Skip to main content

NIS2 Compliance

NIS2
Ghidul complet pentru 2026

The European Union has just redesigned the cybersecurity map, and your organization could stand on a new territory.

NIS2 Compliance Guide 2026

WhenGDPR landed in 2018, it sent shock waves through every company dealing with EU citizens’ data. Now, the NIS2 Directive does the same for cybersecurity, but this time, the scope is wider, sanctions are tougher, and technical requirements are much more prescriptive. If you are a CTO, CISO or compliance officer at a company that operates or serves the EU market, this is not an optional reading.

Here is the uncomfortable truth: according to recent research by ITPro, a significant number of companies are already struggling to comply with the requirements of the NIS2.The deadline for transposition of the Directive in October 2024 has passed, Member States are actively implementing their national frameworks, and enforcement is intensified over the course of 2026.

Do you prefer a concise checklist that you can work section by section? NIS2 Compliance Check List for technology companies (2026 edition).


Understanding the central objective of the Directive

The Network and Information Security Directive (NIS2), published in the Official Journal of the European Union in December 2022, replaces the original 2016 NIS Directive with a dramatically expanded framework designed to address the changing threat landscape.

At its core,NIS2aims to a “high common level of cybersecurity” in all EU Member States.The European Commission has recognized that the voluntary approach and limited scope of the original directive have left critical gaps in Europe’s cyber resilience. EU Digital Strategy documentation The directive responds to the “increasing digitalization of the internal market” and to the “world of evolving cybersecurity threats” accelerated by the COVID-19 pandemic.

The original directive allowed too many variations between Member States, creating a patchwork of requirements that made compliance a nightmare for organizations operating across borders.


From NIS laNIS2 – What’s actually changed

The leap from NIS to NIS2 is not incremental – it is transformative. Understanding these changes is essential to expand your compliance efforts.

Expanded scope and coverage

The original NIS Directive covered about 7 sectors.NIS2 extends this to 18 sectors, bringing about 160,000+ entities under its umbrella.

Harmonized requirements

Where NIS has allowed Member States considerable flexibility, NIS2 shall prescribe specific security measures and deadlines for reporting incidents.

Stricter penalties

Administrative fines can now reach EUR 10 million or 2% of the global annual turnover for key entities, whichever is greater.

Personal accountability

Per the most significant change –NIS2 introduces personal responsibility to management bodies.

Supply chain focus

The Directive explicitly requires organisations to address cybersecurity risks in their supply chains, including direct suppliers and service providers.


The 18 Sectors Now Covered Under NIS2

NIS2 classifies covered entities into two groups, each with separate compliance obligations:

Essential Entities (11 sectors)

  • • Energy (electricity, oil, gas, hydrogen, district heating)
  • • Transport (air, rail, water, road)
  • • Banking and financial market infrastructures
  • • Health (healthcare providers, EU reference laboratories, R&D, pharmaceuticals, medical devices)
  • • Drinking water supply and distribution
  • • Wastewater management
  • • Digital infrastructure (IXPs, DNS providers, TLD registries, cloud computing, data centers, CDNs, trust service providers, electronic communications)
  • • ICT service management (B2B)
  • • Public administration (central and regional)
  • • Space

Important Entities (7 sectors)

  • • Postal and courier services
  • • Waste management
  • • Chemical manufacturing, production, and distribution
  • • Food production, processing, and distribution
  • • Manufacturing (medical devices, computers, electronics, machinery, motor vehicles)
  • • Digital providers (online marketplaces, search engines, social networks)
  • • Research organizations

In general, medium-sized enterprises (50+ employees or turnover of EUR 10 million) and large enterprises in these sectors fall within the scope.


NIS2 Compliance Requirements: What your organization needs to do

Understanding the requirementsNIS2means plunging into technical details.Article 21 of the directive sets out specific measures for managing cybersecurity risks that covered entities must implement.

Risk Management Measures (Article 21 Breakdown)

According to ENISA’s implementation guidelines, organisations must implement measures that are “adequate and proportionate” to their risk exposure.

Risk analysis and information system security policies

You need documented policies that cover the entire information security program.This includes risk assessment methodologies, asset inventories, and security governance frameworks.

2. Incident handling

Beyond having just an incident response plan,NIS2 requires tested procedures for detecting, analyzing, containing and recovering from security incidents.

Business Continuity and Crisis Management

This includes backup management, disaster recovery and crisis management procedures. Your organization needs to demonstrate that it can maintain critical functions during and after a cyber incident.

4. Supply chain security

You need to assess and manage cybersecurity risks from direct providers and service providers.

Security in the acquisition, development and maintenance of network and information systems

Secure development practices, vulnerability management and security testing must be incorporated into the SDLC.

