The Network and Information Security Directive 2 (NIS2) — Directive (EU) 2022/2555 — is the EU's updated cybersecurity framework that entered into force in October 2024. It replaces the original 2016 NIS Directive and significantly expands both the scope of organisations that must comply and the security requirements they must meet.
NIS2 focuses on three things: cybersecurity risk management, incident reporting, and supply chain security. Unlike GDPR which protects personal data, NIS2 protects the network and information systems that underpin critical services and important sectors in the EU economy.
NIS2 applies to medium and large enterprises (50+ employees AND €10M+ annual turnover) operating in any of these 15 sectors:
| High-criticality sectors | Other critical sectors |
|---|---|
| Energy (electricity, oil, gas, hydrogen) | Postal & courier services |
| Digital infrastructure (IXPs, DNS, TLD registries) | Waste management |
| Transport (air, rail, water, road) | Manufacturing of medical devices |
| Banking & financial market infrastructure | Manufacturing of critical products (chemicals, machinery, electronics) |
| Health (hospitals, healthcare providers) | Digital providers (marketplaces, search engines, social media platforms) |
| Drinking water & wastewater | Food manufacturing & processing |
| Public administration (governments at all levels) | |
| Space |
What about small businesses? If you are a small business (under 50 employees or under €10M turnover), you are not directly subject to NIS2 — but you are likely indirectly affected as a supplier to NIS2-covered entities. Your larger clients will require you to demonstrate cybersecurity controls as part of their supply chain security obligations under NIS2 Art. 21.
NIS2 Article 21 requires all covered entities to implement proportionate technical, operational and organisational measures across ten areas:
NIS2 mandates a structured 4-stage incident reporting timeline:
| Step | Deadline | Requirement |
|---|---|---|
| 1. Early warning | Within 24 hours | Notify your CSIRT (Computer Security Incident Response Team) of any significant incident. Include initial assessment of severity and impact. |
| 2. Incident notification | Within 72 hours | Submit a detailed report with cause, systems affected, exploited vulnerabilities, indicators of compromise (IOCs), and an initial impact assessment. |
| 3. Intermediate report | On request | Provide status updates as investigation progresses. The CSIRT may request additional data. |
| 4. Final report | Within 30 days | Submit a complete incident report including root cause, remediation actions taken, evidence of recovery, and measures to prevent recurrence. |
What qualifies as a "significant incident"? Any incident that has caused or is capable of causing severe operational disruption, financial loss, or harm to other entities or individuals. When in doubt, report — the penalty for failing to report is often more severe than the penalty for the underlying security gap.
While NIS2 focuses on organisational cybersecurity posture, your public-facing website is one of the first places auditors and regulators will look. Here's what they check:
All websites serving NIS2-covered entities must enforce TLS encryption. Your certificate must be valid, current, and configured correctly. HSTS (HTTP Strict Transport Security) headers should be present to prevent downgrade attacks. Mixed-content warnings (HTTP resources loaded on an HTTPS page) are a clear indicator of incomplete encryption.
Content Security Policy (CSP), X-Content-Type-Options, Referrer-Policy, X-Frame-Options, and Permissions-Policy headers are the minimum baseline. Missing headers are visible to anyone who inspects your site — including an auditor's penetration testing tools.
Third-party scripts and tracking technologies running on your site create a supply-chain attack surface. Google Analytics, Meta Pixel, Hotjar, and similar tools load JavaScript from external domains — if any of those are compromised, your site becomes the vector. NIS2 supply-chain security (Art. 21(2)(d)) requires you to know what third-party code runs on your site.
Every external domain your site connects to is a potential supply-chain risk. The more third-party scripts loading before consent, the more attack surface you expose without documented control.
An imprint/impressum and accessibility statement with operational contact details are expected. If regulators cannot identify who operates the site, they cannot assess your incident response readiness.
Use the scanner below to check your website's visible security posture — the things any NIS2 auditor would spot on first inspection. It's free, takes under 10 seconds, and requires no installation.
Enter any URL — works on all platforms. No sign-up.
Use this checklist to assess your readiness. Each item maps to a specific NIS2 Article and the type of evidence you should have ready:
| # | Requirement | NIS2 Art. | Evidence | Deadline |
|---|---|---|---|---|
| 1 | Documented cybersecurity risk assessment | 21(2)(a) | Risk register, methodology, findings, remediation plan | Ongoing |
| 2 | Written cybersecurity policy | 21(2)(a) | Policies signed by leadership, review cadence | Immediate |
| 3 | Incident detection & response plan | 21(2)(b), 23 | IR playbooks, roles matrix, escalation tree | Immediate |
| 4 | Business continuity & disaster recovery plan | 21(2)(c) | BCP document, backup verification, recovery tests | Q4 2026 |
| 5 | Supply chain vendor risk assessment | 21(2)(d) | Vendor list, risk scores, contracts with security clauses | Q4 2026 |
| 6 | Network security (firewall, segmentation, patching) | 21(2)(e) | Network diagram, patch log, vulnerability scan results | Ongoing |
| 7 | MFA on all privileged accounts | 21(2)(f) | MFA provider config, user audit, exception list | Immediate |
| 8 | Encryption in transit (TLS) + at rest | 21(2)(g) | TLS certificate inventory, encryption policy | Immediate |
| 9 | Cybersecurity awareness training | 21(2)(h) | Training records, phish test results, completion rates | Q4 2026 |
| 10 | Physical security controls | 21(2)(i) | Access logs, CCTV coverage, visitor policy | Q4 2026 |
| 11 | Vulnerability scanning & disclosure process | 21(2)(j) | Scan schedule, findings tracker, remediation SLA | Ongoing |
| 12 | Incident reporting procedure (24h / 72h / 30d) | 23 | Notification template, CSIRT contact, escalation flow | Immediate |
| 13 | Security headers on public website | 21(2)(e+g) | Live headers check (CSP, HSTS, XFO, XCTO) | Immediate |
| 14 | HTTPS enforced (no fallback to HTTP) | 21(2)(g) | HSTS header, preload status, SSL Labs rating | Immediate |
| 15 | Third-party script inventory | 21(2)(d) | List of external domains loaded, purpose, risk rating | Q4 2026 |
How to use this checklist: Start with items marked "Immediate" — they can be assessed in minutes using the free scanner. The "Ongoing" items require a recurring process you operationalise once. "Q4 2026" items need dedicated projects — start planning now.
NIS2 introduces a tiered penalty structure that is substantially higher than the original NIS Directive:
| Entity type | Maximum fine | Also applies to |
|---|---|---|
| Essential entities (high-criticality sectors) | €10,000,000 or 2% of global annual turnover (whichever is higher) | Managers can be held personally liable for failing to implement measures |
| Important entities (other critical sectors) | €7,000,000 or 1.4% of global annual turnover (whichever is higher) | Same personal liability for management |
Beyond fines, regulators can issue binding instructions to remediate identified gaps, suspend data processing activities, and publicly name non-compliant entities. Reputational damage from enforcement actions often exceeds the fine itself — especially for entities that rely on trust as a competitive differentiator.
Your website's security posture is the easiest thing to assess right now — no internal meetings, no budget approval, no vendor selection. Enter your URL into EUComply and know within seconds whether your public-facing TLS, headers, and third-party risk profile raise red flags for a NIS2 auditor.