NIS2 EU directive

NIS2 Is Knocking: The EU Cybersecurity Law That Can Fine Your Directors

and What Smart Businesses Are Doing About It

Last updated: June 2026

For years, “cybersecurity compliance” was something most business owners filed under important, but not urgent. That era is over. The EU’s NIS2 Directive has quietly become one of the most consequential pieces of business legislation in Europe — and unlike a lot of Brussels paperwork, this one comes with personal liability for company directors and fines that can reach €10 million or 2% of worldwide turnover.

If you run a company in the EU, sell into it, or sit anywhere in the supply chain of a business that does, this is your plain-language guide to what NIS2 actually is, whether it applies to you, and how to get ahead of it without panic.

What is NIS2, really?

NIS2 is the EU’s second-generation cybersecurity law (formally Directive (EU) 2022/2555). It replaced the original 2016 NIS Directive, which proved too narrow and too inconsistently enforced across member states.

The goal is simple to state and hard to deliver: raise the baseline of cyber-resilience across the sectors that modern society depends on. Think energy, transport, water, healthcare, banking, digital infrastructure, food, manufacturing, postal services, waste management, and public administration—eighteen sectors in total.

The directive itself entered into force at the EU level back in January 2023, and member states were told to incorporate it into their national laws by 17 October 2024. Most of them missed that deadline. That delay created a misleading sense of calm. By 2026, the picture looks very different: the large majority of EU countries have now transposed NIS2, the European Commission has launched infringement proceedings against the laggards, and national regulators are switching from “preparation” mode to active supervision and enforcement.

The lesson buried in that timeline is the one most businesses miss: countries that transposed late are now enforcing fast. The grace period is closing, not opening.

Does NIS2 apply to my business? (The part everyone gets wrong)

This is where most of the confusion — and most of the bad advice — lives. Let’s clear it up.

NIS2 generally applies to medium and large organizations operating in one of its covered sectors. The rule of thumb is 50 or more employees, or more than €10 million in annual turnover. Below that threshold, micro and small businesses are usually out of direct scope.

But “usually out of scope” is doing a lot of work in that sentence, and there are three big catches:

  1. Sector matters as much as size. Some entity types are in scope regardless of how small they are—for example, DNS providers, top-level domain registries, and certain trust service providers. A ten-person company can be fully regulated.
  2. Your government can pull you in. Member states can designate smaller organizations as in scope when they’re the sole provider of a critical service or when an outage would seriously affect public safety or health. Several countries have used this power generously.
  3. The supply chain catches almost everyone. Even if NIS2 never names you directly, your in-scope customers are now legally required to manage supply-chain and supplier security. In practice, that means the regulated companies you sell to will start passing the obligations down to you through contracts, security questionnaires, and audits. You can be outside the law and still firmly inside its blast radius.

So the honest answer to “Does this apply to me?” is to check your sector first, your size second, and your biggest customers third.

What NIS2 actually requires

Strip away the legalese, and NIS2 boils down to four practical demands.

Risk management you can prove. Organizations must put in place “appropriate and proportionate” technical and organizational measures—access control, encryption, backups, business continuity, vulnerability handling, multi-factor authentication, supply-chain security, and so on. Crucially, you have to be able to evidence it, not just claim it.

Fast incident reporting. When a significant incident hits, the clock starts immediately. You owe an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. There is no quietly cleaning it up and moving on.

Accountability at the top. This is the provision that has finally moved cybersecurity from the IT basement into the boardroom. NIS2 makes senior management personally responsible for approving and overseeing cyber risk measures—and in several countries, directors can face personal fines or even temporary bans from management roles for serious failures. Management is also required to undergo regular cybersecurity training.

Registration and supervision. In-scope entities must register with their national authority. “Essential” entities (the most critical) face proactive supervision — audits, inspections, security scans — while “important” entities face reactive supervision, triggered by an incident or a complaint.

The price of ignoring it

NIS2 gives regulators real teeth. For essential entities, fines can reach €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the ceiling is €7 million or 1.4% of turnover. Add in the reputational damage of a public breach disclosure, the contracts you lose when customers audit you and walk away, and the personal exposure for your leadership team, and the business case for acting early writes itself.

One directive, twenty-seven laws: why “where you operate” matters

Here’s a trap that catches even well-prepared companies. NIS2 is a directive, not a regulation — which means it doesn’t apply to your business directly. Each EU member state has to write it into its own national law, and that’s where the uniformity ends.

The core obligations are broadly consistent everywhere: risk management, incident reporting, management accountability, and supervision. But the details vary from country to country. Penalty levels, exactly which sectors and entity sizes get pulled in, the designated supervisory authority, registration mechanics, and reporting portals can all differ depending on the national transposition.

That has two practical consequences. First, the relevant rulebook is your national law, not the EU text — the directive tells you the direction, but your obligations are defined locally. Second, if you operate across several member states, you may face several overlapping regimes at once, each with its own authority and its own quirks. A multi-country business can’t write one compliance plan and assume it travels.

The transposition timeline reinforces the point. Because so many countries adopted their laws late, the enforcement start dates are now staggered across the EU — some regimes have been operating for months, others are only just switching on. The safest assumption: identify every country you’re regulated in, then check each one’s actual law and deadline rather than relying on a single EU-wide date.

A practical compliance roadmap

You don’t need to solve everything at once. You need momentum. Here’s a sensible sequence:

  1. Confirm your scope. Map your sector and size against the directive, and check whether your national transposition adds anything. If you’re unsure, assume you might be in scope and keep going.
  2. Run a gap assessment. Compare what you do today against the directive’s risk-management expectations. The gaps are your roadmap.
  3. Fix the high-impact basics first. Multi-factor authentication, tested backups, patching, access control, and an incident-response plan deliver the most protection per euro spent.
  4. Build a real incident-reporting process. Decide in advance who declares an incident, who notifies the authority, and how you’ll hit the 24-hour and 72-hour windows under pressure.
  5. Secure your supply chain. Identify your critical suppliers, assess their security, and write expectations into contracts. Expect your own customers to do the same to you.
  6. Get leadership trained and engaged. Because directors are personally on the hook, board-level sign-off and ongoing training aren’t optional extras — they’re a legal requirement.
  7. Register and document. Register with your national authority when required, and keep evidence of everything. In an audit, “we did it” without proof counts as “we didn’t.”

The bottom line

NIS2 isn’t a one-off project you complete and forget—the EU is already drafting amendments, so the rules will keep evolving through the rest of the decade. But the core message is steady: cybersecurity is now a legal duty, a board-level responsibility, and increasingly a condition of doing business with anyone serious.

The companies that treat NIS2 as a deadline will scramble. The ones that treat it as a baseline for resilience will win contracts, reassure customers, and sleep better. The window to choose which kind of company you are is open right now.


This article is general information, not legal advice. NIS2 obligations depend on your specific sector, size, and the national law of each country you operate in — and those national rules are still changing. Verify your position against the relevant national authority or a qualified advisor before acting.

Scroll to Top