Regulation · EU Regulatory Framework

NIS 2 — cybersecurity became a board-level legal duty

Eighteen sectors, tens of thousands of organisations, personal liability for management — and a supply-chain clause that pushes the obligations onto every supplier. NIS 2 is not an IT regulation; it is a governance regulation with technical teeth.

At a glance

Scope

18 sectors, size-capped

Energy, transport, health, digital infrastructure, cloud, manufacturing… mostly 50+ staff / €10M+, with carve-ins regardless of size

Two tiers

Essential vs. Important

Risk management, data governance, logging, robustness, human oversight, QMS

Core duties

Art. 21 measures

Risk analysis, incident handling, continuity, supply chain, encryption, MFA, training

Reporting

24h / 72h / 1 month²

Early warning, notification, final report to the national CSIRT or authority

Liability

Management, personally

Boards must approve and oversee measures; sanctions can reach individuals

Penalties

Up to €10M / 2%

Essential entities; €7M / 1.4% for important — plus suspension powers

What it is

A directive that behaves like twenty-seven laws

NIS 2 replaced the original NIS Directive with three escalations: far wider scope (from a few hundred operators per country to entire sectors, registration included), harder duties (Article 21’s ten measure families, judged against the state of the art), and real enforcement (supervision, audits, binding instructions, personal accountability for management bodies). For telecoms it absorbed the old EECC security articles; for digital infrastructure and cloud, an implementing regulation specifies the measures in detail.

Being a directive, it lands as national law — and the transpositions are neither synchronised nor identical. Some member states transposed on time in 2024; others are still landing in 2026, Belgium’s law entering into force in October. Registration mechanics, sector interpretations, reporting portals and enforcement styles differ per country, which for multi-country operators turns “NIS 2 compliance” into a portfolio of national compliances with one common core.

The quietly transformative clause is supply-chain security: in-scope entities must manage the risk of their direct suppliers — and they discharge that duty contractually. Security questionnaires, audit rights, certification demands and incident-notification clauses now cascade to companies far outside NIS2’s formal scope. For every entity the directive regulates, several suppliers feel it through procurement. That cascade, not the fines, is how NIS 2 is actually changing European security behaviour.

Key dates

The NIS 2 clock, as of July 2026

17 Oct 2024 DONE

Transposition deadline

Met by some member states; infringement procedures against the laggards

Now Rolling

National laws keep landing

Belgium in force Oct 2026; obligations differ per country as they arrive

Ongoing

Registration & supervision ramp-up

Entity registration, first audits and enforcement precedents accumulating

Continuous

The supplier cascade

Procurement clauses and questionnaires spread the duties beyond formal scope

What it means for you

Four moves that stand up to a supervisor

Settle scope and jurisdiction first

In or out, essential or important, which member states, which registrations — a written scoping analysis is the foundation every audit will start from.

Make Article 21 an engineering programme

“Appropriate measures” means state of the art for your risk — in OT environments that reads as IEC 62443, in IT as ISO 27001. Framework-based programmes survive supervision; control checklists don’t.

Prepare the board, not just the SOC

Management must approve measures, oversee them and train for them — with personal exposure. Governance evidence (decisions, budgets, reviews) is now compliance evidence.

Industrialise both directions of the supply chain

Demand certificates from suppliers; pre-package answers for customers. One assurance mapping serves both — and kills the questionnaire flood.

Expert notes

What we tell clients before they commit

The transposition patchwork is the real project

The directive’s common core hides material national divergence: registration triggers and portals, sector interpretations (is your entity “manufacturing” or “digital infrastructure”?), reporting formats, audit regimes, and timing — some countries enforcing since 2024, others only starting now. Multi-country entities that built one uniform programme against the directive text keep discovering national deltas the hard way, at registration or first incident.

Our position: one control framework, one evidence base, per-country compliance annexes. Track the transpositions as a living matrix — we maintain one, because it changes quarterly.

Article 21(2)(d) makes supplier risk your problem, but nothing obliges you to solve it with bespoke questionnaires. Recognised certificates — ISO 27001, IEC 62443, C5, NESAS, future EU schemes — plus contract clauses on maintenance and incident notification discharge the duty more defensibly than a thousand self-assessment spreadsheets. The same logic inverted: if you are the supplier, one good certificate pre-answers most of your customers’ NIS2 obligations.

Our position: write certificate-maintenance and notification clauses into procurement now, and map your own certifications to the Article 21 measures your customers must evidence. Both sides of that mapping are sales assets, not compliance costs.

NIS 2 without the questionnaire flood

Scoping, Article 21 programmes, board readiness, supplier assurance frameworks — thirty minutes to a plan that survives supervision.

Contact us

Request this document

We’ll send you access by email.