Skip to main content
Back to Blog
May 25, 2026 by Arthur Mayoux GDPR & conformitate

Is your company interested in NIS2?

NIS2 has entered into force in October 2024.Thousands of European companies are now under new cybersecurity obligations, and most of them do not yet know.

You’ve probably heard of NIS2 without being sure it applies to you.Here’s the honest answer: Probably it is.

Or you are a U.S. company and someone has just sent you an email about compliance with NIS2. Your first instinct is to ignore it.

NIS2 is the updated EU Cybersecurity Directive. Its predecessor has covered several hundred critical operators across Europe.

Two questions to find out if you are in the scope

NIS2 is applied based on two criteria: your sector and your size.

Your sector. The Directive divides companies into two buckets:

  • Essential entities: energy, transport, banking, healthcare, water, digital infrastructure
  • Important entities: postal services, waste management, chemicals, food, manufacturing, digital suppliers

Your size. You’re in scope if:

  • You have more than 50 employees.
  • Your annual revenue exceeds €10 million

Type both boxes, sector and size, and you’re almost sure to cover.

You are a provider. you think you are safe.

This is where most SMEs are mistaken.

NIS2 does not just target companies directly. This requires each company within its scope to secure its supply chain. which means that your customers, if subject to NIS2, will push your obligation.

Concretely:

  • Your customers will ask for proof of your security position
  • Contracts may be rejected or suspended if you do not meet their requirements
  • Regulatory pressure flows along the chain, even at the smallest suppliers

If you work with hospitals, banks, energy companies or public infrastructure, wait for the question to land on your desk if it hasn’t happened yet.

CeNIS2 actually asks you to do

If you fall within the scope, the Directive imposes concrete obligations:

  • Reporting security incidents to the national authority within 24 hours
  • Put cybersecurity governance at board levelThis is not something you can delegate to a junior IT person.
  • Run regular risk analyses, documented, not theoretical
  • Ensure access control: strong authentication, supplier management, network segmentation
  • Check business continuity and recovery plans, on paper doesn’t count

What happens if you ignore it?

Penalties for key entities: up to 10 million euros or 2% of global revenue, whichever is higher.

For important entities: up to EUR 7 million or 1.4% of global revenue.

But the real kicker: directors can be held personally responsible.This is not a fine that lands on the company and disappears in the head.

Where to Start

If you have not yet assessed your exposure to NIS2, the first step is a gap analysis.Not a complete compliance program, but just an honest picture of where you are and what is missing.

Most companies who do this find the situation easier to manage than they feared.The problems are specific, remedies are prioritized, and the path is clearer than the regulation itself suggests.


Quick self-check:

  • Is my business on the list?
  • Do I have more than 50 employees or have an income of 10 million euros?
  • Does any of my clients enter subNIS2?
  • Do I have a documented incident response process?
  • Is cybersecurity a board-level topic in my company?

If you answered “no” or “not sure” to any of these, now is the right time to find out.


Scris de Arthur Mayoux
Arthur Mayoux write about operations, compliance programs and scaling security processes.
Portret Arthur Mayoux
ReceiveZebraByteanalytics and guidelines on cyber security, privacy and compliance.
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert