← Back to home NIS2 guide

NIS2 is not a cyber checklist. It is a European management responsibility.

NIS2 establishes a shared cybersecurity baseline across the European Union. In-scope organisations need to govern risk, maintain proportionate measures, report significant incidents and show active management oversight, while following the implementation route in each Member State where they operate.

NIS2 in one minute

NIS2 is Directive (EU) 2022/2555. It raises the common level of cybersecurity across critical sectors in the EU. The Directive creates the European baseline; each Member State gives effect to it through national law and procedures.

Read the official Directive
Who needs to act

Start with the legal entity, the service it provides and the sector it serves.

NIS2 covers 18 critical sectors. They include energy, transport, health, drinking water, digital infrastructure, ICT service management, public administration, space, manufacturing of certain critical products, postal services and food production and distribution.

As a rule, medium-sized and large entities providing covered services fall within scope. Certain entities can be covered regardless of size. The Directive also distinguishes essential from important entities for supervision and enforcement. The final position depends on the legal entity, service, sector and national implementation.

From one Directive to national law

One European baseline, different national routes.

NIS2 is an EU Directive, so each Member State implements it through national law. Registration, competent authorities, reporting portals, supervision and effective dates can therefore differ between countries, even when the underlying responsibilities are shared.

Organisations operating across Europe need one control and evidence model with clear national overlays. Map each legal entity and service to the Member State rules that apply, then preserve the local registration, reporting and accountability route without duplicating the underlying work.

What NIS2 asks of the organisation

Five connected responsibilities, not five separate projects.

Legal, security, operations, procurement, risk, HR and the business each hold part of the picture. Management needs to see how those parts work together.

01

Determine scope and register where required

Map each legal entity, service and Member State, establish whether the entity is essential or important, and follow the applicable national registration route.

02

Make the board accountable

Give the management body measures it can approve and oversee, with training sufficient to understand the risks and challenge the response.

03

Maintain a duty-of-care system

Use proportionate technical, operational and organisational measures across risk, incident handling, continuity, access and cyber hygiene.

04

Control dependencies

Understand assets, systems, suppliers, service providers, vulnerabilities and the contractual relationships that can affect the service.

05

Report and learn from incidents

Detect significant incidents, meet the reporting sequence, preserve decisions and evidence, recover the service and carry lessons into the measures.

Why implementation gets difficult

Security owns the controls. The organisation owns the service.

The security team may know the vulnerabilities, but the service owner knows what cannot stop. Procurement knows the supplier. HR knows the roles. Operations knows the workaround. The board sees a periodic report. NIS2 becomes difficult when these views cannot be followed as one current, accountable story.

A more durable operating model

Connect the service, its risks and its evidence before the regulator asks.

A workable NIS2 model starts with shared records: legal entities, essential or important services, assets, systems, suppliers, risks, measures, owners, incidents, recovery plans, decisions and evidence. The operating record should show what changed and who confirmed it.

Ariadnah helps teams recover knowledge from meetings, email, policies, contracts and separate systems, then give it ownership and connect it to live work. Specialists retain responsibility for scope, risk acceptance and legal judgement. The platform keeps the reasoning and evidence usable between assessments.

Significant-incident reporting

Reporting starts while response is still underway.

Article 23 establishes a staged sequence. The operational challenge is to meet it without drawing people away from containment and recovery. National portals, competent authorities and sector-specific procedures still need to be followed.

24 hours

Early warning

Notify without undue delay after becoming aware of a significant incident, including whether malicious action or cross-border impact is suspected where applicable.

72 hours

Incident notification

Update the early warning with an initial assessment of severity and impact, plus available indicators of compromise.

One month

Final report

Explain the incident, likely root cause, impact, mitigation and any cross-border effect. Ongoing incidents use a progress report followed by a final report after handling.

The NIS2 working file

The questions your records should answer without a reconstruction exercise.

A strong implementation is not a folder of policy documents. It is the ability to answer these questions from current, owned information.

Scope & service

What is actually in scope?

Establish the legal and operational boundary before assigning measures.

  • Which legal entity provides the covered service?
  • What makes the service essential or important?
  • Which systems and locations support it?
  • Which authority and CSIRT apply?
Connect services and assets →

Governance & risk

Can management see and challenge the risk?

Turn policy approval into ongoing oversight of measures and exceptions.

  • Which risks and measures has the board approved?
  • Who owns each measure and review?
  • What evidence shows the measure is effective?
  • Which exceptions need a decision?
Connect risks and measures →

Management oversight is not satisfied by an annual presentation. Read NIS2 Article 20: management-body responsibilities in practice for a practical evidence model covering approval, challenge, training and follow-up.

Incidents & continuity

Can the organisation act before all facts are known?

Keep operational response, reporting and recovery connected under pressure.

  • Who decides whether an incident is significant?
  • Which facts are needed at 24 and 72 hours?
  • Who can contact the authority and CSIRT?
  • How do lessons change measures and plans?
Connect incident decisions →

Supply chain

Can a supplier failure be followed to the service?

Preserve the relationships that make third-party risk operational.

  • Which providers can disrupt the covered service?
  • What security obligations are in the contract?
  • Which vulnerabilities and findings remain open?
  • What fallback or recovery dependency exists?
Connect suppliers and services →
NIS2 and DORA

Use the formal boundary, then reuse the operating evidence.

For financial entities covered by both regimes, DORA is the sector-specific Union act for the NIS2 cybersecurity risk-management, incident-reporting, supervision and enforcement provisions identified by Article 4.

The boundary is entity-specific. A group can contain a DORA financial entity, a NIS2 service provider and other entities outside one or both regimes. Shared policies and controls can still be reused, but the applicable authority, reporting route and legal accountability must remain clear.

Read the DORA guide →
Frequently asked questions

Short answers to the questions that usually come first.

What is NIS2?

NIS2 is Directive (EU) 2022/2555. It establishes cybersecurity risk-management, governance, incident-reporting, supervision and cooperation requirements across critical sectors in the European Union.

How is NIS2 implemented across Europe?

NIS2 establishes a shared EU baseline, but each Member State gives effect to the Directive through national law. Effective dates, registration, competent authorities, supervision and reporting procedures can therefore differ between countries.

Which organisations fall within NIS2 scope?

As a rule, medium-sized and large entities providing covered services in 18 critical sectors fall within scope. Certain entities can be covered regardless of size. The final position depends on the legal entity, service, sector and applicable national law.

What must the management body do under NIS2?

The management body must approve the cybersecurity risk-management measures and oversee their implementation. Members must also follow training so they can identify risks and assess the measures and their impact on the services the organisation provides.

What are the NIS2 incident-reporting deadlines?

For a significant incident, Article 23 provides for an early warning within 24 hours of awareness, an incident notification within 72 hours, and a final report no later than one month after the incident notification. National procedures and sector-specific rules still need to be followed.

How do NIS2 and DORA relate for financial entities?

For financial entities covered by DORA, DORA is the sector-specific Union act for the NIS2 cybersecurity risk-management, reporting, supervision and enforcement provisions identified in Article 4. Scope still needs to be checked for each legal entity and activity in the group.

Primary sources

Use the Directive, Member State law and official guidance as the final authority.

This guide is an operating overview, not legal advice. Scope, classification, proportionality and reporting routes depend on the entity, service, sector and jurisdiction.

Next step

Bring the NIS2 responsibility that is still spread across teams.

A discovery call can start with scope, board oversight, supply-chain evidence, the incident-reporting sequence, or the challenge of turning existing ISO 27001 work into a current NIS2 operating record.

Book a Discovery Call →