NIS2 — Directive (EU) 2022/2555

NIS2 and the suppliers you are now answerable for.

NIS2 is the EU directive that replaced the original NIS Directive and widened both who is regulated and what they must do. Its most under-read provision is Article 21(2)(d), which makes an entity responsible for the security of its direct suppliers and service providers. This page covers what NIS2 is, who falls in scope, what it requires, what it means for UK organisations, and the supply-chain obligations that turn a compliance exercise into a continuing operational commitment.

Last reviewed

What is NIS2?

NIS2 is Directive (EU) 2022/2555, adopted on 14 December 2022. It replaced the 2016 NIS Directive, whose weakness was inconsistency: member states interpreted scope so differently that the same kind of company could be regulated in one country and untouched in another.

NIS2 addresses that in four ways:

  • Wider scope. More sectors, and a size-based rule that captures organisations automatically rather than leaving national regulators to nominate them.
  • Named minimum measures. Article 21 sets out the risk-management measures entities must adopt, rather than requiring “appropriate” security in the abstract.
  • Hard reporting deadlines. A 24-hour early warning, measured in hours rather than left to national discretion.
  • Management accountability. Management bodies must approve and oversee the measures, and can be held personally liable.

It is a directive rather than a regulation, so it does not apply directly. Each member state transposes it into national law, and the transposition deadline was 17 October 2024. That is why NIS2 obligations differ in detail country by country while sharing a common floor — and why a group operating across several member states is dealing with several implementations of the same text.

NIS2 scope: who is actually covered

Scope is a function of three things: sector, size, and a set of exceptions.

NIS2 splits regulated organisations into essential entities (Annex I) and important entities (Annex II). Both must meet the same Article 21 requirements; what differs is supervision — essential entities face proactive supervision, important entities are supervised reactively, after evidence of a problem — and the level of fines.

Essential entities (Annex I)

Energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business to business), public administration and space.

Important entities (Annex II)

Postal and courier services, waste management, chemicals, food, manufacturing (including medical devices, computer, electronic and optical products, machinery and equipment, motor vehicles and other transport equipment), digital providers such as online marketplaces, search engines and social networking platforms, and research organisations.

The size rule

In general the directive applies to medium-sized and larger organisations in those sectors — broadly 50 or more staff, or annual turnover and balance sheet total above €10 million. But size is not the whole test: certain entities are in scope regardless of headcount, including some providers of public electronic communications networks, trust service providers, DNS service providers and TLD name registries, and sole providers of a critical service in a member state.

The practical consequence is that “we are too small” is a conclusion to check rather than assume, and that the entity-by-entity analysis has to be done per member state where a group has legal entities in several.

Our NIS2 scope checker walks the Article 2 and Article 3 tests in four questions, including the size-independent cases and the essential-versus-important split.

NIS2 and the UK

NIS2 does not apply in the UK. The UK left the EU before the directive was adopted and did not transpose it; the domestic successor to the 2018 NIS Regulations is the Cyber Security and Resilience Bill, which is a separate instrument on its own timetable. That is the accurate answer, and it is where most UK coverage stops — which is a mistake, because it is not the answer to the question UK organisations are actually asking. A UK company with an establishment in a member state can be in scope directly. Far more commonly, a UK company that supplies an EU essential or important entity inherits NIS2 obligations contractually: its customer is required by Article 21(2)(d) to manage the security of its direct suppliers, and the mechanism it has for doing that is your contract, your questionnaire and your evidence. In practice UK suppliers meet NIS2 through their customers, not through a regulator.

NIS2 requirements the Article 21 measures

Article 21(2) names the minimum measures. They are deliberately baseline rather than exhaustive — a floor, not a ceiling.

  • Risk analysis and information system security policies
    Documented policies, grounded in an actual assessment of risk.
  • Incident handling
    Detection, response and recovery processes, exercised rather than written.
  • Business continuity and crisis management
    Backup management, disaster recovery, and a crisis-management capability.
  • Supply chain security
    Security-related aspects of the relationship with each direct supplier and service provider. The obligation attaches to the relationship, not just to your own perimeter — see below.
  • Security in acquisition, development and maintenance
    Including vulnerability handling and disclosure across the systems you buy and build.
  • Policies to assess effectiveness
    Measuring whether the risk-management measures work, not merely that they exist.
  • Cyber hygiene and security training
    Basic practice, applied consistently, including at management level.
  • Cryptography and encryption
    Policies on the use of cryptography, and where appropriate encryption.
  • Human resources security, access control and asset management
    Who has access to what, on what basis, and what you own.
  • Multi-factor authentication and secured communications
    MFA or continuous authentication, secured voice, video and text, and secured emergency communications.

Article 21(2)(d): the supply chain duty the expensive one

One line in the directive creates more sustained work than the other nine measures combined.

Article 21(2)(d) requires measures covering “supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers”. Article 21(3) sharpens it: entities must take into account the vulnerabilities specific to each direct supplier and service provider, and the overall quality of the products and cybersecurity practices of those suppliers.

Read carefully, that language does three things.

