BLOG
What Is NIS2 Europe's New Cyber Baseline Explained
Published 30 July 2026
What Is NIS2: Europe’s New Cyber Baseline Explained
Illustration for: What Is NIS2, Europe’s New Cyber Baseline Explained
The most consequential thing about NIS2 is not what it asks organisations to do. Most of its security measures are hygiene that any competent programme already has. The consequential part is who it makes responsible, because for the first time an EU cyber law reaches past the IT department, past the CISO, and lands accountability on the management body itself, with personal consequences attached. If you sell into Europe, run infrastructure in Europe, or manage IT for anyone who does, this is the law that decides whether that accountability includes you.
Where NIS2 came from
The original NIS Directive of 2016 was the EU’s first attempt at a common cyber security baseline for critical services. It aged quickly. Its scope was narrow, member states interpreted it so differently that the same company could be regulated in one country and ignored next door, and the organisations attackers actually use as a way in, the IT providers holding admin credentials for hundreds of clients, were largely outside it.
NIS2, formally Directive (EU) 2022/2555, is the replacement. It was adopted in December 2022 and member states were required to transpose it into national law by 17 October 2024. Many missed the deadline, some by well over a year, and the European Commission has been pursuing infringement action against the stragglers. That matters practically. Because NIS2 is a directive rather than a regulation, it does not apply to you directly. Your actual obligations live in the national law of each member state where you operate, which means the baseline is common but the details, the regulators and the enforcement appetite are not.
Who it catches
NIS2 divides its scope into two tiers across roughly eighteen sectors. Essential entities include energy, transport, banking and financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space. Important entities include postal services, waste management, chemicals, food, manufacturing of critical products such as medical devices, digital providers like marketplaces and search engines, and research organisations.
Two tier diagram of NIS2 scope showing higher tier and second tier sectors above a size threshold bar
The two tiers in outline. The directive’s official terms are essential entities and important entities, and both face the same security duties, differing mainly in how they are supervised and fined.
The size cap does most of the sorting. As a general rule, an organisation in a listed sector is in scope if it has 50 or more staff or annual turnover above 10 million euros. Some entities are captured regardless of size, including DNS service providers, top-level domain registries and sole providers of a critical service in a member state.
The supply chain is deliberately inside the fence. The inclusion of ICT service management, meaning managed service providers and managed security service providers, is the scope change with the longest reach. An MSP with 60 staff serving EU clients is not a bystander to NIS2. It is a regulated entity in its own right, which is exactly what the drafters intended after years of watching supply chain compromises walk through the providers’ doors.
What it actually requires
Management owns it, personally. The management body must approve the cyber security risk measures, oversee their implementation, and undergo training so that ignorance is not a defence. Members can be held personally liable for gross failures, and in serious cases regulators can seek temporary bans on individuals holding management roles. This is the provision that moves budget conversations, and in my experience it does so faster than any technical mandate ever has.
Ten baseline measures. Article 21 lists the minimum measures every in-scope entity must take, on an all-hazards basis:
- Risk analysis and security policies for information systems.
- Incident handling, business continuity and crisis management.
- Supply chain security, including the security of relationships with direct suppliers.
- Security in acquisition, development and maintenance, including vulnerability handling.
- Policies to assess the effectiveness of the measures.
- Cyber hygiene, training, cryptography, access control, asset management, and multi-factor or continuous authentication where appropriate.
None of this is exotic. It reads like the contents page of ISO 27001 because it is meant to, and an organisation with a working ISMS will map to it without drama.
Incident reporting on fixed clocks. In-scope entities must give an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. I have covered those deadlines in detail in an earlier post in this series, and the short version is that they are too tight to improvise against mid-incident.
Registration. Entities must identify themselves to their national authorities, which sounds trivial until you realise it forces the scoping question out into the open. You cannot register if you have not decided whether you are in scope.
The teeth
Essential entities face fines of up to 10 million euros or 2 per cent of worldwide turnover, whichever is higher. Important entities face up to 7 million euros or 1.4 per cent. The supervisory posture differs more than the numbers. Essential entities can be supervised proactively, with audits, inspections and information requests arriving whether or not anything has gone wrong. Important entities are supervised after the fact, when an incident or a complaint draws attention. Neither tier gets to treat the measures as optional, but essential entities should expect to prove compliance on someone else’s schedule.
The honest limits
NIS2 deserves a fair hearing from its critics, and they have real points. The uneven transposition means “NIS2 compliance” is actually twenty-seven national flavours of compliance, with different registration portals, different incident forms and regulators of very different maturity. The directive can reward paperwork over security if a regulator measures policies rather than outcomes, a failure mode Europe knows well from early GDPR enforcement. And the size cap creates hard edges, because a 45-person supplier holding privileged access to essential entities is formally out of scope while a 55-person postal subcontractor is in. Scope by headcount is administrable, but it is not the same thing as scope by risk, and every supplier security clause I have seen written since 2024 quietly acknowledges that by pushing NIS2-shaped duties onto suppliers the directive itself does not touch.
What this means in the UK
NIS2 does not apply in the UK. British critical services still run on the 2018 NIS Regulations, and the government is part way through replacing them with the Cyber Security and Resilience Bill, which I have written about elsewhere in this series. But a UK organisation is far from insulated. If you offer services into the EU in a listed sector, NIS2 catches you directly and may require you to appoint an EU representative. If you supply an in-scope entity, its Article 21 supply chain duties arrive on your desk by contract, questionnaire and audit clause, with all of the obligation and none of the statutory recognition.
Deciding where you stand
Strip away the annexes and NIS2 asks one question most organisations have never formally answered. Are you, or anyone you depend on or supply, part of Europe’s critical fabric? That is not a question to discover in a customer questionnaire or, worse, in a regulator’s information request after an incident. Sit down with the sector list, the size cap and a map of where you actually operate, decide whether you are in scope in each member state, and write the reasoning down with a date and a signature. If you are in scope, the measures are largely things you should be doing anyway, and the accountability is now a fact rather than a preference. If you are out of scope, you will still meet NIS2 in your contracts, and it is far better to have decided your position deliberately than to inherit one by default.
Run your GRC programme in your own network.
RaptorGRC Community Edition is free — every module, offline licence activation, nothing phones home.
Register / Download Contact us