NIS 2 replaced the original NIS Directive with three escalations: far wider scope (from a few hundred operators per country to entire sectors, registration included), harder duties (Article 21’s ten measure families, judged against the state of the art), and real enforcement (supervision, audits, binding instructions, personal accountability for management bodies). For telecoms it absorbed the old EECC security articles; for digital infrastructure and cloud, an implementing regulation specifies the measures in detail.
Being a directive, it lands as national law — and the transpositions are neither synchronised nor identical. Some member states transposed on time in 2024; others are still landing in 2026, Belgium’s law entering into force in October. Registration mechanics, sector interpretations, reporting portals and enforcement styles differ per country, which for multi-country operators turns “NIS 2 compliance” into a portfolio of national compliances with one common core.
The quietly transformative clause is supply-chain security: in-scope entities must manage the risk of their direct suppliers — and they discharge that duty contractually. Security questionnaires, audit rights, certification demands and incident-notification clauses now cascade to companies far outside NIS2’s formal scope. For every entity the directive regulates, several suppliers feel it through procurement. That cascade, not the fines, is how NIS 2 is actually changing European security behaviour.