The NIS2 Directive – who does it cover, what does it require, and who is responsible?

The Network and Information Security Directive 2 (NIS2) is an EU piece of legislation that sets cyber security standards that apply across the European Union. The act is already in force as hard law in all member states. Not as a recommendation. Not as an industry standard of good practice. As an enforced requirement – with fines of up to €10 million and personal liability for the CEO for failure to implement.
What went wrong with NIS1?
The first NIS Directive of 2016 had one structural problem: member states implemented it at their own discretion. As a result, a company operating in Poland and Germany at the same time had to navigate two different legal regimes, which derived from the same source document, but differed dramatically in detail.
On top of that, a growing catalog of computer security incidents made it clear that NIS1 was not getting to where the threats actually hit – digital service providers, cloud operators and IT supply chains. Attacks on SolarWinds, Colonial Pipeline or hospitals across Europe happened in sectors that NIS1 treated marginally or ignored.
NIS2 draws lessons from this: it expands the list of regulated sectors, unifies requirements across all EU member states, and for the first time explicitly names the board of directors as the party responsible for an organization’s security status.
Who is covered by the NIS2 directive? Key and important entities
NIS2 divides regulated organizations into two categories: key entities and important entities (also called material entities). This distinction does not define what you must do; the obligations are very similar in both cases. Instead, it defines how intensively regulators will scrutinize you and how high the penalties are for violations.
Key players – critical sectors for the state and society
Key players operate in sectors whose failure means a real threat to the functioning of the state or the lives of citizens:
- Energy – operators of electricity, heat, gas networks;
- Transportation – airlines, railroads, seaports and inland ports, road infrastructure operators;
- Banking sector – credit institutions;
- Infrastructure of financial markets – exchanges, settlement systems;
- Health care – healthcare institutions, research laboratories, drug and medical device manufacturers;
- Water management – drinking water suppliers and wastewater treatment plant operators;
- Digital infrastructure – Internet traffic exchange points (IXPs), DNS registries, TLD domain name registries, cloud service providers, content delivery networks (CDNs), data centers;
- ICT service management – providers of managed services and managed security services;
- Space – operators of ground infrastructure supporting space services;
- Public administration – state and local government bodies;
- State security – entities of the defense and national security sector.
- Electronic communications entrepreneurs – operators of communications networks and services
Important (significant) entities – wider scope, lower level of supervision
Important entities include public and private entities from sectors such as:
- Postal and courier services
- Waste management
- Production, manufacture and distribution of chemicals
- Food distribution – food manufacturing factories and wholesalers
- Manufacturing – medical devices, electronic products, machinery, motor vehicles
- Digital service providers – online shopping platforms, search engines, social networks
- Research
Size criterion – large and medium-sized enterprises
As a general rule, NIS2 applies to large enterprises (more than 250 employees or a turnover of more than €50 million) and medium-sized enterprises (50-250 employees or a turnover of €10-50 million) operating in the listed sectors.
However, there are specific criteria triggering coverage regardless of size: when the entity is the only provider of the service in question in a member state, when its failure would have a direct impact on state security or public order, or when it belongs to a digital infrastructure – here NIS2 applies without an employment or revenue threshold.
What does the NIS2 directive mean in practice for your organization?
NIS2 imposes three types of responsibilities: implementation of risk management measures, incident reporting and management accountability. Each of these translates into specific actions.
Cyber security risk management requirements
The directive does not require perfection – it requires proportionality and documented diligence. The organization must demonstrate that it has identified risks, implemented adequate measures and keeps them up to date. This includes:
1. risk assessment and security policies
Regularly assess risks to networks and IT systems – not as a one-time implementation exercise, but as a living document that is updated each time the environment changes significantly. The assessment must include risks from its vendors and partners: compromising a third-party IT service provider is one of the most popular avenues of attack today.
2. incident handling
Cybersecurity incident response procedures, designated roles, defined internal and external communication channels. NIS2 specifies deadlines for reporting major incidents to relevant supervisory authorities – initial notification must be within 24 hours of detection.
3. continuity of operations
Business continuity plans include backup management, procedures for restoring systems after an attack, and crisis management. The key question: how long does it take your company to restore critical data after a ransomware incident? If you don’t know – the plan doesn’t exist in practice, only on paper.
