Guide

What Is the NIS2 Directive? Scope, Sectors and Deadlines

A plain-English explanation of the NIS2 directive: what it is, which sectors and company sizes it covers, what it asks organisations to do, and how it reaches small businesses through their customers.

By SecureBusinessHub Editorial, International cybersecurity desk — · 7 min read

The NIS2 directive is the European Union's network and information security law: Directive (EU) 2022/2555, adopted in 2022, replacing the original NIS directive from 2016. It sets baseline cybersecurity and incident-reporting obligations for organisations in a defined list of sectors, and it is written as a directive rather than a regulation, which means each EU member state turns it into its own national law. Member states were required to transpose it by 17 October 2024. This guide explains what the directive covers, which organisations fall inside it, what it asks them to do, and the indirect route by which it reaches small businesses that are nowhere near its size thresholds.

This is an explainer of the instrument itself. If your question is the more practical one of what applies to your own business across both major regimes, start with our guide to NIS2 requirements and GDPR for small business. Nothing here is legal advice; the directive is national law in twenty-seven different versions, and the only reliable answer for your situation comes from someone qualified in your jurisdiction.

What the directive is trying to do

The 2016 NIS directive was the EU's first attempt at cross-border cybersecurity rules, and it was widely judged to have been applied unevenly. Member states interpreted its scope differently, so an organisation that counted as critical in one country was unregulated in another, and enforcement was thin. NIS2 is the response: a wider list of sectors, a size-based rule for who is in scope so that member states have less room to diverge, harder reporting deadlines, and explicit accountability at management level.

The shape of the obligations is worth understanding even if you are outside scope, because it is quickly becoming the reference model for what "reasonable security" looks like in Europe. Insurers, enterprise procurement teams and client security questionnaires increasingly borrow their questions from it, which is why a ten-person supplier can end up answering NIS2-shaped questions without ever being regulated by the directive.

Which sectors it covers

NIS2 splits covered organisations into two tiers. Essential entities are the largest organisations in the highest-criticality sectors, listed in the directive's Annex I. Important entities are medium-sized organisations in those sectors, plus organisations in the other critical sectors listed in Annex II. Both tiers face the same core security obligations; the difference is mainly in how they are supervised, with essential entities subject to proactive oversight and important entities generally supervised after the fact.

  • Annex I, high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management between businesses, public administration, and space.
  • Annex II, other critical sectors: postal and courier services, waste management, chemicals, food production and distribution, several categories of manufacturing including medical devices and electronics, digital providers such as online marketplaces and search engines, and research organisations.
  • Some organisations are in scope regardless of size, including certain DNS service providers, top-level domain registries and trust service providers.
  • Member states may designate additional entities where a disruption would have significant national impact, so national lists can be broader than the annexes.

The size rule, and why most small businesses sit outside it

NIS2 generally uses a size cap. An organisation falls in scope if it operates in a listed sector and is at least medium-sized under the EU's own definition, which means fifty or more employees, or annual turnover and balance sheet total above ten million euros. Large organisations in Annex I sectors, meaning roughly two hundred and fifty or more employees or turnover above fifty million euros, are the essential tier. Below the medium-sized threshold, most businesses are outside the directive's direct scope unless a member state has specifically designated them or they fall into one of the size-independent categories above.

That is the answer to the question most small business owners actually have, and it is usually reassuring: a twelve-person accounting firm, design studio or logistics broker is very unlikely to be directly regulated by NIS2. What that does not mean is that the directive is irrelevant to them, which is the part that catches people out.

How it reaches a business that is not in scope

One of the specific security measures NIS2 names is supply chain security. In-scope organisations are expected to consider the security practices of their direct suppliers and service providers, which turns into a very practical behaviour: they start asking. If you sell software, IT services, logistics, payroll processing, or anything that touches a regulated customer's systems or data, expect a questionnaire, a contractual security schedule, or an annual review that exists because your customer is in scope and you are part of what they are accountable for.

This is the most common way a small business first encounters the directive: not as a regulator, but as a customer asking questions it cannot answer. Being able to answer them is a commercial matter rather than a legal one, and it works in both directions, because you have your own suppliers with their own access to your systems. Our walkthrough of how to run a vendor risk assessment covers that side of it, including what to ask and how to score the answers when you have no procurement team to do it for you.

What in-scope organisations are asked to do

The directive sets out a list of risk-management measures rather than a prescriptive technical standard. The obligations are proportionate, meaning the expected depth scales with the organisation's size, exposure and the likely impact of an incident. The recurring themes will look familiar to anyone who has worked through a security questionnaire.

  • Risk analysis and written information system security policies.
  • Incident handling: detection, response and the internal process for escalating an event.
  • Business continuity, including backup management, disaster recovery and crisis management.
  • Supply chain security, covering the security practices of direct suppliers and service providers.
  • Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure.
  • Policies to assess whether the risk-management measures actually work.
  • Basic cyber hygiene practices and security training, including for management.
  • Cryptography and encryption policies, access control, asset management and human resources security.
  • Multi-factor authentication, secured communications, and secured emergency communications.

The one genuinely new element compared with the 2016 directive is management accountability. NIS2 requires the management bodies of in-scope entities to approve and oversee the risk-management measures, requires them to undergo training, and provides that they can be held responsible for failures. Cybersecurity is framed as a board-level duty rather than something delegated entirely to whoever runs IT.

The reporting timeline

NIS2 uses a staged reporting process for significant incidents, and the first stage is fast. An early warning goes to the national computer security incident response team or competent authority within twenty-four hours of becoming aware of the incident, a fuller incident notification within seventy-two hours, and a final report within one month. Exactly what counts as significant, and which authority receives the report, is set by each country's implementing law.

