Log inGet Assessment
ResourcesWhite Paper
White PaperJuly 202615 min read

In Force Across the EU: NIS2 Cybersecurity Directive

A practical guide to the EU NIS2 Cybersecurity Directive now that it is in force across member states, and what organizations need to do to comply.

Introduction

In an increasingly interconnected and digital world, protecting critical infrastructure and essential services against cyber threats has become a paramount concern for governments, businesses, and individuals. To strengthen cybersecurity across the European Union, the EU adopted the NIS2 Directive, and it is now national law across most of the bloc.

The NIS2 Directive (the Network and Information Systems Directive) is a comprehensive framework designed to strengthen the EU’s resilience against cyber incidents. Building on the original NIS Directive of 2016, NIS2 addresses emerging threats, adapts to evolving technologies, and fosters closer collaboration between public and private entities. Its main objective is harmonized, robust cybersecurity governance across member states: protecting critical infrastructure sectors and digital service providers, and raising the level of readiness and incident response that safeguards the availability, integrity, and confidentiality of vital networks and systems.

Where NIS2 Stands Today
27 Dec 2022
Published in the Official Journal (L333)
16 Jan 2023
Entered into force
17 Oct 2024
Transposition deadline passed; NIS2 is now law across most of the EU
6 Dec 2025
Germany: amended BSI Act (NIS2UmsuCG) in force, with no transition period

In short, the NIS2 Directive tightens security requirements in the EU by:

  • Extending its scope to more sectors and entities
  • Introducing the concept of “management bodies” (corporate accountability)
  • Streamlining and standardizing reporting requirements
  • Introducing control and monitoring measures
  • Harmonizing and strengthening sanctions across all member states

Is My Company Affected By NIS2?

The NIS2 Directive distinguishes between essential and important entities. The main difference: important entities are subject to lower fines and reactive supervision by the authorities, as opposed to the proactive supervision reserved for essential entities. There are no longer different minimum thresholds across the EU; applicability is determined by uniform criteria, and medium and large companies are covered.

Essential entities
  • > 250 employees
  • > €50M sales
  • > €43M balance sheet
Sectors: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space.
Important entities
  • 50–250 employees
  • €10–50M sales
  • < €43M balance sheet
Sectors: postal & courier services, waste management, food production and distribution, manufacturing, chemicals, digital providers, research.
Important note: the authorities will not tell you if this directive applies. Your company or institution must evaluate itself against the criteria, including sector elements and size considerations. An ‘important’ organization holding significant market share in its sector may even be treated as an essential entity. If none of the sectors below apply to you, NIS2 does not apply to you.

Fines And Penalties

NIS2 clarifies and strengthens the fines for non-compliance with cybersecurity risk-management measures (Article 21) and reporting obligations (Article 23). Article 34(4) provides for administrative fines that vary depending on whether the entity is essential or important:

€10M or 2%
of total worldwide annual turnover — essential entities (a maximum of at least this amount)
€7M or 1.4%
of total worldwide annual turnover — important entities (a maximum of at least this amount)

National laws can go beyond the directive’s minimum. Germany’s BSIG brings roughly 29,500 organizations into scope across 18 sectors, codifies personal liability for managing directors and boards, and sets fines of up to €10 million or 2% of global annual turnover. Always check the national law where you operate, not only the directive text.

NIS2 For Suppliers To Important And Essential Entities

Now that NIS2 is in force, the obligations reach beyond directly regulated entities. Companies that act only as suppliers feel it through their customers. The clearest example is the financial sector: banks and insurance companies have always had stringent rules, and the “banking supervisory requirements for information technology” (BAIT) provisions are an integral part of their risk management. For third-party service providers, this can mean that a client must assess their cybersecurity and include the result in the annual financial statements prepared by auditing firms.

IT service providers and other suppliers must expect supplier audits examining the robustness of their information security. De facto, the supply chain will have to meet the exact requirements that apply to regulated clients.

What Essential And Important Entities Must Do

Affected organizations must take appropriate action in areas such as cyber risk management, supply chain security, business continuity management, penetration testing, incident response, reporting, and remediation. NIS2 is also an opportunity for CISOs to reinforce their position: under the directive, senior management is responsible for managing cybersecurity risks, and violations carry severe penalties. As a CISO, the action plan for NIS2 compliance should focus on four main areas: hardening of the company’s complete tech stack, security monitoring of that stack, incident detection and response, and governance.

“Take appropriate and proportionate technical, operational and organizational measures to manage the risks posed to the security of network and information systems…” — NIS2 Article 21

Under Article 21, essential and important entities must take at least these 10 actions:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity: backup management, disaster recovery, and crisis management
  4. Supply chain security, including relationships with direct suppliers and service providers
  5. Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
  6. Policies and procedures (testing and auditing) to assess the effectiveness of cybersecurity risk-management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies and procedures regarding the use of cryptography and, where appropriate, encryption
  9. Human resources security, access control policies and asset management
  10. Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems

NIS2 Vs ISO 27001:2022

Complying with NIS2 is a multi-year program for many organizations. To make the path clearer, Mondoo maps NIS2 requirements to the ISO/IEC 27001:2022 standard. With the directive transposed and the Commission’s implementing regulation (EU) 2024/2690 setting concrete technical measures for several digital sectors, the requirements are far better defined than at adoption, and ISO 27001:2022 remains the most practical lens for gauging how far along you already are.

