Skip to content
Updated: 5 min read

NIS2: Compliance Obligations for Mid-Size and Large Companies

What obligations does the NIS2 directive place on mid-size and large companies — who is in scope, what security measures are required, and what penalties apply for non-compliance.

Marcin Godula Author: Marcin Godula

NIS2 (EU Directive 2022/2555) significantly widens the circle of companies subject to cybersecurity obligations compared to the previous NIS directive — it now covers mid-size and large companies across 18 sectors, from energy to digital services, and places personal accountability on management boards for risk oversight.

Quick Overview

What you’ll learn:

  • Which companies are in scope of NIS2 and how to check if yours qualifies
  • What risk management measures NIS2 requires you to implement
  • How the incident reporting obligation works and within what deadlines
  • What penalties apply for non-compliance

Who this article is for:

  • Boards and executives at companies in NIS2-covered sectors
  • Compliance and security teams
  • IT teams responsible for implementing technical requirements

Reading time: 6 minutes

NIS2 compliance obligations for mid-size and large companies: who is in scope

NIS2 splits entities into two categories: essential entities (energy, transport, banking, financial market infrastructure, healthcare, water, digital infrastructure, public administration) and important entities (postal services, waste management, chemicals manufacturing, food, medical device and electronics manufacturing, digital services, research). In both categories the size threshold is generally mid-size and large enterprises — above 50 employees or €10 million annual turnover, though some entities fall in scope regardless of size due to the critical nature of the services they provide.

The NIS2 directive doesn’t apply directly on its own — it requires transposition into national law (in Poland, through amendments to the National Cybersecurity System Act, KSC). Under the directive’s own deadline, member states were required to transpose its provisions by 17 October 2024 — in practice, the transposition process in many EU countries, including Poland, has run past that deadline, which does not, however, exempt companies from the need to prepare for the incoming requirements.

What risk management measures NIS2 requires

NIS2 sets out a specific catalogue of minimum cybersecurity risk management measures that essential and important entities must implement:

AreaRequired measures
Risk managementRisk analysis and information system security policies
Incident handlingProcedures for detecting, responding to and reporting incidents
Business continuityBackup management, disaster recovery, crisis management
Supply chain securitySecurity assessment of suppliers and service providers
Access controlAccess control and asset management policies
AuthenticationMulti-factor authentication (MFA) solutions where warranted
TrainingBasic cyber hygiene practices and staff cybersecurity training

A key change from the previous directive: NIS2 explicitly requires staff training as a formal element of the security measures catalogue, not merely a best-practice recommendation — which makes the training budget a compliance element, not just a team development investment.

The incident reporting obligation: deadlines you can’t move

NIS2 introduces a strict, three-stage timeline for reporting significant incidents to the competent CSIRT (Computer Security Incident Response Team): an early warning within 24 hours of detecting an incident, a full notification within 72 hours with an initial assessment of severity and impact, and a final report within one month of the notification, detailing the incident, its causes and the remediation measures taken.

These windows are markedly shorter than what many companies applied in practice before — which means having a tested, documented incident response procedure (not just a theoretical plan) becomes a precondition for meeting the requirements in real time.

Board accountability and penalties for non-compliance

NIS2 introduces an unprecedented element: personal accountability of board members for overseeing compliance with cybersecurity requirements, including the possibility of a temporary ban from management functions for serious violations. Boards must approve risk management measures and undergo cybersecurity training themselves — they can no longer delegate this responsibility solely to the IT department.

Financial penalties for violations reach, depending on entity category, up to €10,000,000 or 2% of total worldwide annual turnover for essential entities (whichever is higher), and up to €7,000,000 or 1.4% of turnover for important entities — a mechanism comparable to GDPR-style penalties, but dedicated specifically to cybersecurity compliance.

Read Also

Develop Your Skills

Preparing your organisation for NIS2 compliance is best started with the training The NIS2 Directive in Practice: Preparing Your Organization. Check the programme and sign up to build your team’s skills with EITT experts.

FAQ

How do I know if my company is actually in scope of NIS2?

It depends on sector and size. NIS2 covers 18 sectors split into essential and important entities, with a threshold generally starting at 50 employees or €10 million turnover — but some entities fall in scope regardless of size due to the critical nature of their services, so it’s worth verifying your status individually.

How much time does a company have to report a significant security incident?

The process is three-staged: an early warning within 24 hours of detection, a full notification within 72 hours, and a final report within one month — these deadlines are considerably shorter than what many companies applied in practice before.

Can the board delegate all NIS2 responsibility to the IT department?

No. NIS2 introduces personal accountability for board members over compliance oversight, including the risk of a temporary ban from management functions for serious violations — the board must approve risk management measures and undergo its own cybersecurity training.

Is employee training formally required under NIS2?

Yes — unlike the previous directive, NIS2 explicitly lists basic cyber hygiene practices and cybersecurity training as part of the formal catalogue of risk management measures, not merely a best-practice recommendation.

Request a quote

Develop Your Competencies

Check out our training and workshop offerings.

Request Training
Call us +48 22 487 84 90