NIS2 is the European Union's expanded cybersecurity directive that obliges a wide range of essential and important organizations — from hospitals and utilities to food processors, postal services, and managed IT providers — to maintain baseline security measures, report serious incidents within tight deadlines, and answer for management-level failures, with fines reaching €10 million or 2% of global turnover. It entered into force in 2023, with member states translating it into national law through 2024 and enforcement activity ramping through 2025 and into 2026. If your organization operates in the EU or provides services into it, the practical question is not whether the rules apply but which registration, reporting, and security obligations your national authority now enforces.
KAJ News publishes information, not legal advice; compliance determinations require counsel familiar with your jurisdiction's implementing law.
Who is covered?
NIS2 replaces the 2016 directive of the same family and roughly quadruples the population of regulated entities. It sorts them into two tiers. Essential entities include energy, transport, banking, health, drinking water, wastewater, digital infrastructure, public administration, and space. Important entities capture a longer tail: postal services, waste management, chemicals, food production and distribution, manufacturing, digital providers, and research. The size thresholds generally kick in above 50 employees or €10 million turnover, but size exemptions vanish for special sectors like healthcare and public administration. Crucially for the supply chain, managed service providers and data-center operators are covered regardless of customer size — which is how NIS2 reaches small firms through their enterprise customers.
What must covered organizations actually do?
Article 21 lists ten minimum measures, which read like a distilled security-basics checklist:
- Risk analysis and information-system security policies
- Incident handling — detection, response, and a defined reporting chain
- Business continuity, including backups, disaster recovery, and crisis management
- Secure development and maintenance of systems, including vulnerability handling and disclosure
- Supply-chain security, evaluating providers' practices before and during contracts
- Effectiveness-testing of the above, including periodic audits and penetration testing where appropriate
- Basic cyber hygiene and training, with security awareness for all staff
- Cryptography and encryption policies
- Human-resources security, including access management and offboarding
- Multi-factor authentication and secured communications as baseline access controls
None of this is exotic. The directive mostly forces organizations to do documented, verifiable versions of what mature operators already do — and to prove it when asked.
What are the reporting deadlines?
Incident reporting runs on a strict clock once an incident is judged significant: an early warning within 24 hours, an incident notification within 72 hours covering initial assessment and indicators of compromise, and a final report within one month on root cause and mitigation. Significant incidents are those causing or capable of causing severe operational disruption or financial loss, or affecting others through the victim's services. That 24-hour early warning is the deadline most organizations are not operationally ready to meet — it presumes someone is already watching, with a drafted notification path to the national CSIRT.
Who is personally accountable, and what are the penalties?
Management bodies must approve security measures and can be held responsible for infringements — and member states are required to require training for management. Essential entities face fines up to €10 million or 2% of worldwide annual turnover, whichever is higher; important entities up to €7 million or 1.4%. Essential entities additionally face supervisory powers that include temporary suspension of certifications or authorizations and, for persistent failure, temporary bans on individuals exercising managerial functions. The directive also protects whistleblowers who report vulnerabilities or breaches.
What does NIS2 mean for non-EU companies?
Three spillover paths matter. First, EU-based subsidiaries and branches of foreign firms are directly covered. Second, covered EU entities must assess their suppliers' security, so vendors everywhere receive NIS2-shaped questionnaires and contract clauses. Third, the directive pattern is spreading — the EU's Cyber Resilience Act adds product-security duties, and other jurisdictions keep citing NIS2 as a model. As of 2026, the realistic posture for any vendor serving European customers is to meet the Article 21 list on paper and in practice, because the due-diligence chain transmits the obligation even where the law itself does not.
For more context, read The cybersecurity skills shortage: how many jobs, and does it even exist?.
For more context, read cyber insurance.
For more context, read Why schools are ransomware's favorite target.

