NIS2 (Directive (EU) 2022/2555) is not just for banks and power grids: it expansively covers “essential and important entities” across 18 sectors — including food processing, manufacturing, postal services, waste management, research labs, and digital providers above size thresholds — and even sub-threshold companies get pulled in via member-state rules or supply-chain pressure from customers who are covered. Core duties read like an incident-readiness program: risk-management measures (policy, asset inventory, patching, access control, MFA, supply-chain security, crypto planning), mandatory 24-hour early-warning / 72-hour incident notification with an interim and final report, management accountability (fines AND personal liability for executives who approved inadequate measures), and registered-entity obligations Member States enforce with audits, directives, binding instructions, and — for essential entities — temporary suspension of certification or managers. The pragmatic program for an ordinary business: treat NIS2 as a forcing function for the basics that were overdue anyway — asset inventory, MFA everywhere, tested backups, a written-down incident plan with a 24/72-hour reporting capability, vendor security clauses, and board-level ownership with a named accountable executive.
If you run a mid-sized food-processing plant, a logistics firm, a municipal water utility’s contractor, or a medical-device lab, there is a decent chance a directive you have never read already applies to you. NIS2 — the EU’s second Network and Information Security Directive — replaced its 2016 predecessor with a dramatically wider scope, harder timelines, and a genuinely novel stick: personal accountability for management bodies whose organisations mishandle cyber risk.
The banks-and-grid mental model is the single most damaging misconception about NIS2. The directive’s Annexes list eighteen sectors, from energy and health through manufacturing, food, waste, postal services, chemicals, space, research, and public administration — and the size thresholds that trigger coverage are moderate, not enterprise-scale. Below the thresholds, you are still not safely “out”: Member States may register smaller high-risk providers (and several are doing exactly that for critical-supplier niches), and — often more decisively — your covered customers will contractually impose NIS2-style obligations on you because their own compliance demands supply-chain assurances.
This article is the orientation for organisations discovering NIS2 without a compliance department: who is actually caught, what the obligations concretely are, the reporting clock mechanics, what “management accountability” really means, and a pragmatic readiness program sequenced by risk-reduction-per-euro rather than by annex reference.
Who Is Actually Covered (and How Far the Ripples Go)
NIS2 sorts the world into three practical tiers:
- Essential entities (Annex I sectors — energy, transport, banking, health, drinking water, digital infrastructure, public administration, ICT service management, space…): medium-and-large entities in those sectors (50+ employees or €10M+ turnover, per the directive’s size tests), subject to the full supervisory regime including proactive audits and, at the extreme, enforcement that can reach management suspension.
- Important entities (broadened Annex II + medium-sized Annex I entities): manufacturing, food processing, waste management, chemicals, postal/courier, research, digital providers (marketplaces, search, social networks above thresholds)… The same risk-management duties apply, but supervision is ex-post: regulators act after incidents rather than auditing proactively.
- Everyone else, practically speaking: sub-threshold firms in cyber-critical niches (Member-State discretionary registration is live), plus any vendor whose covered customers demand contractual NIS2-equivalence. The supply-chain ripple is why “too small to matter” is now a niche prediction rather than a safe assumption.
Two procedural points worth more attention than they get: entities must register with their national authority (registration windows vary by Member State — several have been missed by large fractions of the in-scope population), and cloud/hosting/managed-service providers sit inside scope by their own nature, which drags their customers’ obligations into shared-responsibility conversations that many contracts are not yet written to handle.
The Core Obligations: What NIS2 Actually Demands
Article 21’s risk-management measures — the heart of the directive — are deliberately technology-neutral. In practice, an authority assessing an incident will look for evidence across ten domains:
| Article 21 domain | What it means operationally |
|---|---|
| Risk analysis & information-system security policy | Written, current, actually practised — not the PDF nobody reads |
| Incident handling | Detection capability, defined roles, a tested process that feeds the reporting clock |
| Business continuity: backups, DR, crisis management | Tested restores (an untested backup is a rumour), a crisis team that has met before the crisis |
| Supply-chain security | Vendor risk assessment, security clauses, flow-down of duties where you outsource critical functions |
| Security in acquisition, development, maintenance (incl. vulnerability handling & disclosure) | Patch management with SLAs, secure development or procurement standards, a way to receive and act on vulnerability reports |
| Policies to assess effectiveness | Metrics, reviews, internal audit — evidence the other nine rows are real |
| Cyber hygiene & training | Role-appropriate training, phishing rehearsal, aware non-IT staff |
| Cryptography & encryption policies | Where crypto protects data at rest/in transit, plus a post-quantum posture note (NIS2 mentions quantum resistance explicitly — visibility, not panic migration) |
| Access control & asset management | -knows-what-it-has inventory, least privilege, MFA, joined-up identity lifecycle |
| MFA / secured communications / emergency comms | MFA on remote access and admin paths; a crisis channel that survives email being down |
The two additions that generate the most real-world work are supply-chain security (your processors, your SaaS, your contract manufacturers — with Article 21 flowing down through contracts) and the explicit callout of 24/7 vulnerability handling and disclosure — meaning a way for third parties to report a vulnerability in your product or service, and a process that triages it. For many mid-sized firms, “we don’t have a security@ inbox” is the first gap the directive exposes.
