Skip to main content
← All posts·
Regulatory Compliance

How to Implement NIS2 Compliance: Guide for Essential & Important Entities [2026]

Step-by-step NIS2 implementation guide. Covers entity classification, risk management measures, incident reporting setup, supply chain security, board accountability, and national transposition variations across EU member states.

Luca Berton13 min read

NIS2: Broader Scope, Stricter Requirements, Real Penalties

The NIS2 Directive (2022/2555) significantly expands the scope of EU cybersecurity regulation. Where NIS1 covered a few hundred entities per member state, NIS2 covers thousands. If you're in energy, transport, banking, healthcare, digital infrastructure, public administration, manufacturing, food, chemicals, or postal services — you're likely in scope.

Member states had until 17 October 2024 to transpose NIS2 into national law. Implementation is your responsibility now.

Step 1: Determine Your Classification

Essential vs Important Entities

CriteriaEssential EntityImportant Entity
SectorsAnnex I: Energy, transport, banking, health, water, digital infra, space, public adminAnnex II: Postal, waste, chemicals, food, manufacturing, digital providers, research
SizeLarge (250+ employees or €50M+ turnover)Medium (50+ employees or €10M+ turnover)
SupervisionProactive (ex ante)Reactive (ex post)
PenaltiesUp to €10M or 2% global turnoverUp to €7M or 1.4% global turnover

Step 2: Implement Risk Management Measures (Art. 21)

The 10 Minimum Measures

NIS2 Article 21(2) mandates at least these 10 cybersecurity measures:

  1. Risk analysis and information system security policies
  2. Incident handling — Detection, analysis, containment, response, recovery
  3. Business continuity and crisis management — Backups, disaster recovery, crisis procedures
  4. Supply chain security — Security requirements for suppliers and service providers
  5. Security in network and information systems acquisition, development, and maintenance — Including vulnerability handling
  6. Policies and procedures for assessing cybersecurity risk management effectiveness
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on use of cryptography and encryption
  9. Human resources security, access control policies, and asset management
  10. Multi-factor authentication (MFA) and continuous authentication
📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon

Step 3: Incident Reporting Setup

Reporting Timeline (Art. 23)

  • 24 hours: Early warning to CSIRT/competent authority — "We have a significant incident"
  • 72 hours: Incident notification with initial assessment — severity, impact, indicators of compromise
  • 1 month: Final report — Root cause, mitigation measures, cross-border impact

Significant incident criteria: Caused or capable of causing severe operational disruption or financial loss; affected or capable of affecting other entities.

Step 4: Supply Chain Security

Practical Supply Chain Measures

  • Vendor security assessment — Evaluate cybersecurity posture of critical suppliers before onboarding
  • Contractual requirements — Include cybersecurity requirements and incident notification obligations in vendor contracts
  • SBOM management — Maintain software bills of materials for critical systems (aligns with CRA)
  • Continuous monitoring — Monitor vendor security ratings and vulnerability disclosures
  • AI-specific: Include AI model providers, training data sources, and ML library dependencies in your supply chain risk assessment
🎓 Course

Federated Learning and Privacy-preserving RAGs

Implement secure AI models using federated learning techniques.

Start on Pluralsight

Step 5: Board Accountability (Art. 20)

NIS2 puts personal accountability on management bodies:

  • Approve cybersecurity risk management measures
  • Oversee their implementation
  • Undergo training to gain sufficient cybersecurity knowledge
  • Can be held personally liable for non-compliance in some member state transpositions

Action: Schedule board cybersecurity briefings quarterly. Include AI-specific risks in the briefing material.

National Transposition Variations

NIS2 is a directive — member states transpose it into national law with some variation:

  • Netherlands: Cyberbeveiligingswet — in development, expected to closely follow NIS2 text
  • Germany: NIS2-Umsetzungsgesetz — additional critical infrastructure requirements from existing KRITIS regulation
  • France: Amendments to existing ANSSI framework — historically stricter than EU minimum
  • Italy: Decreto legislativo — building on existing Perimetro di Sicurezza Nazionale Cibernetica

Multi-country enterprises: Comply with the strictest transposition applicable to your operations. Map requirements per jurisdiction.

📋 Free Resource

EU AI Act Compliance Checklist

40-point checklist covering risk classification, data governance, transparency, and human oversight. Based on the official regulation.

Get Free Checklist
NIS2
compliance
implementation
critical infrastructure
cybersecurity
how-to guide
incident reporting

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →