Clear answers to the most common questions from European SMEs about NIS2 requirements, cybersecurity obligations, and how to get started.
NIS2 (Network and Information Security Directive 2) is the EU's updated cybersecurity law, significantly expanding who must comply and introducing personal liability for management. It affects approximately 350,000 organizations across the EU—including many mid-sized companies that never considered themselves "cybersecurity-relevant."
The key changes from the original directive:
NIS2 generally applies if you operate in a covered sector AND meet size thresholds: 50+ employees OR €10M+ annual revenue. The 18 sectors covered by NIS2 are: energy; transport; banking; financial market infrastructures; health; drinking water; wastewater; digital infrastructure; ICT service management (B2B); public administration; space; postal and courier services; waste management; chemicals; food production, processing and distribution; manufacturing; digital providers; and research organisations.
But here's the catch: even if you're below these thresholds, you may still be affected:
Many companies outside NIS2's direct scope are already receiving security questionnaires from their larger customers.
Our free NIS2 applicability report tells you in minutes whether the directive applies to your organization.
Check Your Status →The EU deadline for member states to transpose NIS2 into national law was October 2024. Some countries have grace periods for registration and compliance, but the core requirements are already defined. Track the implementation of the NIS2 Directive across all EU Member States with our NIS2 Legislation Status tracker.
The reality: 95% of what NIS2 requires is already known. Waiting for "final" national guidance means falling behind. Organizations that start gap assessments now will be positioned to comply; those who wait will face resource constraints as specialists become scarce closer to enforcement dates.
This is the most significant shift in NIS2: cybersecurity is now explicitly a board-level responsibility, not something that can be delegated to IT. Under NIS2, management bodies must:
The consequences are real: in cases of non-compliance, executives can face temporary bans from management positions. Some national implementations (like Poland) include fines of up to 600% of salary for negligent managers. This isn't theoretical—NIS2 makes clear that failing to ensure cybersecurity constitutes a breach of fiduciary duty.
No, and this misconception is precisely what NIS2 targets. IT and cybersecurity are related but fundamentally different disciplines—like general medicine and cardiology. Your IT team manages infrastructure; cybersecurity requires specialized threat intelligence, incident response planning, and risk assessment that most internal IT teams aren't resourced to provide.
More importantly, NIS2 explicitly requires management oversight. You cannot delegate this responsibility to IT and consider yourself compliant. Boards must understand the risks, approve the measures, and demonstrate they're actively engaged—not just signing off on whatever IT recommends.
This is the most dangerous myth in cybersecurity. The data tells a different story:
Why? Because attackers use automated tools that scan the internet for vulnerable systems—they don't discriminate by company size. Smaller companies are often "low-hanging fruit" with weaker defenses and slower response times. Additionally, cybercriminals target small suppliers as entry points to larger customers' networks.
Every business has valuable data: customer information, employee records, intellectual property, financial details, login credentials. Even if your data seems mundane, hackers can:
In 80% of hacking cases, compromised credentials or passwords are to blame. Your "uninteresting" business email accounts are exactly what attackers want.
NIS2 introduces strict, time-bound reporting obligations known as the "24-72-30" framework. If you experience a "significant incident":
Basic facts about the incident, whether it appears malicious, potential cross-border impact
Initial assessment of severity, impact, and indicators of compromise
Detailed description, root cause analysis, remediation measures, cross-border effects
These deadlines run from when you "become aware" of the incident—not from when you finish investigating. This forces organizations to have detection and response capabilities that can identify incidents quickly.
Yes. NIS2 explicitly requires organizations to address cybersecurity risks in their supply chains. You must evaluate the vulnerabilities and security practices of direct suppliers and service providers. If a supplier is compromised and it affects your operations, you share the liability if you failed to assess their risk.
Practically, this means:
ENISA research shows that 38% of vulnerabilities stem from third parties—this isn't theoretical.
The NIS2 Applicability Assessment provides a fast, reliable first orientation on whether and how NIS2 applies to your organization—based on an outside-in view.
Instead of starting with internal assumptions, we assess your company as regulators and attackers would see it: sector signals, digital footprint, public dependencies, and exposed services.
Even if NIS2 does not apply to you, the assessment still delivers value: You receive our external security perspective on your most critical digital infrastructure at risk, the derived business-relevant risks, and a concrete set of recommendations and a checklist to improve your overall security posture.
Your IT team manages what they know about. Our assessment reveals what's visible from an attacker's perspective—the reconnaissance phase before any intrusion attempt:
Forgotten subdomains, exposed dev environments, undecommissioned test servers
Employee credentials circulating on dark web from previous breaches
Externally accessible systems running outdated software with known CVEs
Services and integrations creating indirect attack paths
In 80% of our assessments, we find assets the client's IT team didn't know were publicly accessible. The assessment also maps findings directly to NIS2 requirements—showing exactly which compliance gaps these technical findings represent.
A. We use the same methods attackers
use.
Threat actors rely on external reconnaissance to
identify weak points in a company’s attack
surface. We deliberately apply these techniques
first—so you see what they would see, before
they act.
B. We are a security company—security is built in.
Our platform follows security-by-design principles and is protected by industry-leading infrastructure. Trust is not claimed - it is engineered.
Get clarity on your NIS2 obligations with our free applicability assessment.