What Is NIS2 and Does It Apply to Your Company
A client questionnaire labelled “NIS2 compliance” does not mean the law applies to you. The boundary is the national law that transposes the directive, and the questionnaire also arrives at companies it does not cover, because the client is checking its supply chain.
A client questionnaire labelled “NIS2 compliance” does not mean the law applies to you. The boundary is the national law that transposes the directive, and the questionnaire also arrives at companies it does not cover, because the client is checking its supply chain.
A letter arrives from a client’s procurement team and looks harmless: eighteen questions about cybersecurity, two weeks to fill them in, “NIS2 compliance” written across the top. The company has eleven people, none of them a lawyer, and the first question everyone asks each other is the same one — what is NIS2 doing on this letter, and does it actually apply to us, or has someone sent the same form to every supplier in turn, hoping that someone will answer.
The answer is almost always “no, but”, and it is this “but” that is worth getting right, because it decides how much time and money the letter will cost. NIS2 does not apply directly to most small and medium-sized companies, but that does not mean the questionnaire is a mistake, and it does not mean it can be left unanswered. What follows is where the line sits, what sits on each side of it, and why the useful answer does not come from the directive, but from the national law that transposes it — a statute that almost nobody in this conversation names.
What is NIS2: a directive, not a regulation, and that is where the wrong answers start
The General Data Protection Regulation is a regulation, which means it applies directly, in the same wording, in every member state — that is why it can be talked about as one European rulebook, and that is why everyone has got used to European requirements looking like this. NIS2 is a directive, and it works the other way round: it requires a member state to achieve a result in its own law, and it does not, by itself, place duties on a company. The practical consequence is that “what is NIS2 requiring of us” is the wrong question, and the right one is “what does the national transposing act require”.
The directive’s full title is Directive (EU) 2022/2555 of the European Parliament and of the Council on measures for a high common level of cybersecurity across the Union; it entered into force in January 2023, and member states were to transpose it into their own legal systems by mid-October 2024. Most member states missed that deadline, and it is worth being precise here too: what was late was not always the passing of a law, but the notification to the European Commission of complete transposition, and those are two different things that news stories usually collapse into one.
Why this matters in practice, not as a seminar: if a supplier, a consultant or the questionnaire itself claims that “NIS2 requires X”, it is worth asking which article of which statute actually requires it. In a member state that has transposed, the answer will be that country’s act, or the implementing rules under it; in Spain and France, where a national NIS2 law has not yet been adopted and where the Commission this July referred the states to the Court of Justice of the European Union, there is simply no answer to that question. Copying one country’s requirements into another and calling them “European” is the same as quoting a neighbour’s contract, and it has about as much legal force.
Two lists and one size threshold
The directive’s structure is simple, and it is worth knowing even when the duties that actually bind a company come from national law, because national law almost always takes this structure over. There are two sector lists — eleven highly critical sectors in the first, seven other critical sectors in the second — and a company comes into view at all only if its activity falls in one of them. The first list is energy, transport, banking, financial-market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.
The second list is postal and courier services, waste management, manufacture and distribution of chemicals, manufacture and distribution of food, manufacturing in six sub-sectors from medical devices to motor vehicles, digital service providers and research organisations. The phrase “digital service providers” is narrower here than it sounds, and it means online marketplaces, search engines and social-networking platforms. The first of those is worth reading carefully: a marketplace is a platform on which other sellers trade, not an online shop that sells its own goods, and that distinction knocks out a whole class of companies.
The second part is size, and it is the part most people read first. By default the directive applies to medium-sized and larger companies in these sectors, while micro-enterprises and small enterprises stay out of scope. In the Commission’s recommendation a small enterprise is one that employs fewer than 50 people and whose turnover or balance sheet does not exceed €10 million, and a medium-sized one is one that exceeds those thresholds but still employs fewer than 250 people and whose annual turnover does not exceed €50 million or whose balance-sheet total does not exceed €43 million. The “or” between turnover and balance sheet is deliberate, and losing it is a mistake. National law does not always write these figures identically, and there is a separate section on that later.
One more thing that tends to get confused at this point is that the sector list talks about activity, not about the industry code in the register. A company whose registered activity is software development may in fact be administering a client’s information systems, and it is that second activity that appears in the first list as ICT service management — a managed service provider (MSP) in the directive’s language. The reverse also happens: a company with an impressive industry code may in fact do nothing that the list names. The right question is therefore what the company actually does for the client, not what is written in the commercial register.
When size means nothing
This is exactly where most companies draw the wrong conclusion and stop reading. The directive also has a list in which size does not matter at all, and a company that falls on it is in scope even if it is five people with a negligible turnover. It includes providers of public electronic communications networks and of publicly available electronic communications services, trust service providers, operators of top-level domain name registries and DNS service providers, and, in some cases, those who provide domain name registration services.