Policies and procedures for evaluating the effectiveness of cybersecurity risk management

Regular audits, penetration tests and safety assessments are necessary to validate the effective operation of controls.

7. Basic cyber hygiene practices and cybersecurity training

All employees need security awareness training. Technical teams need role-specific training.

8. Cryptography and encryption policies

Where applicable, you need to implement rest and transit data encryption with documented key management procedures.

Security of human resources and access control

It covers background checks, access management, privileged access control and procedures for members, migrants and abandoned persons.

10. Multi-factor authentication and secured communications

MFA is explicitly required "where appropriate" along with secure voice, video and text communications within the organization.


Incident Reporting Obligations — The 24/72 Hour Rule

RequirementsNIS2 on incident reporting is among the most demanding operational elements.The Directive establishes a multi-stage reporting framework that requires substantial organizational preparation.

Early warning (24 hours)

Within 24 hours of being aware of a significant incident, you must send an early warning to the National Cyber Security Incident Response Team (CSIRT) or the competent authority.

Incident notification (72 hours)

Within 72 hours, you must provide an initial assessment, including the severity and impact of the incident, compromise indicators, where available, and any cross-border implications.

Intermediate report (upon request)

The competent authority may request updates on your incident management status.

Final report (one month)

Within one month of the incident notification or the end of the incident management, if later, you must submit a detailed report, including an analysis of the underlying causes, the mitigation measures applied and a cross-border impact assessment.

What constitutes a "significant incident"?

The Directive defines it as an incident that:

  • • has caused or is likely to cause serious operational disruption or financial loss;
  • • has affected or is likely to affect other natural or legal persons, causing substantial material or intangible damage;

Supply Chain Security Requirements

Supply chain provisions in NIS2 reflect the hard lessons learned from incidents such as SolarWinds and Kaseya.

Organizations must:

  • • Assess supplier security: Evaluation of cybersecurity practices of direct providers and service providers
  • • Contractual requirements: Include appropriate security clauses in supplier agreements
  • • Ongoing monitoring: Continuous monitoring of the supplier’s safety position, not only on boarding
  • • Coordinated vulnerability disclosure: Participate in and support vulnerability disclosure processes

Even if your organization is not directly covered by NIS2, you may face these requirements through your customers’ supply chain obligations.


Management Accountability and Personal Liability

Article 20 requires that “the governing bodies of key and significant entities approve measures to manage cybersecurity risks” and “monitor their implementation”.

Management bodies must:

  • • Approve cybersecurity risk-management measures
  • • Monitoring the implementation of these measures
  • • Undergo specific cybersecurity training
  • • Ensure staff receive regular training

The consequences of non-compliance are serious.Member States must ensure that competent authorities can personally hold management accountable for breaches.

This represents a fundamental change in how cybersecurity responsibilities are allocated within organizations. CTOs and CISOs can no longer treat compliance as a purely technical matter – it is now a matter of governance at the board level.


NIS2Compliance calendar and deadlines

Understanding the timetableNIS2is crucial for planning your compliance program.While the directive entered into force in January 2023, actual implementation work takes place at the national level.

  • • Member States were required to transposeNIS2into national law by October 2024
  • • The national measures began to apply to covered entities shortly thereafter.
  • • Between 2025 and 2026, national authorities will carry out registration, surveillance and enforcement activities.
  • • The European Commission will review the functioning of the Directive in October 2027.

NIS2Compliance Cost: What to Budget for

Let’s address the question that every CTO and CFO wants to answer: what will actually cost compliance with NIS2?The answer largely depends on the current security maturity, size and sector of your organization.

Distribution of costs according to the size of the company

Compliance costs vary dramatically depending on several key factors that organizations should carefully evaluate when budgeting:

Small-to-medium enterprises (50-250 employees)

  • • Key cost factors include policy development, implementation of technical controls and training programmes
  • • Organizations with existing security frameworks will see lower initial investments
  • • Availability of internal expertise versus dependence on external consultants has a significant cost impact
  • • Cloud-native companies often face lower infrastructure repair costs than those with traditional on-site systems

Mid-market companies (250-1,000 employees)

  • • Key cost factors include security tools, dedicated compliance staff and third-party assessments
  • • The complexity of your technology and the number of business units affect the scope
  • • Geographic distribution across multiple EU member states increases coordination costs
  • • Existing certifications, such as ISO27001 or SOC2, can significantly reduce the effort to overcome gaps

Large enterprises (1,000+ employees)

  • • The main cost factors include enterprise security platforms, compliance teams, external audits and supply chain management.
  • • The number and critical character of suppliers requiring evaluation dramatically affects supply chain security costs
  • • Regulatory classification as “essential” versus “significant” determines the intensity of supervision and associated costs
  • • M&A business and organizational complexity create additional integration challenges

