Get NIS2 ready
For essential and important entities in scope of the EU's network and information security directive
NIS2 (Directive (EU) 2022/2555) is the EU's expanded cyber security law for critical and important sectors, transposed into member-state law from October 2024. It dramatically widens who is regulated, makes management personally accountable for cyber risk measures, and backs it with supervisory powers and significant fines. If your organisation sells into or operates in the EU in a covered sector, "are we NIS2 compliant?" is now a question customers and regulators both ask.
Who is in scope
NIS2 covers "essential" and "important" entities across eighteen sectors - energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure and ICT service management, public administration and space; plus postal services, waste, chemicals, food, manufacturing (including medical devices and electronics), digital providers and research. As a rule of thumb, organisations with 50+ staff or over €10M turnover in these sectors are in, with some entities in regardless of size. UK organisations are caught through EU establishments or services offered into the EU - and the UK's own Cyber Security and Resilience Bill is set to bring similar duties home, so the preparation pays twice.
What NIS2 actually requires
Article 21 lists the minimum risk-management measures every in-scope entity must take, on an "all-hazards" basis:
- Policies on risk analysis and information system security;
- Incident handling - detection, response and the reporting pipeline below;
- Business continuity - backups, disaster recovery and crisis management;
- Supply chain security - including the security of your direct suppliers and service providers;
- Security in acquisition and development, including vulnerability handling and disclosure;
- Effectiveness assessment - policies and procedures to measure whether any of this works;
- Cyber hygiene and training - including for management, who must approve the measures and can be held liable;
- Cryptography, access control, asset management, MFA and secured communications where appropriate.
Incident reporting is on a strict clock: an early warning to your CSIRT or authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. That timeline is not survivable with an ad-hoc process.
The sensible order of work
- 1. Confirm scope and classification - which entity type, which member state(s), which supervisory authority.
- 2. Assess against Article 21 honestly, so the gap between paper and practice is visible to you before it's visible to a regulator.
- 3. Fix incident response first - the 24-hour clock makes it the sharpest edge.
- 4. Get the supply chain in view - a register of suppliers with security assessments is a NIS2 obligation, not good practice.
- 5. Put management in the loop, on the record - approval, training and regular reporting are explicit duties.
How Assura helps
Assura includes a guided NIS2 assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and every measure is scored with written reasoning:
- a scored readiness view across the Article 21 measures, with a prioritised gap list;
- an incident register with timelines that evidences your handling process;
- vendor risk questionnaires that build the supplier-security picture NIS2 expects;
- staff and management training attestations, recorded per person;
- board-ready reporting for the management accountability requirement;
- and cross-framework mapping, so NIS2 work pre-fills ISO 27001, DORA and Cyber Essentials.
Assura measures and evidences your programme; formal legal classification and reporting obligations stay with your counsel and authority. What we remove is the guesswork about where you actually stand.
Check your readiness with Assura
Related guides: DORA · ISO 27001 · Cyber Essentials