Determine scope and register where required
Map each legal entity, service and Member State, establish whether the entity is essential or important, and follow the applicable national registration route.
NIS2 establishes a shared cybersecurity baseline across the European Union. In-scope organisations need to govern risk, maintain proportionate measures, report significant incidents and show active management oversight, while following the implementation route in each Member State where they operate.
NIS2 in one minute
NIS2 is Directive (EU) 2022/2555. It raises the common level of cybersecurity across critical sectors in the EU. The Directive creates the European baseline; each Member State gives effect to it through national law and procedures.
Read the official DirectiveNIS2 covers 18 critical sectors. They include energy, transport, health, drinking water, digital infrastructure, ICT service management, public administration, space, manufacturing of certain critical products, postal services and food production and distribution.
As a rule, medium-sized and large entities providing covered services fall within scope. Certain entities can be covered regardless of size. The Directive also distinguishes essential from important entities for supervision and enforcement. The final position depends on the legal entity, service, sector and national implementation.
NIS2 is an EU Directive, so each Member State implements it through national law. Registration, competent authorities, reporting portals, supervision and effective dates can therefore differ between countries, even when the underlying responsibilities are shared.
Organisations operating across Europe need one control and evidence model with clear national overlays. Map each legal entity and service to the Member State rules that apply, then preserve the local registration, reporting and accountability route without duplicating the underlying work.
Legal, security, operations, procurement, risk, HR and the business each hold part of the picture. Management needs to see how those parts work together.
Map each legal entity, service and Member State, establish whether the entity is essential or important, and follow the applicable national registration route.
Give the management body measures it can approve and oversee, with training sufficient to understand the risks and challenge the response.
Use proportionate technical, operational and organisational measures across risk, incident handling, continuity, access and cyber hygiene.
Understand assets, systems, suppliers, service providers, vulnerabilities and the contractual relationships that can affect the service.
Detect significant incidents, meet the reporting sequence, preserve decisions and evidence, recover the service and carry lessons into the measures.
The security team may know the vulnerabilities, but the service owner knows what cannot stop. Procurement knows the supplier. HR knows the roles. Operations knows the workaround. The board sees a periodic report. NIS2 becomes difficult when these views cannot be followed as one current, accountable story.
A workable NIS2 model starts with shared records: legal entities, essential or important services, assets, systems, suppliers, risks, measures, owners, incidents, recovery plans, decisions and evidence. The operating record should show what changed and who confirmed it.
Ariadnah helps teams recover knowledge from meetings, email, policies, contracts and separate systems, then give it ownership and connect it to live work. Specialists retain responsibility for scope, risk acceptance and legal judgement. The platform keeps the reasoning and evidence usable between assessments.
Article 23 establishes a staged sequence. The operational challenge is to meet it without drawing people away from containment and recovery. National portals, competent authorities and sector-specific procedures still need to be followed.
Notify without undue delay after becoming aware of a significant incident, including whether malicious action or cross-border impact is suspected where applicable.
Update the early warning with an initial assessment of severity and impact, plus available indicators of compromise.
Explain the incident, likely root cause, impact, mitigation and any cross-border effect. Ongoing incidents use a progress report followed by a final report after handling.
A strong implementation is not a folder of policy documents. It is the ability to answer these questions from current, owned information.
Scope & service
Establish the legal and operational boundary before assigning measures.
Governance & risk
Turn policy approval into ongoing oversight of measures and exceptions.
Management oversight is not satisfied by an annual presentation. Read NIS2 Article 20: management-body responsibilities in practice for a practical evidence model covering approval, challenge, training and follow-up.
Incidents & continuity
Keep operational response, reporting and recovery connected under pressure.
Supply chain
Preserve the relationships that make third-party risk operational.
For financial entities covered by both regimes, DORA is the sector-specific Union act for the NIS2 cybersecurity risk-management, incident-reporting, supervision and enforcement provisions identified by Article 4.
The boundary is entity-specific. A group can contain a DORA financial entity, a NIS2 service provider and other entities outside one or both regimes. Shared policies and controls can still be reused, but the applicable authority, reporting route and legal accountability must remain clear.
Read the DORA guide →NIS2 is Directive (EU) 2022/2555. It establishes cybersecurity risk-management, governance, incident-reporting, supervision and cooperation requirements across critical sectors in the European Union.
NIS2 establishes a shared EU baseline, but each Member State gives effect to the Directive through national law. Effective dates, registration, competent authorities, supervision and reporting procedures can therefore differ between countries.
As a rule, medium-sized and large entities providing covered services in 18 critical sectors fall within scope. Certain entities can be covered regardless of size. The final position depends on the legal entity, service, sector and applicable national law.
The management body must approve the cybersecurity risk-management measures and oversee their implementation. Members must also follow training so they can identify risks and assess the measures and their impact on the services the organisation provides.
For a significant incident, Article 23 provides for an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report no later than one month after the incident notification. National procedures and sector-specific rules still need to be followed.
For financial entities covered by DORA, DORA is the sector-specific Union act for the NIS2 cybersecurity risk-management, reporting, supervision and enforcement provisions identified in Article 4. Scope still needs to be checked for each legal entity and activity in the group.
This guide is an operating overview, not legal advice. Scope, classification, proportionality and reporting routes depend on the entity, service, sector and jurisdiction.
A discovery call can start with scope, board oversight, supply-chain evidence, the incident-reporting sequence, or the challenge of turning existing ISO 27001 work into a current NIS2 operating record.
Book a Discovery Call →