NIS2: Broader Scope, Stricter Requirements, Real Penalties
The NIS2 Directive (2022/2555) significantly expands the scope of EU cybersecurity regulation. Where NIS1 covered a few hundred entities per member state, NIS2 covers thousands. If you're in energy, transport, banking, healthcare, digital infrastructure, public administration, manufacturing, food, chemicals, or postal services — you're likely in scope.
Member states had until 17 October 2024 to transpose NIS2 into national law. Implementation is your responsibility now.
Step 1: Determine Your Classification
Essential vs Important Entities
| Criteria | Essential Entity | Important Entity |
|---|---|---|
| Sectors | Annex I: Energy, transport, banking, health, water, digital infra, space, public admin | Annex II: Postal, waste, chemicals, food, manufacturing, digital providers, research |
| Size | Large (250+ employees or €50M+ turnover) | Medium (50+ employees or €10M+ turnover) |
| Supervision | Proactive (ex ante) | Reactive (ex post) |
| Penalties | Up to €10M or 2% global turnover | Up to €7M or 1.4% global turnover |
Step 2: Implement Risk Management Measures (Art. 21)
The 10 Minimum Measures
NIS2 Article 21(2) mandates at least these 10 cybersecurity measures:
- Risk analysis and information system security policies
- Incident handling — Detection, analysis, containment, response, recovery
- Business continuity and crisis management — Backups, disaster recovery, crisis procedures
- Supply chain security — Security requirements for suppliers and service providers
- Security in network and information systems acquisition, development, and maintenance — Including vulnerability handling
- Policies and procedures for assessing cybersecurity risk management effectiveness
- Basic cyber hygiene practices and cybersecurity training
- Policies on use of cryptography and encryption
- Human resources security, access control policies, and asset management
- Multi-factor authentication (MFA) and continuous authentication
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Step 3: Incident Reporting Setup
Reporting Timeline (Art. 23)
- 24 hours: Early warning to CSIRT/competent authority — "We have a significant incident"
- 72 hours: Incident notification with initial assessment — severity, impact, indicators of compromise
- 1 month: Final report — Root cause, mitigation measures, cross-border impact
Significant incident criteria: Caused or capable of causing severe operational disruption or financial loss; affected or capable of affecting other entities.
Step 4: Supply Chain Security
Practical Supply Chain Measures
- Vendor security assessment — Evaluate cybersecurity posture of critical suppliers before onboarding
- Contractual requirements — Include cybersecurity requirements and incident notification obligations in vendor contracts
- SBOM management — Maintain software bills of materials for critical systems (aligns with CRA)
- Continuous monitoring — Monitor vendor security ratings and vulnerability disclosures
- AI-specific: Include AI model providers, training data sources, and ML library dependencies in your supply chain risk assessment
Federated Learning and Privacy-preserving RAGs
Implement secure AI models using federated learning techniques.
Start on Pluralsight →Step 5: Board Accountability (Art. 20)
NIS2 puts personal accountability on management bodies:
- Approve cybersecurity risk management measures
- Oversee their implementation
- Undergo training to gain sufficient cybersecurity knowledge
- Can be held personally liable for non-compliance in some member state transpositions
Action: Schedule board cybersecurity briefings quarterly. Include AI-specific risks in the briefing material.
National Transposition Variations
NIS2 is a directive — member states transpose it into national law with some variation:
- Netherlands: Cyberbeveiligingswet — in development, expected to closely follow NIS2 text
- Germany: NIS2-Umsetzungsgesetz — additional critical infrastructure requirements from existing KRITIS regulation
- France: Amendments to existing ANSSI framework — historically stricter than EU minimum
- Italy: Decreto legislativo — building on existing Perimetro di Sicurezza Nazionale Cibernetica
Multi-country enterprises: Comply with the strictest transposition applicable to your operations. Map requirements per jurisdiction.
EU AI Act Compliance Checklist
40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.
Get Free Checklist →Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