The Reporting Clock: 24 / 72 / Final
NIS2 harmonised incident notification into a three-stage clock, and the clock is the obligation most likely to bite first — because incidents are certain, and the timeline is short:
- Early warning within 24 hours of becoming aware the incident is “significant”: you don’t need root cause, scope, or even certainty — you need to have noticed and reported. This is a low-content, high-discipline act: “we are aware of a possible significant incident, details to follow.”
- Incident notification within 72 hours: the substantive report — initial assessment of impact, what’s known, whether it’s cross-border, and indicators. If the early warning was a fire alarm, this is the size-up.
- Final report on request / within a month: the post-incident account — cause, remediation, and cross-border impact. Expect these to be requested when the incident touches systemic sectors.
“Significant incident” has defined triggers (severe operational disruption or financial loss ratios, or material non-material harm), but the operative discipline is: a capability to notice, decide, and report inside 24 hours — including weekends. An organisation whose incident process requires a steering committee meeting and a board sign-off cannot meet this clock. Neither can one whose out-of-hours path is “the IT manager’s mobile.” That capability gap, not any single technology, is the most common NIS2 reality check — and the trigger that turns an ordinary incident into an incident plus a regulatory fine for late reporting.
The single helpful equivalence: the 24/72 structure mirrors GDPR’s breach clock closely enough that organisations with a functioning DPO-and-breach pipeline already own the muscle — NIS2 reuses that reflex with sectoral authorities rather than privacy regulators. Build one incident-notification pipeline that serves both, parameterised by which regulator.
Management Accountability: The Part That Changed Everything
NIS2’s signature enforcement novelty is Article 20: the management body must approve the risk-management measures, oversee their implementation, and can be held liable for infringements — with Article 32 allowing supervisors, for essential entities, to request that management be temporarily suspended from duties in persistent-noncompliance scenarios. Fines scale to 2% of global turnover (essential) or 1.4% (important), but the personal-liability provisions changed board behaviour more than percentages ever did.
Operationally, “management accountability” needs artefacts:
- Board minutes recording cybersecurity discussions and approvals (a periodic agenda item, not an annual snapshot)
- A named accountable executive (the directive-era equivalent of the DPO role for security — some Member States formalise this)
- Training for the management body itself — NIS2 explicitly requires management be trained to understand risks and evaluate effectiveness
- Risk-acceptance decisions made on the record: if leadership accepts a gap (budget, timeline, practicality), the acceptance and its rationale are documented — which converts “we knew and chose” from a liability amplifier into a defensible governance decision
The uncomfortable contrapositive: an untrained management body that never discussed security and delegated it entirely downward is precisely the fact-pattern Article 20 was drafted against. The first artefact every covered organisation should create is the board pack: current security posture, top risks, incident readiness status, and the reporting-clock capability — because that pack is the liability boundary.
A Pragmatic Readiness Program (Sequenced by Risk Reduction, Not Annex)
For an ordinary mid-sized organisation starting realistically from partial coverage:
- Determine your status deliberately (weeks 1–2): sector + size assessment against Annexes I/II with counsel; check your Member State’s registry and registration deadlines; and inventory which customers have started contractually demanding NIS2 assurances — the supply-chain ripple frequently bites before any regulator does.
- Stand up the 24/72 capability early (weeks 2–8): an out-of-hours escalation path that ends in a human; a decision rule for “is this potentially significant” that a duty manager can apply at 2am; pre-drafted notification templates; a tested means to contact the authority. This pays for itself in the first incident regardless of NIS2.
- Fix identity first (quarter 1): MFA on every remote-access and admin path; joiner-mover-leaver process; privileged accounts inventoried and reduced; password-manager rollout. Identity is simultaneously the top incident driver and the cheapest large risk reduction.
- Asset inventory and backup testing (quarter 1–2): you cannot patch or report scope without knowing systems; test restores quarterly. NIS2’s “asset management” domain is unglamorous and load-bearing.
- Supply-chain triage (quarter 2): rank vendors by blast radius; get the top ten into security clauses and a review cadence; require incident-notification flow to you from critical providers.
- Vulnerability handling face (quarter 2): a monitored security inbox, a disclosure policy page, a patch-SLA matrix by severity. Small cost, removes an entire class of “we never saw the report” embarrassments.