4. supply chain security
One of the areas that organizations most often neglect. NIS2 requires that you assess the risks arising from supplier relationships and consider security requirements already in the process of acquiring new services and technologies. This means, among other things, security clauses in contracts, the right to audit suppliers and verification procedures.
5. security in the process of network acquisition and maintenance
Secure design principles applied throughout the systems lifecycle – from hardware and software procurement, network maintenance and administration, to decommissioning. Outdated software without vendor support is a de facto open gateway.
6. use of multi-component authentication
NIS2 lists multi-factor authentication (MFA) explicitly as one of the mandatory risk management measures. This applies to access to IT systems, not just external applications. Internal tools and remote access to infrastructure require the same approach.
7. regular cyber security training
Training is required for both employees and management. Not one-time, not at deployment – regular, refreshed as the threat landscape changes. Humans remain the main attack vector: phishing, social engineering and configuration errors are responsible for most real-world incidents.
Obligation to report incidents
Covered organizations are required to report cyber security incidents that have a significant impact on the continuity or quality of services. The deadlines are tough:
- 24 hours – preliminary warning to the relevant CSIRT or supervisory authority;
- 72 hours – full notification with preliminary assessment of the incident;
- 1 month – final report with analysis of causes and corrective actions taken.
Failure to report an incident or delay can be treated as a separate violation – regardless of whether the organization had proper procedures in other areas.
Personal liability of the board of directors – what does it mean in practice?
This is the element of NIS2 that is changing the conversation at the board level. Until now, cyber security has sometimes been delegated down the structure, treated as a technical issue rather than a strategic one. NIS2 removes this through a legal mechanism.
The directive explicitly states that the boards of directors of covered entities:
- Must approve cyber security risk management measures;
- Are responsible for their implementation and effectiveness;
- may be held personally liable for violations leading to serious incidents.
The implementation regulations of individual EU member states may provide for the possibility of temporarily suspending the president or a member of the board of directors from his or her managerial duties if the violations were flagrant or repeated.
In practice, this means that the CEO of a company covered by NIS2 should be able to answer the question, “What was the result of the last risk assessment and what corrective actions were taken?” The lack of answers is not the IT director’s problem, it’s the CEO’s problem.
Financial penalties – the numbers that prompt action
The NIS2 directive establishes the following ceilings for fines:
- Key entities – up to €10 million or 2% of total annual turnover (higher amount applies)
- Valid entities – up to EUR 7 million or 1.4% of total annual turnover
A major difference from the previous regime: financial penalties can be imposed for failure to implement enforced requirements – regardless of whether an incident occurred. The supervisory authority does not have to wait for an attack. An inspection is enough to show a lack of adequate procedures, policies or technical measures.
NIS2 and the national cyber security system in Poland
Poland is implementing the NIS2 Directive through an amendment to the Law on the National Cyber Security System (KSC). The law defines the role of individual institutions in Poland’s digital security ecosystem:
- CSIRT NASK, CSIRT GOV and CSIRT MON – three national computer security incident response teams that receive reports from various sectors;
- Ministers responsible for specific sectors – acting as supervisory bodies for entities operating in their area;
- Government Plenipotentiary for Cyber Security – Coordinating policy at the national level.
It is worth knowing that the Polish implementation goes further than the minimum requirements of the directive at several points – expanding, among other things, the scope of regulated entities. This means that simply checking the text of the NIS2 directive is not enough; national regulations are decisive.
Sectors covered by NIS2 – what does it mean for specific industries?
Energy and critical infrastructure
Operators in the energy sector – providers of electricity, gas, oil, distribution and transmission networks – are among the key players with the highest supervisory priority. The impact of an attack on the power grid goes far beyond the organization itself: hospitals, water treatment plants, transportation systems are all affected. That’s why security requirements in this sector are formulated so rigorously.
Health care institutions
The healthcare sector has been one of the main targets of ransomware attacks worldwide for several years. Healthcare institutions – hospitals, clinics, laboratories – have a specific risk profile: systems are often old, connected to more modern platforms, and IT system downtime has direct clinical consequences. NIS2 treats them as critical entities and requires them to implement the same measures as banks or energy operators.
