Frequently Asked Questions

Everything You Need to Know About NIS2 Compliance

Clear answers to the most common questions from European SMEs about NIS2 requirements, cybersecurity obligations, and how to get started.

Understanding NIS2

NIS2 (Network and Information Security Directive 2) is the EU's updated cybersecurity law, significantly expanding who must comply and introducing personal liability for management. It affects approximately 350,000 organizations across the EU—including many mid-sized companies that never considered themselves "cybersecurity-relevant."

The key changes from the original directive:

  • Expanded scope to 18 sectors (up from 7)
  • Mandatory incident reporting within 24 hours
  • Board-level accountability for cybersecurity
  • Fines up to €10 million or 2% of global turnover
  • Personal liability for executives who fail to ensure compliance

NIS2 generally applies if you operate in a covered sector AND meet size thresholds: 50+ employees OR €10M+ annual revenue. The 18 sectors covered by NIS2 are: energy; transport; banking; financial market infrastructures; health; drinking water; wastewater; digital infrastructure; ICT service management (B2B); public administration; space; postal and courier services; waste management; chemicals; food production, processing and distribution; manufacturing; digital providers; and research organisations.

But here's the catch: even if you're below these thresholds, you may still be affected:

  • If you're the sole provider of a critical service
  • If your disruption could affect public safety
  • If you supply to companies that ARE in scope—their compliance requirements will flow down to you contractually

Many companies outside NIS2's direct scope are already receiving security questionnaires from their larger customers.

Not sure if you're in scope?

Our free NIS2 applicability report tells you in minutes whether the directive applies to your organization.

Check Your Status →

The EU deadline for member states to transpose NIS2 into national law was October 2024. Some countries have grace periods for registration and compliance, but the core requirements are already defined. Track the implementation of the NIS2 Directive across all EU Member States with our NIS2 Legislation Status tracker.

The reality: 95% of what NIS2 requires is already known. Waiting for "final" national guidance means falling behind. Organizations that start gap assessments now will be positioned to comply; those who wait will face resource constraints as specialists become scarce closer to enforcement dates.

Management & Liability

This is the most significant shift in NIS2: cybersecurity is now explicitly a board-level responsibility, not something that can be delegated to IT. Under NIS2, management bodies must:

  • Approve cybersecurity risk management measures
  • Oversee their implementation
  • Undergo cybersecurity training themselves
  • Take accountability for compliance failures

The consequences are real: in cases of non-compliance, executives can face temporary bans from management positions. Some national implementations (like Poland) include fines of up to 600% of salary for negligent managers. This isn't theoretical—NIS2 makes clear that failing to ensure cybersecurity constitutes a breach of fiduciary duty.

No, and this misconception is precisely what NIS2 targets. IT and cybersecurity are related but fundamentally different disciplines—like general medicine and cardiology. Your IT team manages infrastructure; cybersecurity requires specialized threat intelligence, incident response planning, and risk assessment that most internal IT teams aren't resourced to provide.

More importantly, NIS2 explicitly requires management oversight. You cannot delegate this responsibility to IT and consider yourself compliant. Boards must understand the risks, approve the measures, and demonstrate they're actively engaged—not just signing off on whatever IT recommends.

Common Myths

This is the most dangerous myth in cybersecurity. The data tells a different story:

43% of all cyberattacks target small businesses
73% of German SMEs experienced an attack in 2023
45% of data breaches involve small businesses

Why? Because attackers use automated tools that scan the internet for vulnerable systems—they don't discriminate by company size. Smaller companies are often "low-hanging fruit" with weaker defenses and slower response times. Additionally, cybercriminals target small suppliers as entry points to larger customers' networks.

Every business has valuable data: customer information, employee records, intellectual property, financial details, login credentials. Even if your data seems mundane, hackers can:

  • Encrypt your systems and demand ransom (average SME pays €12,000-50,000)
  • Steal credentials to attack your customers or partners
  • Use your systems for cryptocurrency mining
  • Exploit your network access to reach larger targets in your supply chain
  • Sell employee and customer data on dark web markets

In 80% of hacking cases, compromised credentials or passwords are to blame. Your "uninteresting" business email accounts are exactly what attackers want.

Compliance Requirements

NIS2 introduces strict, time-bound reporting obligations known as the "24-72-30" framework. If you experience a "significant incident":

24h
Early Warning

Basic facts about the incident, whether it appears malicious, potential cross-border impact

72h
Full Incident Notification

Initial assessment of severity, impact, and indicators of compromise

30 days
Final Report

Detailed description, root cause analysis, remediation measures, cross-border effects

These deadlines run from when you "become aware" of the incident—not from when you finish investigating. This forces organizations to have detection and response capabilities that can identify incidents quickly.

Yes. NIS2 explicitly requires organizations to address cybersecurity risks in their supply chains. You must evaluate the vulnerabilities and security practices of direct suppliers and service providers. If a supplier is compromised and it affects your operations, you share the liability if you failed to assess their risk.

Practically, this means:

  • Updating contracts to include cybersecurity obligations
  • Requiring certifications (like ISO 27001) from critical vendors
  • Conducting regular security assessments of suppliers
  • Having incident notification requirements that cover supply chain events

ENISA research shows that 38% of vulnerabilities stem from third parties—this isn't theoretical.

Our Services

The NIS2 Applicability Assessment provides a fast, reliable first orientation on whether and how NIS2 applies to your organization—based on an outside-in view.

Instead of starting with internal assumptions, we assess your company as regulators and attackers would see it: sector signals, digital footprint, public dependencies, and exposed services.

  • Clear indication whether NIS2 is applicable or likely applicable
  • Early identification of regulatory exposure
  • A structured starting point before investing in audits or consulting
  • Results mapped directly to NIS2 obligations

Even if NIS2 does not apply to you, the assessment still delivers value: You receive our external security perspective on your most critical digital infrastructure at risk, the derived business-relevant risks, and a concrete set of recommendations and a checklist to improve your overall security posture.

Your IT team manages what they know about. Our assessment reveals what's visible from an attacker's perspective—the reconnaissance phase before any intrusion attempt:

Shadow IT

Forgotten subdomains, exposed dev environments, undecommissioned test servers

Leaked Credentials

Employee credentials circulating on dark web from previous breaches

Vulnerable Services

Externally accessible systems running outdated software with known CVEs

Third-Party Exposure

Services and integrations creating indirect attack paths

In 80% of our assessments, we find assets the client's IT team didn't know were publicly accessible. The assessment also maps findings directly to NIS2 requirements—showing exactly which compliance gaps these technical findings represent.

A. We use the same methods attackers use.
Threat actors rely on external reconnaissance to identify weak points in a company’s attack surface. We deliberately apply these techniques first—so you see what they would see, before they act.

B. We are a security company—security is built in.

  • Passwordless authentication with MFA and strict access controls
  • Encryption in transit and at rest
  • Unique identifiers bound to you and your company
  • No shared access, only you can view your results
  • Minimal data collection, purpose-limited by design
  • Enterprise-grade protection using trusted security partners such as Cloudflare to safeguard our platform and your data

Our platform follows security-by-design principles and is protected by industry-leading infrastructure. Trust is not claimed - it is engineered.

Still Have Questions?

Get clarity on your NIS2 obligations with our free applicability assessment.