Key Changes from NIS1
NIS2 moves away from the fragmented "identification" process of NIS1 and introduces a clearer, broader scoping mechanism.
- Size-cap rule: All medium and large enterprises in selected sectors are included automatically. Use our Size-Cap Checker to see if you are in scope.
- Management accountability: C-level executives can be held personally liable for gross negligence in cybersecurity and may be temporarily suspended from management roles.
- Strict reporting timelines: A phased approach requiring a 24-hour early warning, a 72-hour formal incident notification, and a final report after one month. See our Breach Timeline Tool.
- Supply chain security: Essential and important entities must address cybersecurity risks in their supply chains, significantly expanding the indirect impact of the directive.
Sectors Covered
| Highly Critical Sectors (Annex I) | Other Critical Sectors (Annex II) |
|---|---|
| Energy, Transport, Banking, Financial Market Infrastructure | Postal/Courier services, Waste management |
| Health, Drinking Water, Waste Water | Chemicals manufacturing, production, distribution |
| Digital Infrastructure (IXPs, DNS providers, Cloud computing) | Food production, processing, distribution |
| Public Administration, Space | Digital Providers (Online marketplaces, search engines) |
Common Mistakes
Ignoring the supply chain ripple effect
Even if your company falls below the size thresholds (e.g., a small software vendor with 20 employees), if you supply software to a "Highly Critical" entity like a bank, they will contractually pass NIS2 obligations down to you to fulfill their own compliance requirements. Prepare by assessing your Vendor Risk profile.