NIS2: whether you are in scope, and what it asks of an engineering team

NIS2 pulled in far more companies than its predecessor, added personal liability for management, and set a 24-hour first notification. What the directive actually requires, in engineering terms.

The NIS2 directive replaced the 2016 NIS directive and had to be transposed into national law across the EU by October 2024. Two things changed that matter to companies who had never thought about it: the scope expanded substantially, and the enforcement acquired teeth, including personal responsibility for management bodies.

The first question is whether it applies to you, and a surprising number of companies get this wrong in both directions.

Scope, in practice

NIS2 uses a size-and-sector test. If you operate in one of the listed sectors and you are a medium-sized enterprise or larger — 50 or more employees, or annual turnover and balance sheet above €10 million — you are in scope by default.

The sectors in Annex I (essential entities) include energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management (business-to-business), public administration and space. The digital infrastructure and ICT service management categories are the ones that catch technology companies: cloud computing service providers, data centre service providers, content delivery networks, trust service providers, DNS providers, and managed service and managed security service providers.

Annex II (important entities) covers postal services, waste management, chemicals, food, manufacturing of certain products, digital providers (online marketplaces, search engines, social platforms) and research.

Two consequences people miss:

If you sell managed IT or managed security services, you are probably in scope regardless of what your customers do. MSPs were explicitly brought in because they are a supply chain route into everyone else.

If you are not in scope, your customers who are will pass the obligations to you contractually. The supply chain provisions require in-scope entities to manage supplier risk, and that arrives as clauses in your next renewal: incident notification timelines, evidence of security measures, audit rights. Many companies first encounter NIS2 this way.

Member states also designate entities below the size threshold — sole providers of a critical service in a country, for example — so the size test is a default, not a guarantee.

The ten measures, translated

Article 21 lists the risk management measures. Stripped of the legal phrasing, in engineering terms:

  1. Risk analysis and information system security policies. A maintained risk register, not a document written once.
  2. Incident handling. Detection, response, and the notification path below.
  3. Business continuity: backup management, disaster recovery, crisis management. A tested restore, with the time it took.
  4. Supply chain security. Which suppliers can reach your systems or your data, what their security posture is, and what happens when one of them is breached. An SBOM is part of this answer for the software side.
  5. Security in acquisition, development and maintenance, including vulnerability handling and disclosure. A route for someone outside to report a vulnerability, and an SLA for acting on one.
  6. Policies to assess effectiveness. Measure whether the controls work; do not assert it.
  7. Basic cyber hygiene and training.
  8. Cryptography and encryption policies.
  9. Human resources security, access control and asset management.
  10. MFA or continuous authentication, secured voice, video and text communications, and secured emergency communication. MFA is named explicitly — this is the single most commonly missing item.

The obligations are proportionate to the entity's size, exposure and risk, so a 60-person ICT provider is not held to the standard of a national grid operator. But "proportionate" is assessed against your risk, not your convenience.

The reporting clock

This is the operationally sharpest part of the directive:

  • Within 24 hours of becoming aware of a significant incident: an early warning to the CSIRT or competent authority, stating whether it is suspected to be caused by unlawful or malicious acts and whether it could have cross-border impact.
  • Within 72 hours: an incident notification updating the early warning, with an initial assessment of severity, impact and indicators of compromise.
  • Within one month: a final report with root cause, mitigations applied and cross-border impact.

An incident is significant if it causes or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage to others.

Twenty-four hours is short. It means someone on call has to know, at 3 a.m., that this threshold exists, who the national authority is, and where the reporting form lives. Put that in the runbook with the contact details filled in. A team that has to find out who to notify while the incident is running will miss the window.

Management liability

This is the change that gets attention in boardrooms. Management bodies must approve the risk management measures, oversee their implementation, and can be held personally liable for failures. They are also required to follow training.

Practically, this means the security programme needs a named executive owner, evidence that the board reviewed and approved it, and dated training records. A programme that lives entirely inside the engineering team, with no board record, does not satisfy the directive however good the controls are.

Penalties reach €10 million or 2 percent of global annual turnover for essential entities, and €7 million or 1.4 percent for important entities.

If you already have ISO 27001

You are most of the way there on the measures. ISO 27001 covers risk management, continuity, supply chain, access control, cryptography and training, and the evidence habits transfer directly.

What ISO does not give you is the notification capability against a 24-hour clock, the registration with your national authority, or the management approval trail in the form NIS2 expects. Those three are the gap, and all three are weeks of work rather than months — provided somebody starts them before the incident rather than during it.

ConsultorIA

Want this done on your cloud?

A ten-day read-only assessment is free, and Skyline lets you see your estate on a map before you write to us.

Related articles