Sitting beside that are also four situations in which what decides is not the type of activity but significance, and they are drafted so as to be wide. If the company is the only one in the member state providing a service that supports critical societal or economic activities; if a disruption of its operations could have a significant impact on public safety, security or health; if it could create systemic risk, particularly with a cross-border effect; or if the company is particularly important at national or regional level in its own sector or in other sectors that depend on it — then the size threshold no longer means anything, and the member state takes the decision.
In practice that means the answer to “are we in scope” cannot be read from headcount, and that is the most common mistake in this whole subject. It is read from two things in order: whether the sector is on one of the lists, and whether any of these special criteria apply. Both of those things are written into the national act, and some acts add categories the annexes do not name at all. A sector the annexes name is not, by itself, a duty on the company.
In practice reading those lists takes an afternoon and, in two cases out of three, gives a clear answer. The third case — when the company looks like a candidate for one of the broadly drafted significance criteria — cannot be solved by reading, because there the state takes the decision by drawing up the list of entities, and that is a document the supervisory authority maintains. If that is the feeling, the cheapest step is simply to ask the authority, rather than to commission a legal opinion on a text that the authority itself will apply.
Essential or important: a difference that is not a nuance
If a company is in scope of the directive, it lands in one of two categories, and the directive calls them essential entities and important entities; together they are simply entities. The difference between the two is not in the words: supervision intensity and the cap on fines both follow from it, and it is set by the combination of which list the sector sits on and how large the company itself is. That is why it is worth establishing the category before any conversation with a consultant or a supplier.
In simplified form it looks like this: large companies on the first list are essential, medium-sized companies on the same list are important, and companies on the second list are important regardless of whether they are medium-sized or large. This is the place where summaries go wrong most often, by assuming that the first list means “essential” automatically — it does not, and a medium-sized company in a first-list sector is important, not essential. The gap between those two rows is €3 million in the directive’s fine cap, so it is not worth leaving unread.
Supervision differs too, but not always in the way people quote from the directive. In the directive an essential entity can be inspected regularly and at random even when nothing has happened, while an important entity is inspected when there are indications that something is wrong. Some national acts take that split over; some give the same tools — on-site inspections, remote monitoring, scanning — against every entity and have the authority prioritise them by risk, not by category. The written difference you should actually read is therefore the national supervision article, not the directive’s chapter, and a firm that is budgeting management time should start there.
One more practical consequence is that the category is not permanent. A company that hires fifty people or whose turnover grows can, from one year to the next, move from outside the scope into it or from one category into the other, and nobody will send a separate reminder. That is why it is worth putting this check on the same annual rhythm as the accounts, when the figures are on the table anyway and checking them costs an extra hour, not a separate project. The test you re-run is the one in the national act, which may not be the Commission recommendation’s.
Why the questionnaire arrived if you are not on the lists
The questionnaire arrives because an in-scope company also has to manage the risks that come from its direct suppliers and service providers, and, in choosing measures, has to take into account each particular supplier’s vulnerabilities and overall cybersecurity practices, including secure development procedures. That is a duty on the client, not on you, and almost every questionnaire now travelling along supply chains in Europe follows from that one paragraph of the directive.
That also decides how to answer it. A client that is in scope cannot discharge its duty without knowing how its suppliers work, so it asks. The questionnaire places no statutory duties on you and does not make you an entity; it is a contract question, and the answer to it is a contract answer with everything that belongs to contracts — proportionality, price, and clarity about what you are prepared to promise in writing. If the questions are proportionate, it is worth answering them honestly; if they demand a certificate whose cost exceeds the contract itself, that is a negotiation, not a compliance topic.
The other side of the same thing is that questionnaires become a market requirement faster than they become a legal duty. A company that works with banks, hospitals, energy or public bodies will soon receive this questionnaire from every other client regardless of what the statute says, and then it is cheaper to put the answers in order once and keep them than to write them from scratch each time and discover the same gap each time. That is an entirely different argument for cybersecurity than the fine cap, and in our view a more honest one, because it is about clients, not about fear.
A third, less noticed reason to put the answers in order is insurance. Application forms for cyber-risk policies ask almost the same things as the client’s questionnaire, and an inaccurate answer there costs more than a lost contract, because it can affect the payout at the exact moment it is needed. For a company that has once written an honest description of what it has and what it does not have, that document serves all three purposes at once.
What the national law actually requires
The directive has been in force since January 2023, and that is the text that binds the member state, not the company. The concrete technical requirements are not listed in it as a specification — there is a general rule that an entity puts in place proportionate measures — and the detail, in states that have transposed, sits in the national act and its implementing rules. This two-level structure is typical, and in practice it means you look in the national law to see whether you are an entity, and in the implementing rules for what to do then. The Commission’s page on transposition is how to find that act for the country where the company is established; where there is none yet, Spain still has Real Decreto-ley 12/2018 and Real Decreto 43/2021, and France still has loi n° 2018-133 — the previous directive’s rules, not NIS2.