- Board pack and training (quarter 2, then perpetual): the accountability artefacts from the previous section — this converts the program from IT project into governance, which is where NIS2’s deputies will look.
- Exercise it (quarter 2–3): a tabletop that walks an incident through detection → decision → 24h early warning → 72h notification → authority contact. First tabletops reliably surface broken phone trees and absent decision rules — cheap lessons before the regulator’s clock is live.
Total honest timeline for a mid-sized firm from standing start to defensible NIS2 posture: 12–18 months with internal ownership plus selective external help — faster where a GDPR-grade incident pipeline already exists (it halves step 2’s cost).
FAQ: NIS2 for Ordinary Businesses
We’re 60 people in food manufacturing — are we really covered?
Very possibly yes: food is an Annex II sector, and the size thresholds (50+ employees or €10M+ turnover) catch mid-sized firms. As an “important entity” you carry the same risk-management and 24/72 reporting duties — supervision is ex-post rather than audit-driven, but the obligations are real, and your covered customers will impose them contractually regardless.
How is NIS2 different from GDPR?
They rhyme structurally (risk-management duties, a regulated notification clock, serious fines) but protect different things: GDPR protects personal-data privacy with a 72-hour breach clock; NIS2 protects network-and-information-system security with a 24-hour early warning plus 72-hour substantive notification, sector-scoped authorities, and — its novelty — direct management liability. Organisations with a working GDPR breach pipeline should extend it to serve both clocks.
What happens if we miss the 24-hour early warning?
The 24h window exists so authorities can watch for cross-sector cascades early; missing it (or being incapable of it) is itself an infringement that stacks onto the incident. The required content is minimal — awareness + intent to follow up — so the investment is a working out-of-hours escalation path and a pre-approved template, not sophisticated forensics.
Do we need a CISO / security team to comply?
Not necessarily a dedicated CISO; NIS2 needs a capability, not an org chart. A named accountable executive, documented ownership of security functions (internal or as-a-service), and evidence the Article 21 domains are actually practised satisfy the substance. External security officers-as-a-service are a legitimate pattern for mid-sized entities — the failure mode is abdicating oversight, not outsourcing execution.
How does NIS2 reach us through our customers?
Covered entities must manage supply-chain risk — so their contracts with you increasingly demand: security clauses, incident notification to them within defined hours, audit or attestation rights, and evidence of your own controls. For many sub-threshold firms, the commercially binding version of NIS2 arrives a year before the legal one; treat customer security questionnaires as your true scope signal.
What’s the first thing to do this week?
Three moves: (1) assess your sector/size status and your Member State’s registration requirement with counsel; (2) write the one-page out-of-hours incident escalation path and verify it reaches a decision-capable human; (3) put NIS2 on the next management-meeting agenda with the Article 20 liability point — because an informed, on-the-record management body is both the directive’s core demand and your best defence.
Key Takeaways
- NIS2 is not bank-and-grid regulation: 18 sectors including food, manufacturing, postal, waste, research, and digital services, with moderate size thresholds — and sub-threshold firms still get pulled in via Member-State registration and covered customers’ contractual flow-down.
- The obligations are an incident-readiness program, not a shopping list: Article 21’s ten domains (policy, incident handling, backup testing, supply-chain security, vulnerability handling, hygiene training, crypto planning, access control, MFA, effectiveness measurement) reward organisations that operationalise rather than paper them.
- The 24/72-hour reporting clock is the first duty that bites: 24-hour early warning (minimal content, maximal discipline), 72-hour substantive notification, final report on request — requiring a weekend-capable escalation path and pre-drafted templates; reuse your GDPR pipeline as the skeleton.
- Management accountability is the enforcement novelty: boards must approve, oversee, train, and document — with personal liability and, for essential entities, potential temporary management suspension; start the board pack now, because it defines the liability boundary.
- Sequence by risk-reduction-per-euro: status determination, then the reporting capability, then identity/MFA, inventory and restore-testing, supply-chain triage, a vulnerability-handling face, and an exercised tabletop — a defensible posture in 12–18 months, faster if GDPR muscle already exists.
References
- Directive (EU) 2022/2555 (NIS2) — Annexes I/II sector scope, Article 21 risk-management measures, Article 20 management accountability, Articles 23/33 incident notification & enforcement
- European Commission NIS2 implementation guidance & national transposition trackers (registration deadlines and sectoral authority maps per Member State)
- ENISA — NIS2 implementation advice, incident-notification templates, and the technical-methodology series for essential/important entities
- National competent-authority portals (e.g., recognise-your-sector self-assessment tools published during transposition)
- Internal: The First 24 Hours of a Ransomware Attack — the operational playbook behind the 24-hour clock
