In Force Across the EU: NIS2 Cybersecurity Directive
A practical guide to the EU NIS2 Cybersecurity Directive now that it is in force across member states, and what organizations need to do to comply.
Introduction
In an increasingly interconnected and digital world, protecting critical infrastructure and essential services against cyber threats has become a paramount concern for governments, businesses, and individuals. To strengthen cybersecurity across the European Union, the EU adopted the NIS2 Directive, and it is now national law across most of the bloc.
The NIS2 Directive (the Network and Information Systems Directive) is a comprehensive framework designed to strengthen the EU’s resilience against cyber incidents. Building on the original NIS Directive of 2016, NIS2 addresses emerging threats, adapts to evolving technologies, and fosters closer collaboration between public and private entities. Its main objective is harmonized, robust cybersecurity governance across member states: protecting critical infrastructure sectors and digital service providers, and raising the level of readiness and incident response that safeguards the availability, integrity, and confidentiality of vital networks and systems.
In short, the NIS2 Directive tightens security requirements in the EU by:
- Extending its scope to more sectors and entities
- Introducing the concept of “management bodies” (corporate accountability)
- Streamlining and standardizing reporting requirements
- Introducing control and monitoring measures
- Harmonizing and strengthening sanctions across all member states
Is My Company Affected By NIS2?
The NIS2 Directive distinguishes between essential and important entities. The main difference: important entities are subject to lower fines and reactive supervision by the authorities, as opposed to the proactive supervision reserved for essential entities. There are no longer different minimum thresholds across the EU; applicability is determined by uniform criteria, and medium and large companies are covered.
- > 250 employees
- > €50M sales
- > €43M balance sheet
- 50–250 employees
- €10–50M sales
- < €43M balance sheet
Fines And Penalties
NIS2 clarifies and strengthens the fines for non-compliance with cybersecurity risk-management measures (Article 21) and reporting obligations (Article 23). Article 34(4) provides for administrative fines that vary depending on whether the entity is essential or important:
National laws can go beyond the directive’s minimum. Germany’s BSIG brings roughly 29,500 organizations into scope across 18 sectors, codifies personal liability for managing directors and boards, and sets fines of up to €10 million or 2% of global annual turnover. Always check the national law where you operate, not only the directive text.
NIS2 For Suppliers To Important And Essential Entities
Now that NIS2 is in force, the obligations reach beyond directly regulated entities. Companies that act only as suppliers feel it through their customers. The clearest example is the financial sector: banks and insurance companies have always had stringent rules, and the “banking supervisory requirements for information technology” (BAIT) provisions are an integral part of their risk management. For third-party service providers, this can mean that a client must assess their cybersecurity and include the result in the annual financial statements prepared by auditing firms.
IT service providers and other suppliers must expect supplier audits examining the robustness of their information security. De facto, the supply chain will have to meet the exact requirements that apply to regulated clients.
What Essential And Important Entities Must Do
Affected organizations must take appropriate action in areas such as cyber risk management, supply chain security, business continuity management, penetration testing, incident response, reporting, and remediation. NIS2 is also an opportunity for CISOs to reinforce their position: under the directive, senior management is responsible for managing cybersecurity risks, and violations carry severe penalties. As a CISO, the action plan for NIS2 compliance should focus on four main areas: hardening of the company’s complete tech stack, security monitoring of that stack, incident detection and response, and governance.
“Take appropriate and proportionate technical, operational and organizational measures to manage the risks posed to the security of network and information systems…” — NIS2 Article 21
Under Article 21, essential and important entities must take at least these 10 actions:
- Policies on risk analysis and information system security
- Incident handling
- Business continuity: backup management, disaster recovery, and crisis management
- Supply chain security, including relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
- Policies and procedures (testing and auditing) to assess the effectiveness of cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies and procedures regarding the use of cryptography and, where appropriate, encryption
- Human resources security, access control policies and asset management
- Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems
NIS2 Vs ISO 27001:2022
Complying with NIS2 is a multi-year program for many organizations. To make the path clearer, Mondoo maps NIS2 requirements to the ISO/IEC 27001:2022 standard. With the directive transposed and the Commission’s implementing regulation (EU) 2024/2690 setting concrete technical measures for several digital sectors, the requirements are far better defined than at adoption, and ISO 27001:2022 remains the most practical lens for gauging how far along you already are.