The competent authority is designated by the member state, and is often also the single point of contact for cooperation with the other member states. Incidents are taken by a different body, and that tends to surprise people: the national computer security incident response team (CSIRT) is named in the same act, and it is not a single European address. Defence and national-security systems are often carved out or given a different authority. Mixing those addresses is a mistake that usually shows up at the worst possible moment.
Another feature of national law that summaries tend to lose is the size definition. The directive points at the Commission recommendation, but many acts write their own. Latvia’s Nacionālās kiberdrošības likums, in force since 1 September 2024, treats a firm as large if it meets any one of the three figures — 250 staff, or turnover above €50 million, or a balance sheet above €43 million — so a company with a hundred people and a large turnover can be large there and still medium under the recommendation. The reverse also happens. A questionnaire that quotes other figures is quoting another country’s law, or a consultant’s paraphrase.
One terminology point is worth pinning down, because it tends to produce misunderstandings in conversations with lawyers. A personal data breach and a cyber incident are not the same event, they are reported to different authorities and on different clocks, and one event can be both at once. Notification of a personal data breach is already a duty wherever the GDPR applies; a NIS2 incident notification is a duty only once the national act says you are an entity. For a company that is both, that means two notifications to two addresses, and that is exactly why it is worth writing the reporting order on one page while nothing has happened.
When the reporting clock starts, and what starts it
If a company is an entity under the national act, then in the event of a significant incident the reporting clock starts, and this is the only one of all these duties that cannot be performed after the fact or put off until next week. The directive writes the clock as an early warning without undue delay and in any event within twenty-four hours, an incident notification without undue delay and in any event within seventy-two hours, and for trust service providers that second deadline is also twenty-four hours. The final report follows within a month of the incident notification, but if the incident has not yet been resolved, a progress report goes first instead. National law may copy those hours, or it may not; the clock that binds you is the one in the act.
The word “significant” is not decorative here, and the practical decision turns on it. The directive writes it as an incident that has caused or is capable of causing severe operational disruption or financial loss for the entity itself, or that has affected or is capable of affecting other persons by causing considerable damage. That is not always the national switch: some implementing rules add a euro or turnover trigger — Latvia’s cabinet regulation treats an incident as significant at material losses of at least €500,000 or 5% of annual turnover, taking the lower of the two — and that figure is not European. In practice the decision whether to report is taken in the first hours and almost always on incomplete information, so companies that have done it once write from a prepared template the next time.
Practical readiness here is a much smaller thing than it sounds in a meeting. You need to know who takes the decision to report, where the first notification is sent and what has to go in it, and you need that information to be available even when the system itself is down and the mail is on that same system. Companies that prepare only policy documents and never rehearse this chain discover on a Friday evening that the only person with access is on leave and that nobody knows the right address.
Who is liable, and what a mistake costs
In the directive the duty sits on the management body: it approves the risk-management measures, oversees their implementation, answers for infringements and undergoes training. National law may personalise that onto a named officer — Latvia’s act makes the head of the entity responsible and requires them to appoint a cybersecurity manager — and the point is the same either way. It is not a reason to treat the subject as an IT-department matter; the question has to arrive where budget decisions are taken.
The fines are written in national law, and they are written differently from the way they are usually quoted in presentations. In the directive an essential entity may face up to €10 million or 2% of the worldwide turnover of the whole undertaking, whichever is higher, and an important entity up to €7 million or 1.4%. Some acts copy that phrase; some drop “whichever is higher” and only engage the percentage limb above €500 million of turnover. A direct quotation from the directive is therefore not a correct sentence about any one country.
The figures in these provisions look threatening, and it is worth remembering that they are a cap, not a tariff, and that they are written so as to reach even Europe’s largest companies. What matters more in practice than the sum is that the competent authority also has other tools — orders, warnings and inspections — and that a conversation with it looks entirely different for a company that has put a foundation in place and can show it in documents than for a company that learns its status during an incident from the authority that supervises it.
One more thing these provisions do not say is that the fine is not the only financial consequence. In practice the most expensive part is usually downtime and the loss of clients, and that is exactly why companies that have been through this subject talk about it as business continuity, not as compliance. Putting it that way is also how to talk about it with the board: not “we face ten million”, which is untrue for almost any small or medium-sized company, but “how long can we not operate, and what does that cost”.
How the same thing looks in the rest of Europe
If a company works in several markets, the uniformity described in one sentence of the directive turns out in practice to be eleven different laws with different dates of entry into force. In Lithuania, Italy and Latvia their laws have been in force since autumn 2024, in Finland since last April, in Germany since last December, in Estonia and Sweden since this January, and in Poland since this April. Each of them has its own annexes, its own definitions and its own supervisory authorities, and compliance in one country proves nothing in another.