  • It is per supplier, not portfolio-wide. “Each direct supplier” rules out a single generic policy applied uniformly. The assessment has to be specific enough to reflect what that supplier actually does for you.
  • It covers practices, not just products. “Cybersecurity practices” is an assessment of how a supplier operates, which cannot be answered by a certificate alone.
  • It is continuous by implication. A vulnerability is a live property. An annual questionnaire describes one day and says nothing about the 364 that follow.

This is where NIS2 programmes tend to stall. The measures that apply to your own estate are bounded — you know what you own. Supplier obligations scale with the number of suppliers, and for most in-scope organisations that is hundreds of relationships, each needing an assessment specific to it and a view that stays current between assessments. Doing that with a questionnaire cycle and a spreadsheet is where the headcount goes.

Incident reporting deadlines

Article 23 sets a staged timetable for significant incidents. The clock starts when you become aware of the incident, not when you finish investigating it.

StageDeadlineWhat it must contain
Early warning24 hoursNotice that a significant incident has occurred, whether it may have been unlawful or malicious, and whether it could have cross-border impact.
Incident notification72 hoursAn update on the early warning, with an initial assessment of severity, impact and indicators of compromise where available.
Final reportOne monthA detailed description, the type of threat or root cause, mitigation applied, and any cross-border impact.

Notification goes to the relevant national authority or CSIRT. A 24-hour early warning is short enough that it has to be a rehearsed process rather than a decision made under pressure — and if the incident originates at a supplier, you are dependent on that supplier telling you in time to meet a deadline that is yours, not theirs.

Penalties and management liability

Article 34 requires member states to provide for administrative fines up to at least these levels — whichever is higher, the amount or the percentage.

€10m / 2%
Essential entities
Or 2% of total worldwide annual turnover for the preceding financial year
€7m / 1.4%
Important entities
Or 1.4% of total worldwide annual turnover for the preceding financial year
Personal
Management liability
Management bodies must approve and oversee the measures, and can be held liable

A NIS2 checklist start here

Not a compliance guarantee — a sequence that establishes whether you have a problem and how large it is.

  1. Determine scope, entity by entity and state by state
    Check each legal entity against the Annex I and Annex II sectors and the size thresholds, in each member state where it operates. Record the reasoning, not just the conclusion — you will be asked to justify it.
  2. Identify which national transposition applies
    The directive is the floor; the obligation that binds you is national law, and implementations differ in detail, deadlines and regulator.
  3. Gap-assess against the ten Article 21 measures
    Assess what exists, what is documented, and what is evidenced. Those are three different states and only the third survives supervision.
  4. Build the direct-supplier register
    List every direct supplier and service provider, what each one accesses or processes, and how critical it is to your service. Most organisations discover at this step that no single authoritative list exists.
  5. Assess each supplier specifically
    Per-supplier, covering their vulnerabilities and cybersecurity practices — not one questionnaire sent to everyone. Prioritise by what the supplier can reach.
  6. Put the 24-hour reporting process in place and rehearse it
    Including how you learn about an incident that starts at a supplier, which is the path most likely to breach the deadline.
  7. Get management sign-off, in writing
    The management body has to approve and oversee the measures. Minute it, because personal liability makes the record of who approved what a material document.

NIS2, answered.

Does NIS2 apply in the UK?
Not directly. The UK did not transpose NIS2; its domestic successor to the 2018 NIS Regulations is the Cyber Security and Resilience Bill. UK organisations are affected in two ways nonetheless: an establishment in a member state can bring you into scope directly, and supplying an EU essential or important entity means your customer’s Article 21(2)(d) obligations reach you through your contract.
What is the difference between essential and important entities?
The same Article 21 requirements apply to both. Essential entities are supervised proactively and face fines of up to at least €10 million or 2% of worldwide annual turnover; important entities are supervised reactively, after evidence of non-compliance, with fines up to at least €7 million or 1.4%.
When did NIS2 come into force?
The directive was adopted on 14 December 2022 and member states had to transpose it into national law by 17 October 2024. Because it is a directive, the instrument that actually binds you is your member state’s transposing law.
What does NIS2 require for supply chain security?
Article 21(2)(d) requires measures covering the security-related aspects of the relationship with each direct supplier and service provider, and Article 21(3) requires you to account for the vulnerabilities specific to each of them and the overall quality of their products and cybersecurity practices. The obligation is per supplier, covers practices as well as products, and does not lapse between assessments.
How quickly must an incident be reported under NIS2?
An early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, and a final report within one month.
Is NIS2 the same as DORA?
No. DORA is a regulation applying to EU financial entities and their critical ICT third-party providers, and it applies directly without transposition. NIS2 is a directive covering a much broader set of sectors. A financial entity can be subject to both, in which case DORA generally takes precedence as the more specific instrument. See our DORA compliance page for that side.
Are small companies exempt from NIS2?
Generally the directive applies to medium-sized and larger organisations in the listed sectors, but the size rule has exceptions. Certain providers are in scope regardless of size, including some public electronic communications providers, trust service providers, DNS service providers, TLD name registries, and any entity that is the sole provider of a critical service in a member state.

Article 21(2)(d) says each direct supplier.

Book a 30-minute call and we will show you a per-supplier NIS2 evidence trail on your own vendors — assessed, scored and kept current between questionnaires.