NIS2 — Network & Information Security Directive

NIS2, out of the spreadsheet.

Essential and important entities. Supply-chain security obligations. 24-hour incident notification, transposed differently across 27 member states. The Agency keeps your NIS2 evidence trail current and your supply-chain visibility live.

What is NIS2?

NIS2 is the EU directive on measures for a high common level of cybersecurity across the Union. It entered into force on 16 January 2023, with member states required to transpose it into national law by 17 October 2024, and it replaces the original 2016 NIS Directive — widening both who is regulated and what they must do.

It divides entities into essential and important, across sectors including energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, ICT service management, public administration, space, postal services, waste, chemicals, food, manufacturing and digital providers. The split affects supervision — essential entities face proactive supervision, important entities largely reactive — and the maximum penalty, not the substance of what is required.

Because it is a directive rather than a regulation, the detail varies by member state, and transposition has run at very different speeds. A group operating across several countries faces one set of obligations and several national implementations of them.

The provision that matters most here is Article 21(2)(d): entities are responsible for the security of their direct suppliers and service providers. That makes supply chain security a legal obligation rather than good practice. Our full NIS2 explainer covers scope, the essential-versus-important test and the reporting deadlines in detail.

The numbers your team already knows.

NIS2 raised the stakes — wider scope, stricter supply-chain obligations, and member-state transpositions that move the goalposts country by country. Your evidence trail has to keep up.

27 states
EU member states, each transposing NIS2 with local nuances
Cross-border evidence reuse matters
24 hrs
Initial incident notification window
NIS2 Article 23
Article 21
Risk management and supply-chain security obligations
Continuous, evidence-backed

TARA, VANCE, REX — your NIS2 evidence layer.

Three of The Agency's leads cover NIS2 end-to-end: continuous gap analysis, regulator-formatted reporting per member state, and supply-chain monitoring that keeps Article 21 obligations evidenced.

TARA avatar
TARA
Compliance & Remediation

Article 21 supply-chain security, continuously evidenced. TARA assesses your supply-chain posture against NIS2 obligations on a rolling basis — and tracks remediation against the deadlines the directive expects.

What you get
  • Article 21 supply-chain security gap analysis
  • Member-state-aware control mapping
  • Treatment plans with deadlines and SLA tracking
VANCE avatar
VANCE
Regulatory Reporting

Incident reports formatted for the right regulator. VANCE generates NIS2 incident packs, board-pack summaries and cross-border evidence bundles — formatted for the supervisory authority actually reviewing them.

What you get
  • 24-hour and 72-hour incident reports composed
  • Cross-border evidence packages assembled automatically
  • Tamper-evident audit trail per output
REX avatar
REX
Supply-Chain Monitoring

Supply-chain visibility kept live, not point-in-time. REX maps your vendors, their vendors, and the breach signal from both — so Article 21 supply-chain security has actual evidence behind it.

What you get
  • Fourth-party discovery — supply-chain depth mapped
  • Continuous breach signal correlated against the chain
  • Material-change detection within the 24-hour window

Four shifts you'll feel across member states.

NIS2 stops being a sprint to the local transposition deadline and becomes a continuous evidence layer that adapts when each member state moves the goalposts.

Article 21 supply-chain security, evidenced

Supply-chain posture is mapped, scored and continuously evidenced — not asserted in a slide deck.

Incident notifications within the 24-hour window

REX detects material change continuously; VANCE drafts the notification; your team reviews and submits.

Sector-aware NIS2 mapping

Essential entity vs important entity, with the right evidence depth and reporting cadence per classification.

Cross-border evidence assembly compressed

One evidence layer feeds reports for every member state your operations touch — no re-assembly per regulator.

The brief format is the difference. We stopped getting lists of findings and started getting decisions. That's the bit that was missing.

SR
Head of Third-Party Risk
UK Tier 1 Bank

What NIS2 means in practice.

Scope, timing and the essential-versus-important split are covered on our NIS2 explainer. These are the questions that follow once you know you are in scope.

What are the penalties for NIS2 non-compliance?
For essential entities, administrative fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, up to €7 million or 1.4%, on the same whichever-is-higher basis. Because NIS2 is a directive rather than a regulation, these are floors that member states transpose into national law, so the enforcement posture you actually face depends on the regulator in each country you operate in.
Who is personally accountable under NIS2?
Management bodies — and this is the provision that changed the conversation at board level. Article 20 requires them to approve the cybersecurity risk-management measures, oversee their implementation, and undergo training, and it makes them liable for infringements. For essential entities, regulators may go further and temporarily bar an individual at chief-executive or legal-representative level from exercising managerial functions. Accountability is explicitly not delegable to the security team.
What risk-management measures does Article 21 require?
Ten categories, to be applied proportionately to the risk: risk-analysis and information-system security policies; incident handling; business continuity, backup and crisis management; supply chain security; security in acquiring, developing and maintaining systems, including vulnerability handling; policies to assess whether the measures are working; basic cyber hygiene and security training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication and secured communications. The supply chain item is the one that reaches third-party risk directly.
Does NIS2 work the same way in every member state?
No, and planning as though it does is a common mistake. NIS2 is a directive: each member state transposes it into national law, and they have diverged on registration mechanics, sector interpretation, reporting channels and supervisory intensity. Transposition has also run at different speeds, with several states past the October 2024 deadline. A group operating in multiple member states is dealing with one set of obligations and several national implementations of them.
How does RiskXchange help with NIS2 compliance?
Mainly against the supply chain limb of Article 21(2), which is where most of the third-party work sits. REX monitors supplier posture continuously rather than at onboarding. ARIA structures the evidence suppliers return and validates it against what the outside-in scans show. TARA assesses posture against the framework and drives remediation with deadlines attached. VANCE composes the reporting an auditor or regulator asks for. The measures that are internal to your own estate — cryptography, access control, staff training — remain yours to implement and evidence.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.