Factors affecting costs across all sizes of the organization

  • • Current security maturity: Organizations already aligned with frameworks such as ISO27001 or NIST CSF will have significantly lower costs of fixing gaps
  • • Technical debt: Inherited systems that lack modern security capabilities require substantial investments to bring compliance
  • • Industry sector: Highly regulated sectors, such as health and finance, may already have overlapping controls, while less regulated sectors are experiencing faster growth.
  • • Internal expertise: Organizations with established security teams can manage more internal work, while others have to budget for managed consultants and services
  • • Tool consolidation: Companies with fragmented security tools face higher integration and management costs than those with consolidated platforms

These cost structures align with what we see in the comparable framework. SOC 2 compliance costs or ISO 27001 certification investments will recognize similar models, although the prescriptive requirements of NIS2 often push costs to a higher end of comparable frameworks.

Hidden Costs Most Organizations Miss

Beyond the obvious line elements, several hidden costs catch organizations out of the guard:

  • • Technical debt remediation: Many organizations find that their existing infrastructure cannot support the requirements of NIS2. inherited systems lacking MFA capabilities, nepatched software and inadequate logging create significant repair costs.
  • • Supply chain compliance: Organizations report spending 15-25% of their NIS2 budget on supply chain security activities.
  • • Incident response readiness: The ability to build a real response to incidents – including 24/7 monitoring, forensic capabilities and tested manuals – often exceeds initial estimates.
  • • Ongoing training: The training requirements of NIS2 extend beyond the unique awareness programmes. budget for continuing education, specialized training for technical teams and management-level education in cybersecurity.
  • • Opportunity cost: Compliance projects consume a significant range of IT and security teams. Factor in the cost of delayed projects and extended resources.

Why companies struggle to comply (and how to avoid their mistakes)

Recent research by ITPro paints a worrying picture: many organizations struggle to meet NIS2 requirements despite the extended timetable for implementation of the directive.

The Technical Debt Problem

Organizations facing compliance with NIS2 often discover:

  • • Insufficient logging and monitoring: Incident detection requires comprehensive visibility.Many organizations do not have adequate SIEM capabilities or centralized log management.
  • • Inadequate access controls: The requirements of the MFA Directive on privileged access management expose gaps in identity infrastructure.
  • • Undocumented systems: You can’t protect what you don’t know exists. gaps in the asset inventory make it impossible to assess the risks.

The solution is not just the acquisition of new tools – it is the systematic approach to technical liabilities while building compliant processes.

Resource Constraints in SMEs

Small and medium enterprises face particular challenges:

  • • Limited security expertise: Many SMEs do not have dedicated security staff, the fewer specialists in compliance
  • • Budget constraints: Competing priorities make it difficult to finance comprehensive compliance programmes
  • • Vendor overwhelm: The market for compliance tools is noisy, making it difficult to identify suitable solutions

Enterprise GRC platforms designed for Fortune 500 companies are not suitable for a SaaS company of 75 people.

Cross-Border Complexity Challenges

Organizations operating across multiple EU member states face additional complexity:

  • • Varying national requirements: Despite harmonization, member states have discretion in certain areas
  • • Multiple competent authorities: Understanding the authority that has jurisdiction - and their specific expectations - requires careful analysis
  • • Language barriers: Guidance documents and regulatory communications often appear first (or only) in local languages

How the platform simplifies your journeyNIS2

The platform manages the entire compliance process for you hands-off, combining dedicated expert guidance with powerful automated compliance software to your compliance faster and with less stress.

Here’s what’s included when you join the platform:

  • • Dedicated Compliance Expert Direct access to compliance experts whenever you need guidance.Stop guessing or looking for answers - your expert is just a message away.
  • • Onboarding Meeting An on-board meeting with your dedicated expert to understand the full context, technology and specific compliance needs from day one.
  • • Policies & Risk Assessment Stop starting from scratch or wondering if your policies meet the requirements of the directive.
  • • Implementation Support We will guide you through the implementation of the technical and organizational controls required by Article 21, ensuring that the security measures are appropriate and proportionate to your risk profile.
  • • Quarterly Follow-ups NIS2 needs continuous improvement – the platform ensures that you keep up with regulatory changes and evolving threats.
  • • Access to the Compliance Platform A centralized workspace for managing all compliance activities, with automatic sampling and audit-ready documentation, which keeps everything organized and accessible.

Ready to Tackle NIS2?

Book a meeting
ZebraByte

Framework-uri gestionate Managed frameworks

Can’t find the framework you are looking for?
Talk to us — we may be able to include it in the program.
Don’t see the framework you are looking for?
Reach out – it may already be supported in the program.

SOC 2 Type 1
ISO 27001
ISO 42001
CCPA
GDPR
ISO 27701
HIPAA
FERPA
CASA
SOC 2
Talk to an expert Talk to an expert