Platform

HexaCore, The unified resilience core HexaSOC, AI agentic SOC & MDR HexaInt, Cyber & dark-web intelligence HexaOT, OT & ICS security HexaComply, Compliance & TPRM HexaAI, AI security & governance HexaCustody, Digital content custody HexaStrike, Agentic offensive security HexaMatrix, ATT&CK coverage & mapping HexaView, Multi-tenant customer portal

Solutions

Managed Detection & Response, 24/7 AI-agentic detection & response Co-Managed SOC, Your team and ours, one operation Detection Engineering, Coverage you can measure Incident Response Retainer, A hand on the wheel before you need it Penetration Testing, See your estate the way attackers do Red & Purple Teaming, Offence that hardens your defence Continuous Security Validation, Validate continuously, not annually Cyber Crisis Tabletop & War-Gaming, Rehearse the bad day Continuous Threat Exposure Management, From a list of vulns to a plan Cyber Risk Quantification, Risk as a number the board can use Managed Threat Intelligence, Signal, not noise Digital Risk & Brand Protection, Protect your name where you cannot see Managed OT & IoT Monitoring, Security for systems that cannot go down OT/ICS Assessment, Know your OT before an attacker does Compliance as a Service, Gap assessment to certification Third-Party & Supply-Chain Risk Management, Risk does not stop at your perimeter Virtual CISO & Governance Advisory, Executive security leadership, on tap AI Security & Governance, Govern the AI you are adopting Managed Content Custody, Custody for your crown jewels

Industries

Maritime, Fleets, ports and shore-side IT Media & Entertainment, Pre-release content and production Casino & Gaming, Platform integrity and player trust Financial Services, DORA, resilience and fraud Critical National Infrastructure, Converged IT and OT estates Manufacturing, Plants, PLCs and supply chain Healthcare, Clinical systems and patient data Pharmaceutical & Life Sciences, Research IP, GxP and data integrity Energy & Utilities, Generation, grid and SCADA Government, Sovereign data and assurance

Partners

Partner programme, Refer, resell or white-label Cyber Dockside AI, Maritime, exclusive partner TeamLogic IT, US channel partner Walking Comet, Australia, casino & gaming Copla, GRC technology partner Nexovern, Runtime AI sensor partner

Learning

Learning Hub: explainers, guides and briefings

Company

About HexaShield Contact Book a meeting Client Login Book a demo
Explainer

NIS2: are you in scope, and what changes if you are

Broader sectors, tighter deadlines and personal accountability for management. How to work out whether it reaches you.

Updated August 2026 · 7 minute read

Directive, not regulation

This distinction matters more than it sounds. NIS2 sets the floor; each member state writes it into national law, and states have added their own detail, thresholds and reporting mechanics. If you operate in several member states you are dealing with several implementations of one directive.

The practical consequence: never plan against the directive text alone. Plan against the transposition in each state where you have an in-scope entity.

Who is in scope

NIS2 widened the net considerably. Energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space sit in one band. Postal services, waste management, chemicals, food, manufacturing of critical products, digital providers and research sit in another.

Size thresholds generally bring in medium and large entities, with carve-outs that can capture smaller ones where they are uniquely critical. Sector alone does not settle it, and neither does headcount.

Essential versus important

The classification changes how you are supervised rather than what you must do. Essential entities face proactive supervision: audits, inspections and requests can arrive unprompted. Important entities are supervised reactively, generally after evidence that something has gone wrong.

The security obligations themselves are largely common to both. Planning to be classified as important in order to do less is a poor strategy.

What it actually requires

Risk analysis and information system security policies. Incident handling. Business continuity and crisis management. Supply chain security. Security in acquisition, development and maintenance. Policies to assess the effectiveness of measures. Cyber hygiene and training. Cryptography. Access control and asset management. Multi-factor authentication and secured communications.

Two of those deserve attention because they are where most programmes are thin: assessing effectiveness, and supply chain security. Both require evidence about things you do not directly control.

Management accountability

Management bodies must approve the cyber risk measures, oversee their implementation, and can be held accountable for failures. Several transpositions attach personal consequences.

This changes what reporting has to do. A board paper that describes activity is no longer enough; the board needs to be able to demonstrate it understood the risk and approved a proportionate response.

Reporting timetable

Reporting is staged rather than single-shot: an early warning shortly after becoming aware of a significant incident, a fuller notification after that, and a final report later. Exact windows and mechanics come from your national transposition.

The reason to rehearse this is simple. The first clock starts when you become aware, which is usually the moment you have least information and most to do.

FAQ

Questions, answered

We are a manufacturer. Are we in scope?
Possibly. NIS2 covers manufacturing of certain critical product categories as an important sector, subject to size thresholds, and national transpositions vary. It is also increasingly reaching manufacturers indirectly through customers who are in scope and must secure their supply chain. Applicability is confirmed with your counsel.
Does NIS2 apply to entities outside the EU?
It can reach non-EU entities that provide certain services within the EU, and it reaches many others commercially, through in-scope customers passing obligations down their supply chain.
What is the relationship with ISO 27001?
ISO 27001 is not a substitute for NIS2 compliance, but a functioning ISMS covers a large proportion of what NIS2 asks for. The gap is usually in supply chain security, effectiveness assessment and the reporting mechanics, rather than in the core control set.

Want this applied to your estate?

Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.