NIS2 compliance: what is actually required
A clear breakdown of NIS2 obligations for in-scope organisations, the management accountability it introduces, the reporting clock, and how to evidence security maturity over time.
By André Årnes·Cybersecurity Partner, White Label Consultancy
NIS2 widened both the range of in-scope organisations and the expectations placed on them. The directive is less about a fixed control list and more about demonstrable risk management, accountable governance, and timely incident reporting. If you are newly in scope, the instinct to look for "the checklist" is the wrong starting point.
Who is in scope
NIS2 covers "essential" and "important" entities across a broad set of sectors, energy, transport, banking, health, digital infrastructure, public administration, manufacturing of certain products, and more, generally above a size threshold. The expansion is significant: many organisations that were comfortably outside the original NIS directive now fall within NIS2, often via the supply-chain and digital-services provisions. The first task is therefore an honest scoping exercise, including whether you are caught as a supplier to an essential entity.
The core obligations
- Risk-management measures. A baseline set covering policies on risk, incident handling, business continuity and crisis management, supply-chain security, security in acquisition and development, vulnerability handling and disclosure, the use of cryptography, and access control.
- Incident reporting. A structured clock: an early warning within 24 hours of becoming aware of a significant incident, a fuller incident notification within 72 hours, and a final report within one month.
- Management accountability. Management bodies must approve the risk-management measures and oversee their implementation, and they can be held liable for failures. Training for management is an explicit expectation, not a nice-to-have.
- Supply-chain security. You are expected to account for the security posture of your suppliers and service providers, which makes supplier governance part of NIS2, not a separate exercise.
How to evidence it over time
NIS2 rewards a maturity model, not a binder. Pick a control framework, score where you are, set targets, and track movement. When an auditor or regulator asks, you want to show a trend and the evidence behind it, not produce a fresh scramble. "Our supply-chain security maturity moved from Level 2 to Level 3 over the year, here is what changed" is a far stronger position than a folder of policies with no evidence they operate.
Don't silo the incident clock
A significant security incident often has parallel obligations under the GDPR if personal data is involved, with its own 72-hour breach-notification clock. Running security incident handling and data breach notification from one incident record avoids missed clocks and the contradictory timelines that come from managing the same incident in two systems. The 24/72/30 NIS2 rhythm and the GDPR breach clock should be driven off one set of facts.
NIS2 is, at heart, an instruction to run security as a governed, evidenced, accountable discipline. The organisations that find it manageable are the ones already treating it that way; the checklist mindset is what makes it feel impossible.
See the maturity model, control evidence, supplier risk, and NIS2 mapping in Pritect.
