Guide

Get NIS2 ready

For essential and important entities in scope of the EU's network and information security directive

NIS2 (Directive (EU) 2022/2555) is the EU's expanded cyber security law for critical and important sectors, transposed into member-state law from October 2024. It dramatically widens who is regulated, makes management personally accountable for cyber risk measures, and backs it with supervisory powers and significant fines. If your organisation sells into or operates in the EU in a covered sector, "are we NIS2 compliant?" is now a question customers and regulators both ask.

Who is in scope

NIS2 covers "essential" and "important" entities across eighteen sectors - energy, transport, banking and financial market infrastructure, health, drinking and waste water, digital infrastructure and ICT service management, public administration and space; plus postal services, waste, chemicals, food, manufacturing (including medical devices and electronics), digital providers and research. As a rule of thumb, organisations with 50+ staff or over €10M turnover in these sectors are in, with some entities in regardless of size. UK organisations are caught through EU establishments or services offered into the EU - and the UK's own Cyber Security and Resilience Bill is set to bring similar duties home, so the preparation pays twice.

What NIS2 actually requires

Article 21 lists the minimum risk-management measures every in-scope entity must take, on an "all-hazards" basis:

Incident reporting is on a strict clock: an early warning to your CSIRT or authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. That timeline is not survivable with an ad-hoc process.

The sensible order of work

How Assura helps

Assura includes a guided NIS2 assessment among its 20 frameworks. You answer in plain English, attach evidence as you go, and every measure is scored with written reasoning:

Assura measures and evidences your programme; formal legal classification and reporting obligations stay with your counsel and authority. What we remove is the guesswork about where you actually stand.

Check your readiness with Assura

Related guides: DORA · ISO 27001 · Cyber Essentials