Cibernetica.io

Compliance

NIS2

In scope in the EU, or supplying someone who is, both routes lead here.

NIS2 is an EU directive raising cybersecurity requirements across essential and important entities, transposed into national law by each member state. Two things about it catch organisations out: it reaches considerably further down the supply chain than its predecessor, and it places obligations on management personally.

Scope, obligations, and the supply chain route

The directive covers sectors including energy, transport, banking, health, water, digital infrastructure, public administration, and several others, splitting in-scope organisations into essential and important entities with differing supervisory regimes. Core obligations cover risk management measures, incident handling, business continuity, supply chain security, and incident reporting on defined timelines — with an early warning obligation measured in hours rather than days. The supply chain provisions are what bring smaller companies into contact with NIS2. An in-scope entity must manage the security risks arising from its suppliers, which in practice means passing requirements down through contracts. Many organisations first encounter NIS2 not because they are in scope, but because a customer who is has sent them a set of obligations. UK-based organisations should note that the UK is not implementing NIS2. The UK retains the NIS Regulations 2018, with separate domestic reform in progress. A UK company can still be in scope of NIS2 by operating within a member state, or can be affected contractually by supplying an entity that is. Which applies to you depends on where you operate and who you sell to.

Who needs it

  • Organisations operating in EU member states in a covered sector
  • Suppliers who have received NIS2-derived security requirements from a customer
  • Companies uncertain whether they qualify as an essential entity, an important entity, or neither
  • Businesses with EU operations that need incident reporting processes capable of meeting the timelines

What you get

A scope determination first

Whether the directive applies to you directly, reaches you through a customer contract, or does not apply at all. Worth establishing before spending anything else.

Consultants with the relevant national transposition

Member states have implemented the directive differently. Matching accounts for where you actually operate rather than treating NIS2 as uniform.

Incident reporting that can meet the clock

Reporting obligations are measured in hours. Processes and escalation paths need to exist beforehand, not be assembled during an incident.

Frequently asked questions

Does NIS2 apply to UK companies?

The UK is not implementing NIS2 — it retains the NIS Regulations 2018 with separate domestic reform under way. However, a UK company operating in an EU member state may be in scope there, and a UK company supplying an in-scope EU entity may receive NIS2-derived obligations through contract. The supply chain route is how most UK businesses encounter it in practice.

What is the difference between an essential and an important entity?

The classification depends on sector and organisation size, and determines the supervisory regime. Essential entities face proactive supervision, including the possibility of inspections without prior cause. Important entities are supervised reactively, typically following evidence of non-compliance. The substantive security obligations are broadly similar across both.

What are the reporting deadlines?

The directive sets a staged process, beginning with an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report later. Exact mechanics follow the national transposition where you operate. The practical implication is that the decision path has to exist before an incident, because 24 hours is not enough time to invent one.

Our customer sent us NIS2 requirements. Are we in scope?

Not necessarily in scope of the directive itself, but you may be contractually bound to meet requirements your customer has passed down. That is a real obligation with commercial consequences even where the law does not reach you directly. The first step is separating what the contract requires from what the directive requires — they are frequently not the same thing.