NIS2: Expanding the Cybersecurity Perimeter

October 2024 marked the transposition deadline for NIS2, fundamentally widening who is considered critical infrastructure in Europe.

Key Changes from NIS1

NIS2 moves away from the fragmented "identification" process of NIS1 and introduces a clearer, broader scoping mechanism.

  • Size-cap rule: All medium and large enterprises in selected sectors are included automatically. Use our Size-Cap Checker to see if you are in scope.
  • Management accountability: C-level executives can be held personally liable for gross negligence in cybersecurity and may be temporarily suspended from management roles.
  • Strict reporting timelines: A phased approach requiring a 24-hour early warning, a 72-hour formal incident notification, and a final report after one month. See our Breach Timeline Tool.
  • Supply chain security: Essential and important entities must address cybersecurity risks in their supply chains, significantly expanding the indirect impact of the directive.

Sectors Covered

Highly Critical Sectors (Annex I) Other Critical Sectors (Annex II)
Energy, Transport, Banking, Financial Market Infrastructure Postal/Courier services, Waste management
Health, Drinking Water, Waste Water Chemicals manufacturing, production, distribution
Digital Infrastructure (IXPs, DNS providers, Cloud computing) Food production, processing, distribution
Public Administration, Space Digital Providers (Online marketplaces, search engines)

Common Mistakes

Ignoring the supply chain ripple effect

Even if your company falls below the size thresholds (e.g., a small software vendor with 20 employees), if you supply software to a "Highly Critical" entity like a bank, they will contractually pass NIS2 obligations down to you to fulfill their own compliance requirements. Prepare by assessing your Vendor Risk profile.