Back to Blog
security10 min read·May 20, 2026

NIS2 Compliance: What It Means for Your Infrastructure

DMK

Dr. Marcus Kessler

Chief Security Officer

/What Is NIS2?

The Network and Information Security Directive 2 (NIS2, Directive (EU) 2022/2555) is the EU's updated cybersecurity law, replacing the original 2016 NIS Directive. It substantially broadens the sectors in scope, raises the baseline of required security measures, and introduces personal liability for management.

NIS2 entered force in October 2024 and was to be transposed into national law by 17 October 2024. Many member states are now actively enforcing. Non-compliance can bring fines up to €10 million or 2% of global turnover for essential entities.

/Who Is in Scope?

NIS2 covers two tiers. "Essential" entities include energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, and public administration. "Important" entities include postal, waste, manufacturing, chemicals, food, and digital providers. The scope is far wider than the original directive.

/The Ten Risk-Management Measures

Article 21 requires in-scope organizations to implement appropriate and proportionate technical, operational, and organizational measures. The directive lists ten minimum elements that must be addressed.

  • Policies on risk analysis and information system security
  • Incident handling (detection, response, recovery)
  • Business continuity and crisis management
  • Supply chain security (auditing suppliers and service providers)
  • Secure acquisition and development of systems
  • Vulnerability handling and disclosure policies
  • Cybersecurity training and hygiene practices
  • Policies on assessing the effectiveness of measures
  • Basic cyber hygiene (encryption, MFA, asset management)
  • Human resources security, access control, and asset management

/Incident Reporting Obligations

NIS2 introduces a faster reporting cadence than GDPR. An in-scope entity must report a significant incident to its CSIRT within 24 hours of detection (early warning), an updated report within 72 hours, and a final report within one month. Management boards must approve and sign off on security measures.

NIS2 makes senior management personally accountable: directors can be held liable and temporarily prohibited from management duties for failures.

/NIS2 and GDPR: Where They Overlap

NIS2 and GDPR are complementary. A personal data breach often triggers both: GDPR Article 33 (72-hour authority notification) and NIS2 incident reporting (24-hour early warning). The technical measures required — encryption, MFA, vulnerability management — satisfy both Article 32 (GDPR) and Article 21 (NIS2). A unified security program addresses both at once.

Our audit framework maps your controls against both NIS2 Article 21 and GDPR Article 32 in a single assessment, so you produce evidence once for both regimes. Contact us to scope a NIS2 readiness review.

NIS2ComplianceInfrastructureRisk ManagementEU
NIS2 Compliance: What It Means for Your Infrastructure | SecureAudit Pro Blog | SecureAudit Pro