EinloggenAssessment anfordern
Compliance Guide

Understanding and Meeting EU's NIS2 Cybersecurity Directive

A practical guide to achieving compliance with the EU Network and Information Security Directive 2 (NIS2). Learn what's required and how to prepare.

NIS2 is in force
The EU transposition deadline (17 October 2024) has passed. NIS2 now applies through national law, and the rules that bind you are your member state's. In Germany that is the amended BSI Act, in force since 6 December 2025.

Whitepaper herunterladen

Füllen Sie das Formular aus, um sofortigen Zugang zum vollständigen NIS2-Compliance-Whitepaper zu erhalten.

Mit dem Absenden dieses Formulars stimmen Sie unserer Datenschutzerklärung zu.

Affected sectors

NIS2 covers 18 sectors across two annexes, plus their supply chains

Annex I, essential
  • Energy
  • Transport
  • Banking
  • Financial market infrastructures
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure
  • ICT service management (B2B)
  • Public administration
  • Space
Annex II, important
  • Manufacturing
  • Chemicals
  • Food
  • Postal and courier services
  • Waste management
  • Digital providers
  • Research

Key NIS2 Requirements

The directive mandates these security measures for covered entities

Risk Management
Implement comprehensive cyber risk management measures
Incident Reporting
Report significant incidents within 24-72 hours
Supply Chain
Assess and manage third-party security risks
Business Continuity
Ensure operational resilience and recovery
Encryption
Implement appropriate cryptographic controls
Access Control
Enforce multi-factor authentication and least privilege

Path to Compliance

Follow these steps to achieve and maintain NIS2 compliance

01

Assess Your Scope

Determine if your organization falls under NIS2 as an essential or important entity based on sector and size criteria.

02

Gap Analysis

Evaluate your current security posture against NIS2 requirements to identify areas needing improvement.

03

Implement Controls

Deploy technical and organizational measures to address identified gaps and meet NIS2 requirements.

04

Document Everything

Maintain comprehensive documentation of policies, procedures, and security measures for audit purposes.

05

Continuous Monitoring

Establish ongoing monitoring and assessment processes to maintain compliance over time.

Non-Compliance Penalties

NIS2 introduces significant penalties for non-compliance

Essential entities
Up to €10M or 2% of total worldwide annual turnover, whichever is higher
Important entities
Up to €7M or 1.4% of total worldwide annual turnover, whichever is higher
Management accountability
Management bodies must approve and oversee the risk-management measures, and can be held accountable for failures

NIS2 Timeline

January 2023
NIS2 Directive entered into force
October 2024
EU transposition deadline. Most member states missed it.
December 2025
Germany's implementation enters force, with no transition period
Ongoing
National deadlines and supervision differ by member state

Need Help with NIS2 Compliance?

Mondoo closes the loop on the technical measures NIS2 holds you accountable for: continuous assessment, the shipped fix, and the evidence that it worked.

Request a Demo