NIS2 (EU Directive 2022/2555) significantly widens the circle of companies subject to cybersecurity obligations compared to the previous NIS directive — it now covers mid-size and large companies across 18 sectors, from energy to digital services, and places personal accountability on management boards for risk oversight.
Quick Overview
What you’ll learn:
- Which companies are in scope of NIS2 and how to check if yours qualifies
- What risk management measures NIS2 requires you to implement
- How the incident reporting obligation works and within what deadlines
- What penalties apply for non-compliance
Who this article is for:
- Boards and executives at companies in NIS2-covered sectors
- Compliance and security teams
- IT teams responsible for implementing technical requirements
Reading time: 6 minutes
NIS2 compliance obligations for mid-size and large companies: who is in scope
NIS2 splits entities into two categories: essential entities (energy, transport, banking, financial market infrastructure, healthcare, water, digital infrastructure, public administration) and important entities (postal services, waste management, chemicals manufacturing, food, medical device and electronics manufacturing, digital services, research). In both categories the size threshold is generally mid-size and large enterprises — above 50 employees or €10 million annual turnover, though some entities fall in scope regardless of size due to the critical nature of the services they provide.
The NIS2 directive doesn’t apply directly on its own — it requires transposition into national law (in Poland, through amendments to the National Cybersecurity System Act, KSC). Under the directive’s own deadline, member states were required to transpose its provisions by 17 October 2024 — in practice, the transposition process in many EU countries, including Poland, has run past that deadline, which does not, however, exempt companies from the need to prepare for the incoming requirements.
What risk management measures NIS2 requires
NIS2 sets out a specific catalogue of minimum cybersecurity risk management measures that essential and important entities must implement:
| Area | Required measures |
|---|---|
| Risk management | Risk analysis and information system security policies |
| Incident handling | Procedures for detecting, responding to and reporting incidents |
| Business continuity | Backup management, disaster recovery, crisis management |
| Supply chain security | Security assessment of suppliers and service providers |
| Access control | Access control and asset management policies |
| Authentication | Multi-factor authentication (MFA) solutions where warranted |
| Training | Basic cyber hygiene practices and staff cybersecurity training |
A key change from the previous directive: NIS2 explicitly requires staff training as a formal element of the security measures catalogue, not merely a best-practice recommendation — which makes the training budget a compliance element, not just a team development investment.
The incident reporting obligation: deadlines you can’t move
NIS2 introduces a strict, three-stage timeline for reporting significant incidents to the competent CSIRT (Computer Security Incident Response Team): an early warning within 24 hours of detecting an incident, a full notification within 72 hours with an initial assessment of severity and impact, and a final report within one month of the notification, detailing the incident, its causes and the remediation measures taken.
These windows are markedly shorter than what many companies applied in practice before — which means having a tested, documented incident response procedure (not just a theoretical plan) becomes a precondition for meeting the requirements in real time.
Board accountability and penalties for non-compliance
NIS2 introduces an unprecedented element: personal accountability of board members for overseeing compliance with cybersecurity requirements, including the possibility of a temporary ban from management functions for serious violations. Boards must approve risk management measures and undergo cybersecurity training themselves — they can no longer delegate this responsibility solely to the IT department.
Financial penalties for violations reach, depending on entity category, up to €10,000,000 or 2% of total worldwide annual turnover for essential entities (whichever is higher), and up to €7,000,000 or 1.4% of turnover for important entities — a mechanism comparable to GDPR-style penalties, but dedicated specifically to cybersecurity compliance.
Read Also
- Employee Security Awareness: A Step-by-Step Training Programme — how to meet NIS2’s staff training requirement
- The NIS2 Directive - What Do Companies Need to Know and How to Prepare — a companion overview of NIS2 obligations
- AI Act and Team Competencies - How to Prepare Your Company — how NIS2 connects to other EU technology risk regulations
Develop Your Skills
Preparing your organisation for NIS2 compliance is best started with the training The NIS2 Directive in Practice: Preparing Your Organization. Check the programme and sign up to build your team’s skills with EITT experts.
FAQ
How do I know if my company is actually in scope of NIS2?
It depends on sector and size. NIS2 covers 18 sectors split into essential and important entities, with a threshold generally starting at 50 employees or €10 million turnover — but some entities fall in scope regardless of size due to the critical nature of their services, so it’s worth verifying your status individually.
How much time does a company have to report a significant security incident?
The process is three-staged: an early warning within 24 hours of detection, a full notification within 72 hours, and a final report within one month — these deadlines are considerably shorter than what many companies applied in practice before.
Can the board delegate all NIS2 responsibility to the IT department?
No. NIS2 introduces personal accountability for board members over compliance oversight, including the risk of a temporary ban from management functions for serious violations — the board must approve risk management measures and undergo its own cybersecurity training.
Is employee training formally required under NIS2?
Yes — unlike the previous directive, NIS2 explicitly lists basic cyber hygiene practices and cybersecurity training as part of the formal catalogue of risk management measures, not merely a best-practice recommendation.