Compliance

NIS2: What the Directive Requires and Who It Affects

The NIS2 Directive raises the cybersecurity bar for thousands of European organisations. We explain what it is, who it affects by sector and size, what obligations it imposes, the incident reporting deadlines and how a compliant infrastructure provider helps you meet them.

business EasyDataHost calendar_today September 9, 2026 schedule 9 min read

Cybersecurity has stopped being a matter for the IT department alone and become a legal obligation with direct consequences for company management. The NIS2 Directive (Directive EU 2022/2555) is the European rule that makes that shift real: it significantly raises the security requirements for the critical and essential infrastructure of the European Union, and vastly expands the number of organisations obliged to meet them.

Many companies discover they fall under NIS2 without having anticipated it, simply because they belong to a regulated sector or because they provide services to an essential entity within the supply chain. Understanding what the directive requires, who it affects and how to prepare is now a governance question, not just a technical one.

In this article we review what NIS2 is, the sectors and company sizes that fall within its scope, the technical and organisational obligations it imposes, the incident reporting deadlines, the new management liability regime and how working with a compliant infrastructure provider (certified in ISO 27001 and ENS) makes compliance easier.

What the NIS2 Directive Is

NIS2 is the short name for the "Network and Information Security Directive 2", formally Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022. Its aim is to achieve a high and consistent level of cybersecurity across the whole territory of the Union, reducing the fragmentation caused by its predecessor.

NIS2 replaces the original NIS Directive of 2016 (the first European cybersecurity rule for infrastructure), which had proved insufficient: it covered few sectors, left too much room for interpretation to each Member State and lacked a robust enforcement regime. The new directive broadens the sectors covered, unifies the criteria for application, strengthens the risk management and reporting obligations, and introduces serious financial penalties and personal liability for directors.

Because it is a directive and not a regulation, NIS2 does not apply directly: each Member State must transpose it into its national law. The transposition deadline set by the EU was 17 October 2024, from which point the obligations become enforceable through each country's legislation. This means the specific details (competent authorities, procedures, exact fine amounts) depend on the national law transposing the directive in each State.

Who It Affects: Sectors and Size

NIS2 distinguishes two categories of organisation within its scope: essential entities and important entities. The difference lies less in the obligations (which are very similar) than in the supervision regime and in the maximum amount of the penalties, which is more severe for essential entities.

Membership of one or the other category is determined by combining two criteria: the sector of activity and the size of the organisation. As for sectors, the directive covers a much broader range than its predecessor:

  • check_circle Sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure (data centers, DNS, clouds, communications networks), B2B ICT service management, public administration and space.
  • check_circle Other critical sectors: postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing (medical devices, electronics, machinery, vehicles), digital providers (online marketplaces, search engines, social networks) and research.
  • check_circle Size criterion: as a general rule, the directive applies to medium and large companies, that is, from 50 employees or 10 million euros in annual turnover. Micro and small enterprises are, as a general rule, outside the scope.

There are important exceptions to the size rule: certain types of entity fall under NIS2 regardless of how many employees they have, because of their critical role. This is the case for DNS service providers, top-level domain (TLD) name registries, providers of electronic communications networks and services, or certain public administrations. In addition, each Member State can designate further entities where their disruption would have a significant impact on public safety or social order.

Transposition in Spain

In Spain, NIS2 is transposed through a national cybersecurity coordination and governance law that replaces and expands the previous framework (Royal Decree-law 12/2018, which transposed the first NIS directive). This law designates the competent authorities by sector, sets the national enforcement regime and specifies the supervision and reporting procedures.

A key element of the Spanish model is how it builds on existing bodies: the reference incident response teams (CCN-CERT for the public sector, INCIBE-CERT for the private sector and citizens, and ESPDEF-CERT in the defence sphere) act as points of contact and coordination. The national law also integrates NIS2 with instruments already established in the country, such as the National Security Framework (ENS), so that the ENS technical measures serve as a basis to demonstrate a large part of the NIS2 obligations.

Important notice:

This article is purely informational and educational and does not constitute legal advice. The text applicable to your organisation is always the national transposition law and the directive itself. To determine whether you are affected and which specific obligations apply to you, consult a specialised legal advisor.

Key Security Obligations

NIS2 requires entities to adopt appropriate and proportionate technical, operational and organisational measures to manage the risks to their network and information systems. The directive lists a minimum set of measures based on an "all-hazards" approach. The main ones are:

  • check_circle Risk analysis and security policies: systematic assessment of threats and information security policies approved by management.
  • check_circle Incident handling: procedures for detection, response, containment and recovery from cybersecurity incidents.
  • check_circle Business continuity and crisis management: backups, disaster recovery plans and guaranteed availability of essential services.
  • check_circle Supply chain security: control of the security of suppliers and service providers, including infrastructure and managed service providers.
  • check_circle Encryption, access control and multi-factor authentication (MFA): use of cryptography, access control policies, identity management and MFA to protect access to systems.
  • check_circle Training, cyber hygiene and personnel security: continuous awareness, basic cybersecurity good practices and human resources and asset management policies.

The following table maps each NIS2 obligation to the practical way of covering it within an infrastructure security strategy:

NIS2 obligation How to cover it
Risk analysis and security policy ISMS compliant with ISO 27001; documented risk analysis reviewed regularly.
Incident handling 24/7 monitoring, SIEM, incident response plan and CSIRT reporting channel.
Business continuity and backup 3-2-1 offsite backup, disaster recovery plan with defined RPO/RTO.
Supply chain security Certified providers (ISO 27001, ENS), contractual security clauses and audits.
Encryption and access control Encryption in transit and at rest, identity management, MFA and least privilege.
Training and awareness Continuous cybersecurity and cyber hygiene training plan for all staff.
Incident reporting Procedures and templates to meet the 24h, 72h and one-month deadlines.

