Securance logo

NIS2 explained

NIS2 explained: what European organisations need to know in 2026

Emma dau n 4i TY1 Km DE unsplash

If you've been keeping an eye on EU cybersecurity legislation, NIS2 has probably come up more than once over the past year. And with good reason. Directive (EU) 2022/2555 — commonly known as NIS2 — is now the most significant piece of cybersecurity law in the European Union, replacing the original NIS Directive that's been in place since 2016. The transposition deadline for EU Member States was 17 October 2024, and the first compliance audit deadline for in-scope entities is set for 30 June 2026.

So if you're a compliance officer or CISO at a SaaS or tech company operating in Europe, now is the time to make sure everything is in order.

 

Who actually needs to comply?

One of the biggest changes NIS2 brings is the sheer scale of its scope. The original directive covered around 1,000 organisations across 7 sectors. NIS2 potentially captures over 100,000 entities across 18 sectors.

The directive splits in-scope organisations into two categories:

  • Essential entities — organisations in high-criticality sectors like energy, transport, banking, health, digital infrastructure, and public administration. These are typically larger organisations with 250+ employees or over €50 million in annual turnover.
  • Important entities — organisations in other critical sectors including digital providers (online marketplaces, cloud services, SaaS platforms), manufacturing, postal services, and research. The threshold here drops to 50+ employees or €10 million in turnover.

For SaaS and tech companies, this is where it gets particularly relevant. If your platform provides cloud computing, managed IT services, or digital infrastructure to European customers, you're almost certainly in scope — even if your headquarters are outside the EU. And even smaller vendors that serve in-scope Essential or Important Entities may find themselves pulled into compliance through supply chain obligations.

Not sure whether your organisation falls under the directive? Securance's dedicated NIS2 advisory service is a good starting point to map your position and plan your next steps.

 

The four pillars of NIS2 compliance

NIS2 organises its obligations around four core areas. Getting comfortable with these will help you understand where your current controls stand and where the gaps might be.

 

Risk management and security measures

Article 21 of the directive requires organisations to implement at least 10 specific cybersecurity measures. These include policies on risk analysis, incident handling, business continuity, supply chain security, cryptography, access control, and multi-factor authentication. It's a broad set of requirements, and for many organisations, it means formalising practices that may have been ad hoc up to now.

If your organisation already holds ISO 27001 certification, you'll find significant overlap — the benefits of ISO 27001 extend directly into NIS2 readiness. The two frameworks share a common DNA around risk-based security management.

 

Incident reporting (the 24-72-30 rule)

This is where a lot of organisations feel the pressure. Under Article 23, when a significant incident occurs, you're required to follow a three-stage reporting process:

  • 24 hours — submit an early warning to the relevant national CSIRT or competent authority
  • 72 hours — submit a full incident notification with an initial assessment
  • 1 month — submit a detailed final report

Missing these windows isn't just a compliance failure. It's the kind of thing that attracts regulatory attention. Having your operational risk management processes documented and tested in advance makes the difference between a controlled response and a chaotic scramble.

 

Executive accountability

Here's something that tends to grab the attention of boards very quickly: under Article 20, management bodies are personally responsible for approving and overseeing cybersecurity measures. Non-compliance can lead to personal liability and even temporary bans on holding managerial positions.

This isn't a box-ticking exercise that sits with the IT team. NIS2 makes cybersecurity governance a board-level responsibility. Executives are also required to undergo cybersecurity training. That shift in accountability is worth communicating clearly to your leadership team if you haven't already.

 

Supply chain security

NIS2 places a notable emphasis on the security of suppliers and third-party service providers. Organisations must assess and manage the cybersecurity risks posed by their supply chains — and that means your own contracts and procurement practices may need reviewing. If your organisation is a vendor to in-scope entities, don't be surprised if customers start asking for evidence of your own compliance posture as part of due diligence.

Understanding cybersecurity threats in supply chain contexts is increasingly important as attackers target smaller vendors to reach larger organisations further up the chain.

 

What are the penalties for non-compliance?

The financial consequences of falling short are significant. Fines are tiered based on entity classification:

  • Essential entities: up to €10 million or 2% of global annual turnover, whichever is higher
  • Important entities: up to €7 million or 1.4% of global annual turnover, whichever is higher

Beyond fines, national supervisory authorities have broad enforcement powers — including the ability to conduct security audits, demand access to information, and impose temporary operational restrictions. The European Commission had already opened infringement procedures against 23 Member States for failing to fully transpose the directive on time, signalling that enforcement intent is serious.

 

What's changing in 2026?

It's worth noting that NIS2 isn't completely static. In March 2026, the European Commission announced proposed amendments through the EU Digital Omnibus package. The proposals don't change who is in scope or the core security obligations — instead, they focus on introducing a single EU reporting portal for incident notifications to reduce duplicate submissions across national authorities and parallel regimes like GDPR. The substantive deadlines and legal thresholds in Article 23 remain unchanged.

For compliance officers, the practical message is: your core programme should focus on the existing requirements, while keeping an eye on how the portal implementation develops at the national level.

This also connects neatly with the broader EU regulatory picture. If you're working through ISO 27001, SOC 2, and NIS2 as part of a unified compliance strategy, there's real efficiency to be found in aligning them rather than treating each as a separate workstream.

 

Getting your programme in shape

If your NIS2 readiness work hasn't started yet, the 30 June 2026 audit deadline doesn't leave a great deal of runway. A structured approach helps. Start with a clear gap assessment — understanding where your current controls sit relative to the 10 Article 21 measures — and work outward from there.

Regular cybersecurity risk assessments aligned with NIS2 give you the documentation trail you'll need when supervisors come asking. Technical testing — including penetration testing and vulnerability scanning — should be part of your ongoing cadence, not a one-off exercise.

The good news is that NIS2 compliance, done properly, doesn't just tick a regulatory box. It gives your organisation a stronger security posture, clearer governance, and something concrete to point to when clients and partners ask about your approach to cybersecurity. That's a genuine competitive asset — and one that Securance experts has been helping European SaaS and tech organisations build for over 25 years.

If you'd like to understand where your organisation stands today, speak to the Securance team. We're happy to help you map the path to NIS2 compliance in a way that fits your structure and timeline.