What is NIS2 compliance?
NIS2 compliance is the process through which companies meet the requirements of the European cybersecurity directive by implementing technical, organizational and procedural measures. Companies often rely on cybersecurity consulting services to achieve compliance efficiently.
Directive (EU) 2022/2555, known as NIS2, is the updated European framework for the security of network and information systems, applicable to essential and important entities across critical sectors.
NIS2 replaces the original NIS Directive from 2016 and introduces a higher level of cybersecurity requirements, procedures and responsibilities for companies. The directive expands its scope and imposes mandatory measures for risk management, incident reporting and management accountability.
Why NIS2 compliance is important
NIS2 compliance is essential for companies because it helps reduce cyberattack risks, prevent penalties and ensure business continuity. At the same time, complying with the directive increases the trust of clients, partners and stakeholders in the organization’s ability to protect data and critical infrastructure.
Steps for NIS2 compliance in companies
This guide is designed to help companies understand their obligations and prepare a practical action plan for NIS2 compliance.
1. Scope of application for NIS2 compliance
The first step is to identify how NIS2 applies to your organization. The directive covers two main categories:
Essential entities
Critical sectors such as:
- energy
- transport
- healthcare
- digital infrastructure
- public administration
- banking and financial services
- drinking water and wastewater
Important entities
Sectors that, although not traditionally critical, can have a significant impact:
- manufacturing of critical equipment
- postal and courier services
- waste management
- food production and distribution
- digital services such as marketplaces, cloud services and search engines
2. Risk assessment for NIS2 compliance
The NIS2 Directive requires companies to adopt strong cybersecurity measures covering the entire IT and operational ecosystem. These requirements include:
- cyber risk management
- security policies approved by management
- access control and strong authentication
- supply chain security
- encryption and communication protection
- continuous monitoring and incident detection
- business continuity and disaster recovery
Companies need to adopt a security governance approach, with clear processes that can be audited and demonstrated.
3. Management accountability in NIS2 compliance
A key element of the NIS2 Directive is that top management is directly responsible for compliance. Company leadership may face consequences in cases of serious non-compliance or negligence.
Management obligations include:
- approving cybersecurity policies
- supervising the implementation of security measures
- participating in cybersecurity risk training
- being involved in incident response processes
The correct implementation of NIS2 compliance measures and regular audits are essential for reducing cyber risks and meeting legal requirements.
4. Incident reporting in NIS2 compliance
NIS2 establishes strict deadlines for reporting significant cybersecurity incidents.
Companies must report:
Early warning
Within 24 hours after becoming aware of a significant incident.
Incident notification
Within 72 hours, with additional details about the incident.
Final report
Within a maximum of one month.
To meet these requirements, organizations should have:
- a formal incident response plan
- clearly defined teams and responsibilities
- active monitoring and detection systems
5. Supply chain security under NIS2
NIS2 requires companies to assess suppliers and critical partners, as vulnerabilities within the supply chain can affect the entire organization.
Companies should introduce:
- minimum cybersecurity requirements in contracts
- periodic audits
- supplier risk assessments
- clear onboarding and offboarding criteria
6. Documentation required for NIS2 compliance
Entities that fall within the scope of NIS2 must be able to demonstrate at any time that they comply with the directive’s requirements. Authorities may carry out:
- planned audits
- unannounced audits
- inspections
- document requests
Documentation should include:
- policies and procedures
- risk assessment reports
- incident registers
- evidence of implemented technical measures
- testing and simulation reports
7. Classification of entities under NIS2
NIS2 introduces two distinct regimes:
Essential entities
These are subject to proactive supervision, including:
- frequent audits
- direct checks by authorities
- extended documentation obligations
Important entities
These are mainly supervised reactively, after an incident or suspicion of non-compliance.
The classification influences the level of supervision, penalties and reporting obligations.
8. Implementing NIS2 compliance in your company
To implement NIS2 effectively, many companies need a structured program that includes:
- an initial gap assessment
- definition of responsibilities, including a cybersecurity officer or responsible person
- employee training
- updates to contracts and internal policies
- strengthening of IT infrastructure
- incident simulations and internal exercises
NIS2 compliance is not a one-time action, but an ongoing process that requires regular updates, reviews and improvements.
9. Penalties and risks under NIS2
NIS2 provides for significant penalties:
- for essential entities: up to EUR 10 million or 2% of global annual turnover
- for important entities: up to EUR 7 million or 1.4% of global annual turnover
These penalties may be accompanied by non-financial measures, including remediation orders, suspension of activities or measures against management.
NIS2 is one of the most ambitious cybersecurity initiatives in the European Union. For companies, compliance requires an integrated approach based on:
- strong governance
- clear processes
- advanced technical measures
- management accountability
- complete and updated documentation
Companies that act proactively not only reduce the risks of non-compliance, but also strengthen operational resilience and increase the trust of clients and business partners.
NIS2 compliance is an ongoing process, and the proper implementation of cybersecurity measures helps companies reduce risks and meet European legal requirements.
If your organization needs support with NIS2 compliance, contact our team to discuss your cybersecurity and regulatory requirements.



