NIS2: are you in scope, and what changes if you are
Broader sectors, tighter deadlines and personal accountability for management. How to work out whether it reaches you.
Directive, not regulation
This distinction matters more than it sounds. NIS2 sets the floor; each member state writes it into national law, and states have added their own detail, thresholds and reporting mechanics. If you operate in several member states you are dealing with several implementations of one directive.
The practical consequence: never plan against the directive text alone. Plan against the transposition in each state where you have an in-scope entity.
Who is in scope
NIS2 widened the net considerably. Energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space sit in one band. Postal services, waste management, chemicals, food, manufacturing of critical products, digital providers and research sit in another.
Size thresholds generally bring in medium and large entities, with carve-outs that can capture smaller ones where they are uniquely critical. Sector alone does not settle it, and neither does headcount.
Essential versus important
The classification changes how you are supervised rather than what you must do. Essential entities face proactive supervision: audits, inspections and requests can arrive unprompted. Important entities are supervised reactively, generally after evidence that something has gone wrong.
The security obligations themselves are largely common to both. Planning to be classified as important in order to do less is a poor strategy.
What it actually requires
Risk analysis and information system security policies. Incident handling. Business continuity and crisis management. Supply chain security. Security in acquisition, development and maintenance. Policies to assess the effectiveness of measures. Cyber hygiene and training. Cryptography. Access control and asset management. Multi-factor authentication and secured communications.
Two of those deserve attention because they are where most programmes are thin: assessing effectiveness, and supply chain security. Both require evidence about things you do not directly control.
Management accountability
Management bodies must approve the cyber risk measures, oversee their implementation, and can be held accountable for failures. Several transpositions attach personal consequences.
This changes what reporting has to do. A board paper that describes activity is no longer enough; the board needs to be able to demonstrate it understood the risk and approved a proportionate response.
Reporting timetable
Reporting is staged rather than single-shot: an early warning shortly after becoming aware of a significant incident, a fuller notification after that, and a final report later. Exact windows and mechanics come from your national transposition.
The reason to rehearse this is simple. The first clock starts when you become aware, which is usually the moment you have least information and most to do.
Questions, answered
We are a manufacturer. Are we in scope?
Does NIS2 apply to entities outside the EU?
What is the relationship with ISO 27001?
Want this applied to your estate?
Tell us what you are protecting and where you feel exposed. We will map it to the right capabilities and set up a walkthrough.