When aligning NIS2 measures with ISO 27001:2022, most of the relevant controls come from Annex A, which lists the security controls organizations use to demonstrate compliance with clause 6.1.3 (information security risk treatment) and its Statement of Applicability:
| NIS2 (Article) | ISO 27001:2022 |
|---|---|
| 21.2 a) policies on risk analysis and information system security | 5.2 Policy; 6.1.2/6.1.3 and 8.2/8.3 risk assessment & treatment; A.5.1, A.5.2, A.5.7, A.5.12, A.5.37 |
| 21.2 b) incident handling | A.5.24–A.5.28 incident management; A.6.8 event reporting; A.8.15 logging, A.8.16 monitoring |
| 21.2 c) business continuity: backup, disaster recovery, crisis management | A.5.29, A.5.30, A.5.37; A.8.13 backup, A.8.14 redundancy, A.8.15/A.8.16 |
| 21.2 d) supply chain security | A.5.19–A.5.23 supplier relationships, ICT supply chain & cloud services |
| 21.2 e) secure acquisition, development and maintenance, incl. vulnerability handling and disclosure | A.5.37; A.8.8 technical vulnerabilities; A.8.9 configuration management; A.8.19–A.8.21 |
| 21.2 f) policies and procedures to assess the effectiveness of measures | 9.1 monitoring & evaluation, 9.2 internal audit, 9.3 management review; A.5.35, A.5.36 |
| 21.2 g) basic cyber hygiene and cybersecurity training | 7.2 competence, 7.3 awareness, 7.4 communication; A.5.10, A.5.15, A.5.16, A.6.3 |
| 21.2 h) cryptography and, where appropriate, encryption | A.8.17 clock synchronization; A.8.24 use of cryptography |
| 21.2 i) human resources security, access control and asset management | A.5.2, A.5.3, A.5.9–A.5.11, A.5.15–A.5.18; A.6.1–A.6.7; A.7.7, A.7.9, A.7.10, A.7.14; A.8.1–A.8.5 |
| 21.2 j) multi-factor / continuous authentication, secured communications | A.5.14, A.5.16, A.5.17; A.8.5 secure authentication |
| 21.3 supplier-specific vulnerabilities, product quality and secure development of suppliers | A.8.25–A.8.33 secure development life cycle, testing, change management |
| Article 23 reporting obligations | A.5.14 information transfer; A.6.8 event reporting |
| Article 24 European cybersecurity certification schemes | A.5.20 information security within supplier agreements |
NIS2: Additions To ISO 27001
The ISO 27001 Annex A controls that are not included in the mapping to NIS2:
- A.5.4 Management responsibilities
- A.5.5 Contact with authorities
- A.5.6 Contact with special interest groups
- A.5.8 Information security in project management
- A.5.12 Classification of information
- A.5.13 Labelling of information
- A.5.31 Legal, statutory, regulatory and contractual requirements
- A.5.32 Intellectual property rights
- A.5.33 Protection of records
- A.5.34 Privacy and protection of PII
- A.7.1 Physical security perimeters
- A.7.2 Physical entry
- A.7.3 Securing offices, rooms and facilities
- A.7.4 Physical security monitoring
- A.7.5 Protecting against physical and environmental threats
- A.7.6 Working in secure areas
- A.7.8 Equipment siting and protection
- A.7.11 Supporting utilities
- A.7.12 Cabling security
- A.7.13 Equipment maintenance
- A.8.6 Capacity management
- A.8.7 Protection against malware
- A.8.10 Information deletion
- A.8.11 Data masking
- A.8.12 Data leakage prevention
- A.8.18 Use of privileged utility programs
- A.8.22 Segregation of networks
- A.8.23 Web filtering
- A.8.34 Protection of information systems during audit testing
Streamlining Incident Reporting
NIS2 imposes stricter incident response obligations and shorter timeframes than the original NIS Directive. The first step is to create or review your Incident Response Plan, so the process is fast and orderly when a reporting obligation is triggered. NIS2 works with two distinct concepts:
In the event of a cyber threat or significant incident, essential and important entities must notify, without undue delay: the competent authorities or the national Computer Security Incident Response Team (CSIRT), including any information enabling determination of cross-border impact; where appropriate, the recipients of their services if the incident is likely to affect them; and, for a significant cyber threat, the measures or remedies those recipients can take. When reporting to the competent authority or CSIRT:
An incident is considered significant if it has caused (or can cause) severe operational disruption or financial loss for the entity, or has affected (or can affect) other persons by causing considerable material or non-material damage.