These deadlines sit alongside, not instead of, the separate obligation under data protection law to report personal data breaches to a supervisory authority. An incident can trigger both, on different clocks, to different authorities, and working out who has to be told what is a decision nobody wants to make for the first time at nine in the morning during an outage. Our guide to data breach notification requirements covers how to map those obligations out in advance.

A worked example

A fourteen-person company builds and hosts scheduling software, mostly for private clinics. It is far below the size threshold, is not a designated entity, and is not directly regulated by NIS2. In the spring, its three largest customers, all mid-sized healthcare providers that are in scope, each send a supplier security assessment. The questionnaires are not identical, but they overlap heavily: do you have a written security policy, how do you handle incidents and how fast do you notify us, do you enforce multi-factor authentication, how do you manage access when staff leave, what are your backup and recovery arrangements, and who are your own subprocessors.

The company answers honestly, discovers it has no written incident process and no documented offboarding checklist, and spends a fortnight writing both. Nothing about its legal position changed: it was outside scope before and it is outside scope after. What changed is that it kept three contracts it might otherwise have had to renegotiate, and it now has documents its own next customer will ask for too. That is the realistic version of how this directive affects a small business.

Where this fits

This article explains the instrument. For what the two major European regimes ask of a smaller business in practice, read our guide to NIS2 requirements and GDPR for small business, and for the supplier side of the supply chain obligation, our walkthrough of vendor risk assessment. Third-party compromise is also a live attack route in its own right, not just a paperwork question, which we cover in third-party and supply chain attacks. If you would rather adapt structured documents than write the policies and questionnaires from a blank page, our editable policy template pack is built for small businesses answering exactly these questions.

NIS2 requirements: the second regime to know about

Data protection law is not the only European regime a business gets asked about. The NIS2 directive sets baseline cybersecurity and incident-reporting obligations for organisations in a defined list of sectors, and it is the source of most of the security questions that now arrive attached to contracts. The two regimes cover different ground: data protection law governs personal data and what people can ask you to do with it, while the NIS2 requirements govern the security and resilience of network and information systems, whether or not personal data is involved. A single incident can engage both, on separate clocks, to separate authorities.

The directive applies to organisations in its listed sectors that are at least medium-sized, meaning broadly fifty or more employees or turnover and balance sheet above ten million euros. That size rule puts most small businesses outside its direct scope, and the honest answer for a ten-person company is usually that the directive does not regulate it. What the size rule does not do is keep the requirements away, because one of them is supply chain security: organisations inside scope are expected to consider the security practices of their direct suppliers, and the way that expectation shows up in the world is as a questionnaire in your inbox.

The measures the directive names are a reasonable checklist for any business, which is why they are worth knowing even when they do not apply to you directly. They cover risk analysis and written security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, basic cyber hygiene and training including for management, encryption and access control policies, and multi-factor authentication. Reporting is staged and fast for the organisations it covers: an early warning within twenty-four hours of becoming aware of a significant incident, a fuller notification within seventy-two hours, and a final report within one month.

Because the directive is national law in each member state rather than a single rulebook, the details of scope, thresholds and reporting differ by country. For a fuller explanation of the instrument itself, see our guide to what the NIS2 directive is, and for the supplier side of the supply chain obligation, our walkthrough of vendor risk assessment. The reporting clocks that run alongside data protection deadlines are covered in data breach notification requirements.

Frequently asked questions

Does NIS2 apply to a small business?

NIS2 generally applies to organisations in its listed sectors that are at least medium-sized, meaning broadly fifty or more employees or turnover and balance sheet total above ten million euros. Most smaller businesses fall outside its direct scope, unless a member state has specifically designated them or they sit in one of the size-independent categories such as DNS service providers or trust service providers. Being outside scope does not stop the directive reaching you through customers who are inside it.

What is the difference between GDPR and NIS2?

GDPR governs personal data: what you may collect, why you may hold it, and what rights people have over it. NIS2 governs the security and resilience of network and information systems in specific sectors, whether or not personal data is involved. One incident can engage both regimes at once, on separate reporting clocks and to separate authorities.

How long do you have to report a data breach?

Under the European model, a personal data breach is reported to the supervisory authority without undue delay and, where feasible, within seventy-two hours of becoming aware of it, and affected individuals are told without undue delay where the risk to them is high. Organisations in scope of NIS2 carry a separate obligation: an early warning within twenty-four hours, a fuller notification within seventy-two hours, and a final report within one month.

Does a small business need a data protection officer?

Under GDPR a data protection officer is required where the organisation is a public authority, where its core activities involve regular and systematic monitoring of people on a large scale, or where its core activities involve large-scale processing of special category or criminal offence data. Most small businesses meet none of those tests and are not required to appoint one, though naming someone internally as the contact for privacy questions is worth doing regardless.

What should a small business do when a client's security questionnaire asks about NIS2?

Answer what you actually do rather than what you think the client wants to hear. The questions usually cover written security policies, incident handling and how fast you would notify them, multi-factor authentication, access control when staff join and leave, backup and recovery arrangements, and which of your own subprocessors touch their data. Gaps are common, and disclosing one with a date for closing it lands far better than an answer that does not survive the follow-up question.

Do these rules reach a business based outside the EU?

They can. GDPR reaches organisations outside the EU that offer goods or services to people in the EU or monitor their behaviour, and other regions have their own regimes with their own triggers. NIS2 obligations follow the sectors and the member states that transpose it, but its supply chain expectations travel through contracts, which is how they reach suppliers anywhere in the world.

Related reading