Incident Reporting: 24h, 72h and 1 Month

One of the most demanding novelties of NIS2 is its staged procedure for reporting significant incidents to the CSIRT or the competent authority. An incident is considered significant when it has caused or is capable of causing severe operational disruption or financial loss, or when it affects other natural or legal persons. The deadlines are strict:

bolt 24 hours

Early warning

Initial notice indicating whether the incident may be due to an unlawful act or have cross-border impact.

description 72 hours

Incident notification

Initial assessment with severity, impact and indicators of compromise known so far.

task_alt 1 month

Final report

Detailed description, root cause, mitigation measures applied and cross-border impact.

Meeting these deadlines requires having a detection and response capability in place beforehand: without continuous monitoring and a defined incident response plan, it is practically impossible to issue an early warning within 24 hours. That is why reporting is not an isolated requirement, but the visible consequence of mature incident handling. An infrastructure provider with 24/7 monitoring helps detect and scope the incident within the required deadlines.

Management Liability and Fines

One of the most profound changes introduced by NIS2 is that it makes the management bodies directly accountable. It is no longer enough to delegate cybersecurity to the technical team: the directive obliges management to approve the risk management measures, oversee their implementation and answer for non-compliance. In addition, members of the management bodies must receive cybersecurity training and ensure that staff also receive regular training.

The penalty regime is robust and sets harmonised minimum caps across the EU. For essential entities, fines can reach a maximum of at least 10 million euros or 2% of total worldwide annual turnover, whichever is higher. For important entities, the maximum is set at at least 7 million euros or 1.4% of worldwide annual turnover. On top of this come supervisory measures that can go, in serious cases involving essential entities, as far as the temporary suspension of certifications or of management functions.

How a Compliant Infrastructure Provider Helps

Complying with NIS2 is not only the company's own task: a large part of the obligations depend on the infrastructure that supports the services. Working with a compliant datacenter and hosting provider brings direct advantages on several of the fronts the directive requires:

  • arrow_right Supply chain: a provider with ISO 27001 certification and ENS compliance demonstrates in documented form that its part of the chain meets the security controls, a direct NIS2 requirement.
  • arrow_right Backup and continuity: offsite backup services and disaster recovery with defined RPO/RTO cover the business continuity obligation.
  • arrow_right Monitoring and response: 24/7 monitoring and detection infrastructure that allow incidents to be identified in time and provide the information needed to report on schedule.
  • arrow_right Encryption and access control: encryption in transit and at rest, network segmentation, MFA and access management as part of the platform.

It is worth distinguishing NIS2 from other frameworks it relates to but is not equivalent to. The ENS is the Spanish security framework for the public sector and its providers; ISO 27001 is an international information security management standard adopted voluntarily; and the GDPR governs personal data protection. NIS2 focuses on the cybersecurity of the networks and systems of critical and essential infrastructure. Although they address different aspects, they overlap and reinforce each other: implementing an ISO 27001 ISMS or complying with the ENS covers much of the technical measures of NIS2, and a cybersecurity incident involving personal data can trigger both the NIS2 and the GDPR reporting obligations at once. You can dig deeper into their differences in our article on ISO 27001, ENS and GDPR.

Frequently Asked Questions

Which companies does the NIS2 directive affect?

It affects essential and important entities in sectors such as energy, transport, banking, health, water, digital infrastructure, managed ICT services and public administration, among others. As a general rule it applies to medium and large companies (more than 50 employees or more than 10 million euros in turnover), although some entities are covered regardless of their size, such as DNS providers, domain name registries or telecommunications operators.

What deadlines does NIS2 set for reporting an incident?

A staged procedure: an early warning within a maximum of 24 hours from becoming aware of the significant incident, a more detailed notification within 72 hours with an initial assessment, and a final report within one month covering causes, measures applied and real impact.

Does complying with ISO 27001 or the ENS mean complying with NIS2?

Not automatically, but it helps a great deal. ISO 27001 and the ENS cover much of the technical and organisational measures required by NIS2 (risk analysis, access control, encryption, continuity). NIS2 adds specific requirements on governance, incident reporting within strict deadlines and direct management liability that must be verified separately.

Conclusion

NIS2 marks a turning point in the cybersecurity of European organisations: it broadens the sectors obliged, tightens the security measures, sets strict reporting deadlines and turns cybersecurity into a direct responsibility of management with serious financial penalties. The key points to remember:

  • arrow_right Broad scope: it covers essential and important entities across many sectors and, as a general rule, medium and large companies, with exceptions that catch organisations of any size.
  • arrow_right Concrete obligations: risk analysis, incident handling, continuity and backup, supply chain security, encryption, access control, MFA and training.
  • arrow_right Deadlines and liability: reporting within 24h, 72h and one month, and direct management liability with fines of up to 10M€ or 2% of turnover for essential entities.
  • arrow_right Compliant provider: relying on infrastructure certified in ISO 27001 and ENS covers the supply chain and makes backup, monitoring and on-time reporting easier.

At EasyDataHost we operate our own datacenter in Spain with ISO 27001 certification and ENS compliance, offsite backup, disaster recovery and 24/7 monitoring. If you need to align your infrastructure with the NIS2 requirements, contact our team for a technical review with no obligation. Remember that this article is informational and does not replace legal advice.

NIS2 Compliance Cybersecurity ENS ISO 27001 EU Regulation
policy

Get your infrastructure ready for NIS2

EasyDataHost: our own datacenter in Spain with ISO 27001, ENS compliance, offsite backup, disaster recovery and 24/7 monitoring. We help cover your part of the supply chain.