Two countries among our markets have not yet adopted their law. In Spain and France the European Commission this July referred the states to the Court of Justice of the European Union precisely because complete transposition has not been notified, and that means in practice that a company there today has no national NIS2 statute to comply with, but does have authorities that are already the ones it will be talking to when the law arrives. Norway is a further separate case: it is not in the European Union, its current digital-security act transposes the previous directive, and NIS2 has not yet been implemented there.
Outside the European Union the picture differs further still. In the United Kingdom the 2018 regulations on network and information systems remained after withdrawal, and a bill that would widen them is currently before Parliament, but it has not yet been passed. The practical consequence of all this is simple: if a client cites “NIS2” in a cross-border contract, it is worth asking which country’s law they mean, because the answer often turns out to be that they have not checked.
What to do with the questionnaire already on the table
The first step is to write one paragraph about your status and keep it where you will find it the next time. It has three sentences: which sector the company operates in and whether that sector falls on one of the directive’s lists; how many people it employs, and what the turnover and the balance sheet are; and whether any of the criteria apply for which size does not matter. That paragraph will serve for every later questionnaire, and it is also the answer to the question the board or the owner will ask sooner or later — once it has been read against the national act of the country where the company is established.
The second step is to separate what is a legal duty from what is a client requirement, because those two things look the same on the form. If you are not an entity under that act, the questionnaire is a contract document, and ordinary contract logic applies to it — proportionality, price, and what you are prepared to promise in writing and then perform. If you are an entity, the questionnaire is the smaller of the worries, and the right order is first to read the implementing rules, then to assess your actual state against them, and only then to answer the client.
The third step is for those who supply the public sector, because there the requirements come not only from cybersecurity law but also from the tender specification, and the specification is often more concrete than the statute. We have written separately about which check a tender asks for and how often, and also about how a scan, an audit and a penetration test differ. If you have a question about a particular public-sector project or need help with answers that have to be backed by a technical fact, write to us.
In this article we deliberately do not say whether you specifically are an entity. That is decided by sector, size and the special criteria, all of which have to be read in the national act with your own figures in hand, and anyone who decides it after three minutes of conversation or from one presentation slide is selling certainty, not an answer. What can be said safely is that most of the small companies that receive this questionnaire are not entities — and that the questionnaire does not therefore go away, because it comes from the client’s duty, not from yours.
Frequently asked questions.
What is NIS2, and does it apply to my company?
Most likely not, if the company is small or a micro-enterprise. You do not read the answer from headcount, but from two things in order. First — whether the activity falls on one of the directive’s sector lists, eleven highly critical and seven other critical sectors. Only then — whether the company is medium-sized or larger. There is also a list in which size does not matter at all: electronic communications and trust service providers, operators of domain registries and of the domain name system, and those the state has identified as particularly important. The national transposing act is what actually classifies you.
How do essential entities differ from important entities?
By the cap on fines. In the directive the intensity of supervision differs too, but national law does not always take over that split: some acts give the same inspection tools against every entity and have the authority prioritise them by risk, not by category. The category under the directive is set by the combination of sector list and size: large companies on the first list are essential, medium-sized companies on the same list are important, and companies on the second list are important regardless of size. The assumption that the first list automatically means “essential” is the most common mistake.
A client sent a NIS2 questionnaire, but we are not in scope — do we have to answer?
Yes, but not because the statute requires it. The directive has an article that requires an in-scope company to manage risks that come from its direct suppliers, and the questionnaire is how the client discharges that duty of its own. No statutory duties arise for you from that, and you do not become an entity; it is a contract question with ordinary contract logic — proportionality, price, and clarity about what you are prepared to promise in writing.
How quickly must a cyber incident be reported?
For a significant incident under the directive, the early warning must be given immediately and no later than twenty-four hours, the incident notification no later than seventy-two hours, and for trust service providers the second deadline is also twenty-four hours. The final report follows within a month of the incident notification, and if the incident has not yet been resolved, a progress report goes first instead. National law may copy those hours or write different ones; the CSIRT that receives the notification is named in the transposing act, and there is no single European address.
How large are the fines under NIS2?
They are written in the national transposing act, not in the directive. In the directive an essential entity may face up to €10 million or 2% of the worldwide turnover of the whole undertaking, whichever is higher, and an important entity up to €7 million or 1.4%. Some acts copy that phrase; some drop “whichever is higher” and only engage the percentage limb above €500 million of turnover, so a direct quotation from the directive is not a correct sentence about any one country.
Latvian public institutions since 2010. SSO, official e-delivery, WCAG 2.1 AA and GDPR — we handle the specification and procurement requirements.