When aligning NIS2 measures with ISO 27001:2022, most of the relevant controls come from Annex A, which lists the security controls organizations use to demonstrate compliance with clause 6.1.3 (information security risk treatment) and its Statement of Applicability:

NIS2 (Article)ISO 27001:2022
21.2 a) policies on risk analysis and information system security5.2 Policy; 6.1.2/6.1.3 and 8.2/8.3 risk assessment & treatment; A.5.1, A.5.2, A.5.7, A.5.12, A.5.37
21.2 b) incident handlingA.5.24–A.5.28 incident management; A.6.8 event reporting; A.8.15 logging, A.8.16 monitoring
21.2 c) business continuity: backup, disaster recovery, crisis managementA.5.29, A.5.30, A.5.37; A.8.13 backup, A.8.14 redundancy, A.8.15/A.8.16
21.2 d) supply chain securityA.5.19–A.5.23 supplier relationships, ICT supply chain & cloud services
21.2 e) secure acquisition, development and maintenance, incl. vulnerability handling and disclosureA.5.37; A.8.8 technical vulnerabilities; A.8.9 configuration management; A.8.19–A.8.21
21.2 f) policies and procedures to assess the effectiveness of measures9.1 monitoring & evaluation, 9.2 internal audit, 9.3 management review; A.5.35, A.5.36
21.2 g) basic cyber hygiene and cybersecurity training7.2 competence, 7.3 awareness, 7.4 communication; A.5.10, A.5.15, A.5.16, A.6.3
21.2 h) cryptography and, where appropriate, encryptionA.8.17 clock synchronization; A.8.24 use of cryptography
21.2 i) human resources security, access control and asset managementA.5.2, A.5.3, A.5.9–A.5.11, A.5.15–A.5.18; A.6.1–A.6.7; A.7.7, A.7.9, A.7.10, A.7.14; A.8.1–A.8.5
21.2 j) multi-factor / continuous authentication, secured communicationsA.5.14, A.5.16, A.5.17; A.8.5 secure authentication
21.3 supplier-specific vulnerabilities, product quality and secure development of suppliersA.8.25–A.8.33 secure development life cycle, testing, change management
Article 23 reporting obligationsA.5.14 information transfer; A.6.8 event reporting
Article 24 European cybersecurity certification schemesA.5.20 information security within supplier agreements

NIS2: Additions To ISO 27001

The ISO 27001 Annex A controls that are not included in the mapping to NIS2:

  • A.5.4 Management responsibilities
  • A.5.5 Contact with authorities
  • A.5.6 Contact with special interest groups
  • A.5.8 Information security in project management
  • A.5.12 Classification of information
  • A.5.13 Labelling of information
  • A.5.31 Legal, statutory, regulatory and contractual requirements
  • A.5.32 Intellectual property rights
  • A.5.33 Protection of records
  • A.5.34 Privacy and protection of PII
  • A.7.1 Physical security perimeters
  • A.7.2 Physical entry
  • A.7.3 Securing offices, rooms and facilities
  • A.7.4 Physical security monitoring
  • A.7.5 Protecting against physical and environmental threats
  • A.7.6 Working in secure areas
  • A.7.8 Equipment siting and protection
  • A.7.11 Supporting utilities
  • A.7.12 Cabling security
  • A.7.13 Equipment maintenance
  • A.8.6 Capacity management
  • A.8.7 Protection against malware
  • A.8.10 Information deletion
  • A.8.11 Data masking
  • A.8.12 Data leakage prevention
  • A.8.18 Use of privileged utility programs
  • A.8.22 Segregation of networks
  • A.8.23 Web filtering
  • A.8.34 Protection of information systems during audit testing
If you already follow ISO 27001, you’re in a good starting position for NIS2. There is only one part that needs to be added to comply: incident handling and reporting.

Streamlining Incident Reporting

NIS2 imposes stricter incident response obligations and shorter timeframes than the original NIS Directive. The first step is to create or review your Incident Response Plan, so the process is fast and orderly when a reporting obligation is triggered. NIS2 works with two distinct concepts:

Incidents
Any event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data, or of the services offered by or accessible via network and information systems (Article 6(6)).
Cyber threats
Any potential circumstance, event or action that could damage, disrupt or otherwise adversely impact network and information systems and their users (Cybersecurity Act Article 2(8), referred to in NIS2 Article 6(10)).

