The NIS2 Directive significantly expands the EU’s cybersecurity rules, pulling thousands of additional organisations into scope. Many businesses that never considered themselves “critical infrastructure” now carry formal security and reporting duties.
Are you in scope?
NIS2 covers “essential” and “important” entities across sectors including energy, transport, health, digital infrastructure, manufacturing, food, and digital providers. Medium and large organisations in these sectors are generally caught — and so are some smaller ones that play a critical role.
What it asks of you
The core requirements are risk management measures, incident reporting within tight deadlines, supply-chain security, and — importantly — management accountability. Under NIS2, senior leaders can be held personally responsible for failures, which raises cybersecurity from an IT issue to a boardroom one.
Practical first steps
- Confirm whether your organisation qualifies as essential or important.
- Carry out a risk assessment and close the most obvious gaps.
- Establish an incident reporting process that meets the deadlines.
- Brief your board on their obligations.
NIS2 is best treated not as a compliance burden but as a structured way to reduce real operational risk. The reporting deadlines are short, so the time to prepare is before an incident, not during one.