Digital infrastructure and digital service providers
Cloud computing, CDNs, DNS services, data centers – a breach in this area has a multiplied scope: one attacked digital service provider means hundreds or thousands of organizations that lost access to their tools simultaneously. Hence, here NIS2 applies regardless of the size of the company – there is no employment threshold for entities in this category.
Financial sector and financial market infrastructure
Banks and financial market infrastructure have been subject to separate security regulations for years (including DORA for the financial sector). NIS2 harmonizes these requirements with an EU-wide cybersecurity standard, creating a consistent level of protection across the European Union.
Public administration
Public entities: government offices, ministries, local government units have become targets of attacks with clear geopolitical overtones in recent years. Leaks of citizens’ data, paralysis of public records, disinformation through hijacked communication channels – these are real scenarios that NIS2 seeks to prevent.
Electronic communication entrepreneurs
Telecommunications network operators and Internet service providers create the infrastructure through which all digital traffic flows. As electronic communications entrepreneurs, they have an obligation not only to secure their own systems, but also to provide secure and continuous access to services for service recipients.
Water management, space, food distribution
NIS2 also covers sectors whose presence on the list may come as a surprise. Water management – suppliers of drinking water and operators of wastewater treatment plants – is covered because a cyberattack on control systems could literally contaminate drinking water. Food manufacturing factories and food distribution operators are among the important players. Space (operators of terrestrial satellite infrastructure) was included in NIS2 after Viasat communications satellites were attacked hours before the invasion of Ukraine, depriving thousands of users in Europe of network access.
Technical and organizational measures – what specifically to implement?
NIS2 defines categories of risk management measures that organizations must implement. The word “proportionate” combined with “technical measures” is relevant here: the directive does not require the same from a small clinic as it does from a data center serving half of Poland’s e-commerce.
IT infrastructure security:
- Vulnerability management and regular software updates;
- Network segmentation and access control;
- Data encryption at rest and in transit;
- Multicomponent authentication on all systems with privileged access.
Monitoring and detection of threats:
- Security Information and Event Management (SIEM) systems;
- Continuous monitoring of networks and information systems for anomalies;
- Defined incident response procedures.
Backup and recovery:
- Regular, tested data backups;
- Disaster recovery plans with measured RTO and RPO targets;
- Procedures for restoring critical systems within a specified period of time.
Organizational and legal measures
In addition to technology, NIS2 requires building an organizational framework:
- Written information security and risk management policies;
- Incident management procedures with designated roles and escalation channels;
- Regular training for employees at all levels, including management;
- Mechanisms for sharing threat information with relevant authorities and sectoral partners;
- Security clauses and assessments in the process of acquiring new technologies and services.
How to conduct a NIS2 compliance assessment?
Step 1: Determine whether NIS2 applies to you and in what role
Check the sector and size of the organization. Keep in mind the exceptions to the size threshold – digital infrastructure, the only service providers in the country, entities of special importance to public safety. If in doubt, assuming the directive doesn’t apply to you is riskier than being overly cautious.
Step 2: Conduct a risk assessment
Identify assets, threats and vulnerabilities in your network and IT systems. Include risks associated with third-party vendors – any company that has access to your systems is a potential attack vector. A risk assessment is a document you will need to submit to the regulator upon request.
Step 3: Identify the gaps
Compare the results of the risk assessment with the NIS2 list of security requirements. Which areas are unsecured? Where is there a lack of documentation? Where procedures exist only in theory? The results of this exercise will show how far you are from compliance and what needs immediate attention.
Step 4: Implement the remediation plan with management involvement
Based on the gap analysis, determine priorities and timelines. It is essential to implement new processes, but it is also essential to involve the board of directors – not as figureheads approving documents, but as owners of the area who understand the security state of the organization and can be held accountable for it.
Step 5: Maintain and verify
NIS2 compliance is a state that must be actively maintained. Regular reviews of security policies, testing of emergency procedures, updating risk assessments after any significant change to the IT environment – these are all part of a covered organization’s standard operating cycle.
Compliance assessment and audits – what does oversight look like?
Supervisory authorities in the various member states have broad control powers over NIS2 entities. In the case of key entities, these are primarily:
- Security audits conducted ex officio or by accredited auditors;
- On-site and remote inspections;
- Demands for documentation and evidence of implementation;
- Infrastructure Vulnerability Scanning.