In the event of a cyber threat or significant incident, essential and important entities must notify, without undue delay: the competent authorities or the national Computer Security Incident Response Team (CSIRT), including any information enabling determination of cross-border impact; where appropriate, the recipients of their services if the incident is likely to affect them; and, for a significant cyber threat, the measures or remedies those recipients can take. When reporting to the competent authority or CSIRT:

24 hoursInitial notification after becoming aware of the incident, indicating suspected unlawful or malicious acts or possible cross-border impact.
72 hoursIncident notification updating the previous information with an initial assessment of the significant incident, including severity, impact, and available indicators of compromise.
On requestIntermediate report on relevant status updates for a competent authority or CSIRT.
1 monthFinal report: detailed description of the incident, its severity and impact, the likely root cause, applied and ongoing mitigation, and any cross-border impact. If the incident is still ongoing, a progress report then and a final report within one month of handling it.

An incident is considered significant if it has caused (or can cause) severe operational disruption or financial loss for the entity, or has affected (or can affect) other persons by causing considerable material or non-material damage.

Each member state runs its own CSIRT, and national law designates the competent authorities: in Germany the BSI (confirmed under the amended BSI Act), in France ANSSI, in Belgium the CCB.

Sectors In The Scope Of NIS2

Sectors Classified As Essential (Annex I)

SectorType of entity
EnergyElectricity (suppliers, distribution and transmission system operators, producers, market operators), district heating and cooling, oil (pipelines, production, refining, storage, central stockholding), gas (suppliers, distribution/transmission/storage/LNG system operators, natural gas undertakings).
TransportAir (carriers, airport managing bodies, air traffic control), rail (infrastructure managers, railway undertakings), water (passenger and freight transport, port managing bodies, vessel traffic services), road (road authorities, intelligent transport systems operators).
BankingCredit institutions.
Financial market infrastructuresOperators of trading venues, central counterparties (CCPs).
HealthHealthcare providers, manufacturers of medical devices critical during a public health emergency, EU reference laboratories, entities researching and developing medicinal products, manufacturers of basic pharmaceutical products and preparations.
Drinking waterSuppliers and distributors of water intended for human consumption, excluding those for whom it is a minor part of their general activity.
Waste waterUndertakings collecting, disposing of, or treating urban, domestic, and industrial waste water where this is an essential part of the business.
SpaceOperators of ground-based infrastructure supporting the provision of space-based services, owned and managed by Member States or private parties.
B2B ICT service managementManaged service providers (MSP) and managed security service providers (MSSP).
Digital infrastructureInternet exchange points, DNS service providers, TLD name registries, cloud computing providers, datacenter providers, content delivery networks, trust service providers, providers of public electronic communications networks and services.
Public administrationPublic administration entities of central government and regional level, as defined by each Member State in accordance with national law.

Sectors Classified As Important (Annex II)

SectorType of entity
Postal & courier servicesPostal service providers, including providers of courier services.
Waste managementUndertakings carrying out waste management, excluding those for whom it is not their principal economic activity.
Food production, processing, distributionEntities engaged in wholesale distribution and industrial production and processing of food and drink.
ManufacturingMedical devices and in-vitro diagnostics; computer, electronic and optical products; electrical equipment; machinery and equipment; motor vehicles, trailers and semi-trailers; other transport equipment (ships, rail, air and spacecraft).
Digital providersOnline marketplaces, online search engines, and social networking platforms.
ResearchResearch organizations.

Summary

The NIS2 Cybersecurity Directive updates and broadens EU cybersecurity regulations, aiming to enhance resilience against cyber threats. It extends accountability to top management and imposes significant fines for non-compliance. It also affects suppliers, requiring evaluations of third-party cybersecurity. Stricter incident response requirements mandate swift reporting to national CSIRTs or competent authorities, emphasizing a proactive approach to cybersecurity.

Organizations should conduct a thorough assessment of their cybersecurity practices and determine their classification under the directive. This self-assessment helps identify areas for improvement and ensures compliance with regulatory requirements.

How Mondoo Helps With NIS2 Compliance

Meeting NIS2 is not about producing longer lists of findings. It is about closing them, continuously, and being able to prove it. Mondoo is an agentic exposure management platform that runs one continuous closed loop across your entire estate: it detects vulnerabilities and misconfigurations, prioritizes them by real risk, ships the fix, and verifies the fix held. That loop maps directly onto what Article 21 demands, from vulnerability handling and disclosure through to the ongoing assessment of how effective your security measures actually are.

Mondoo also covers the full path from source code to production. Static code analysis and secret scanning, powered by Mondoo’s open-source xgrep across 34+ languages, secure software at the source, while continuous assessment hardens cloud, containers, and the rest of your tech stack. Because NIS2 extends accountability deep into the supply chain, this source-to-close coverage gives both regulated entities and their suppliers the secure-development and third-party assurance evidence the directive requires. And because Mondoo maps its controls to NIS2 and ISO/IEC 27002:2022 out of the box, compliance shifts from a multi-year manual exercise into continuous, evidence-backed monitoring you can put straight in front of an auditor.

You don’t just find the gaps. You close them, and you can show your work.

Share

Compliance is a journey. It doesn’t have to be manual.

See how Mondoo maps NIS2 requirements to continuous, evidence-backed monitoring.