Each member state runs its own CSIRT, and national law designates the competent authorities: in Germany the BSI (confirmed under the amended BSI Act), in France ANSSI, in Belgium the CCB.
Sectors In The Scope Of NIS2
Sectors Classified As Essential (Annex I)
| Sector | Type of entity |
|---|---|
| Energy | Electricity (suppliers, distribution and transmission system operators, producers, market operators), district heating and cooling, oil (pipelines, production, refining, storage, central stockholding), gas (suppliers, distribution/transmission/storage/LNG system operators, natural gas undertakings). |
| Transport | Air (carriers, airport managing bodies, air traffic control), rail (infrastructure managers, railway undertakings), water (passenger and freight transport, port managing bodies, vessel traffic services), road (road authorities, intelligent transport systems operators). |
| Banking | Credit institutions. |
| Financial market infrastructures | Operators of trading venues, central counterparties (CCPs). |
| Health | Healthcare providers, manufacturers of medical devices critical during a public health emergency, EU reference laboratories, entities researching and developing medicinal products, manufacturers of basic pharmaceutical products and preparations. |
| Drinking water | Suppliers and distributors of water intended for human consumption, excluding those for whom it is a minor part of their general activity. |
| Waste water | Undertakings collecting, disposing of, or treating urban, domestic, and industrial waste water where this is an essential part of the business. |
| Space | Operators of ground-based infrastructure supporting the provision of space-based services, owned and managed by Member States or private parties. |
| B2B ICT service management | Managed service providers (MSP) and managed security service providers (MSSP). |
| Digital infrastructure | Internet exchange points, DNS service providers, TLD name registries, cloud computing providers, datacenter providers, content delivery networks, trust service providers, providers of public electronic communications networks and services. |
| Public administration | Public administration entities of central government and regional level, as defined by each Member State in accordance with national law. |
Sectors Classified As Important (Annex II)
| Sector | Type of entity |
|---|---|
| Postal & courier services | Postal service providers, including providers of courier services. |
| Waste management | Undertakings carrying out waste management, excluding those for whom it is not their principal economic activity. |
| Food production, processing, distribution | Entities engaged in wholesale distribution and industrial production and processing of food and drink. |
| Manufacturing | Medical devices and in-vitro diagnostics; computer, electronic and optical products; electrical equipment; machinery and equipment; motor vehicles, trailers and semi-trailers; other transport equipment (ships, rail, air and spacecraft). |
| Digital providers | Online marketplaces, online search engines, and social networking platforms. |
| Research | Research organizations. |
Summary
The NIS2 Cybersecurity Directive updates and broadens EU cybersecurity regulations, aiming to enhance resilience against cyber threats. It extends accountability to top management and imposes significant fines for non-compliance. It also affects suppliers, requiring evaluations of third-party cybersecurity. Stricter incident response requirements mandate swift reporting to national CSIRTs or competent authorities, emphasizing a proactive approach to cybersecurity.
Organizations should conduct a thorough assessment of their cybersecurity practices and determine their classification under the directive. This self-assessment helps identify areas for improvement and ensures compliance with regulatory requirements.
How Mondoo Helps With NIS2 Compliance
Meeting NIS2 is not about producing longer lists of findings. It is about closing them, continuously, and being able to prove it. Mondoo is an agentic exposure management platform that runs one continuous closed loop across your entire estate: it detects vulnerabilities and misconfigurations, prioritizes them by real risk, ships the fix, and verifies the fix held. That loop maps directly onto what Article 21 demands, from vulnerability handling and disclosure through to the ongoing assessment of how effective your security measures actually are.
Mondoo also covers the full path from source code to production. Static code analysis and secret scanning, powered by Mondoo’s open-source xgrep across 34+ languages, secure software at the source, while continuous assessment hardens cloud, containers, and the rest of your tech stack. Because NIS2 extends accountability deep into the supply chain, this source-to-close coverage gives both regulated entities and their suppliers the secure-development and third-party assurance evidence the directive requires. And because Mondoo maps its controls to NIS2 and ISO/IEC 27002:2022 out of the box, compliance shifts from a multi-year manual exercise into continuous, evidence-backed monitoring you can put straight in front of an auditor.
You don’t just find the gaps. You close them, and you can show your work.
Compliance is a journey. It doesn’t have to be manual.
See how Mondoo maps NIS2 requirements to continuous, evidence-backed monitoring.