Key actors are subject to reactive supervision – authorities get involved after an incident or complaint, not on their own initiative. This doesn’t mean, however, that they can act without plans and procedures: if a review occurs, they must show the same due diligence as key players. The difference is when that review will occur – not whether it will.
What does the implementation of NIS2 look like with ITH?
Adapting an organization to NIS2 requirements should not mean working with multiple vendors, creating documentation on your own and coordinating several independent projects. At ITH, we handle NIS2 implementation in an end-to-end model – from compliance assessment to ongoing security monitoring.
Stage 1 Compliance Audit
We begin the process with a detailed analysis of the organization against the requirements of NIS2, ISO 27001 and the National Cyber Security System (NSC) Act.
As part of the audit:
- We assess the current level of compliance;
- We identify gaps and inconsistencies;
- We analyze processes, documentation and technical safeguards;
- We prepare a report with recommendations for action.
The result is a detailed report with a list of implementation priorities.
Stage 2 Documentation and Compliance
NIS2 requires not only adequate technical safeguards, but also documented cybersecurity management processes.
We help prepare, among other things:
- information security policy;
- incident handling procedures;
- Procedures for reporting incidents to competent authorities;
- risk management documentation;
- Business continuity and disaster recovery principles;
- Security requirements for suppliers and partners.
This allows the organization to demonstrate compliance not only during an audit, but also in the event of an actual incident.
Stage 3 Training and preparation of the organization
NIS2 imposes responsibilities not only on the IT department, but also on management and employees.
Therefore, the next step is training that includes:
- executives;
- employees of the organization;
- Those responsible for security and incident handling.
At the end of the process, the organization has training materials and confirmations of training delivery required during audits and inspections.
Stage 4 Closing the implementation and SOC 24/7
The final stage involves verification of the measures carried out and activation of mechanisms for continuous safety monitoring.
As part of this phase:
- conduct a closing audit;
- We confirm the implementation of documentation and procedures;
- We are preparing the organization for supervisory inspection;
- We are launching a Security Operations Center (SOC) service that operates 24/7/365.
As a result, NIS2 compliance does not end with documents, but is supported by continuous monitoring and incident response.
ITH – one partner responsible for the entire implementation
ITH combines audit, legal, organizational and technical competencies. Instead of working with several entities, the organization gets one partner responsible for the entire NIS2 compliance process – from the first audit to ongoing security maintenance.
Want to see what NIS2 implementation looks like in your organization?
Contact ITH experts and receive an initial compliance assessment and an action plan tailored to your company’s specific needs.
The most common questions about NIS2
- Does NIS2 apply to my company if I only operate in Poland?
Yes, as long as you operate in one of the covered sectors and meet the size criterion or specific criteria. NIS2 is an EU directive, but it applies through national implementation laws. In Poland, it is the Law on the National Cyber Security System. The mere question of the territorial scope of operations does not determine coverage.
- Does NIS2 apply to my suppliers?
As an NIS2 covered entity, you are responsible for the security of your supply chain. You need to assess the risks from your relationships with your suppliers, consider security requirements early in the procurement process, and have verification mechanisms in place. Your digital or managed IT service providers may themselves be subject to NIS2, and when choosing a partner, it’s worth checking.
- How long does it take to implement NIS2?
It depends on the baseline. Organizations with mature security processes mainly need documentation and adjustment of procedures – a few weeks to a few months. Companies starting from scratch face a horizon of 6-18 months for full implementation. That’s why it’s not worth postponing NIS2 implementation.
Summary
The NIS2 directive is not another document to be put off. Enforced requirements, personal liability of management and fines as high as €10 million create an environment where inaction is a more costly choice than implementation.
The good news is that the directive does not require perfection – it requires proportionate and documented diligence. An organization that can show a risk assessment conducted, risk management measures implemented, incident reporting procedures and regular training is in a very different position than one that has taken no action.
The first step is to find out if and in what role NIS2 applies to your organization. The next – risk assessment and gap analysis. Both of these steps can be done with external support, without committing a full team for months.
Want to see if NIS2 applies to your company?
Our experts will help assess the baseline and plan the next steps.
No general presentations: a concrete analysis of your infrastructure and a list of requirements that need to be met.













