and employees in the event of a cyber incident. Specify channels of communication, key messaging, and designated spokespersons to maintain transparency and trust.
4. Post-incident review
Conduct a thorough review after each incident to identify lessons learned and improve your incident response capabilities. This includes evaluating the effectiveness of response procedures, updating documentation, and implementing necessary adjustments to prevent similar incidents in the future.
Action 3: Enhance supply chain security
Increasingly, perpetrators compromise the security of an entityās network and information systems by exploiting vulnerabilities affecting third-party products. Per NIS2, organizations should secure their supply chains through:

Vendor risk management
Assess the cybersecurity posture of your vendors and third-party service providers. Require them to adhere to your security standards.
Contractual obligations
Include cybersecurity requirements in contracts with suppliers and partners to ensure they are accountable for their security practices.
Continuous monitoring
Regularly monitor and audit the security practices of your supply chain to identify and address potential vulnerabilities.
For most companies today, their SaaS portfolio is fairly large (or even massive) which means the risk is significant. The average small business with 500 or fewer employees has 162 apps in their stack; mid-market companies between 501 and 2,500 employees have 263 apps on average; and large and enterprise organizations have between 408 and 696 apps.
Hyperproof helps you automate your vendor risk assessment with risk assessment templates. With continuous updates of your list of vendors, secure vendor questionnaires, vendor monitoring, and proof of vendor risk management, we can accelerate the process to achieve robust supply chain security.

Action 4: Foster a culture of cybersecurity
According to the 2026 Verizon Data Breach Investigations Report (DBIR), 62% of all breaches include the human element, with people being involved either via error, privilege misuse, use of stolen credentials, or social engineering. That makes a strong case for good cyber hygiene. Creating a culture of cybersecurity awareness and accountability within your organization is essential. Steps to achieve this include:

Training and awareness programs
Conduct regular cybersecurity training sessions for all employees to ensure they understand the importance of cybersecurity and their role in maintaining it.
Clear policies and procedures
Develop and enforce clear cybersecurity policies and procedures that all employees must follow.
Leadership buy-in
Ensure that senior management is actively involved in cybersecurity governance and decision-making.
Action 5: Ensure compliance with reporting requirements
Compared to its predecessor, NIS2 introduces stricter reporting requirements for cybersecurity incidents. Organizations must comply with:

Timely reporting
Report significant cybersecurity incidents to the relevant national authorities within the required timeframe.
Comprehensive documentation
Maintain detailed records of all cybersecurity incidents, including the nature of the incident, the response measures taken, and the impact on your operations.
Collaboration with authorities
Cooperate with national authorities during incident investigations and follow their guidance on incident management and mitigation.
Organizations must notify the relevant national authorities within 24 hours of becoming aware of a significant incident. If the initial notification was incomplete, an intermediate report providing additional information must be submitted within 72 hours of the initial notification. A final report providing comprehensive information about the incident, including its impact and the remedial actions taken, should be submitted no later than one month after the initial notification.
Additional considerations for NIS2 compliance

International considerations
For multinational organizations, NIS2 compliance can be particularly challenging due to varying regulations across different countries. Some key ways to address cross-border issues include:
Harmonize compliance efforts
Develop a unified approach to compliance that aligns with NIS2 and other international cybersecurity standards, such as the General Data Protection Regulation (GDPR), the Cybersecurity Maturity Model Certification (CMMC), and ISO/IEC 27001. If you already have evidence for compliance with these schemes, it can accelerate your compliance with NIS2. By mapping controls across frameworks, you can satisfy requirements from multiple standards. This saves you time when implementing new frameworks, adapting to new regulations, and staying up to date with existing frameworks.
Cross-border incident response
Establish cross-border incident response protocols to ensure coordinated efforts in the event of a cyber incident that affects multiple jurisdictions.
NIS2 Directive frequently asked questions
How Hyperproof helps with NIS2 compliance
With real-time risk monitoring, incident response tracking, and automated workflows, Hyperproof simplifies meeting NIS2 obligations, reducing the burden of compliance and enhancing overall cybersecurity resilience.

Jumpstart your NIS2 compliance journey with a pre-built framework template, including optional ISO 27001 and 27002 illustrative controls.
Collect, manage, and monitor your risks and ensure risk mitigation work is prioritized and completed based on customizable inherent impact and tolerance.
Crosswalk controls between programs to speed up NIS2 implementation. Avoid duplicative work and adhere to other frameworks, like the EU CRA, NIST CSF, GDPR, DORA, ISO 27001, and more.
Get clear insights into your teamās progress on assessment requests with our dashboards and reports, designed for easy sharing with key stakeholders.
Automatically assign tasks to meet NIS2 directive requirements and streamline workflows to boost efficiency, ensuring you never face delays.
Leverage Hyperproofās powerful integrations, including AWS, Azure, Github, Jira, and more to automate evidence collection and reuse that evidence across multiple controls.
Ready to see
Hyperproof in action?









