Organizations operating in the expanded list of essential and important sectors within the EU, including many mid-sized companies that were out of scope under the original NIS Directive but now meet NIS2's broader size and sector thresholds.
Risk-management measures covering incident handling, business continuity, supply-chain security, and access control; incident reporting on a strict timeline (early warning within 24 hours, incident notification within 72 hours, final report within one month); and direct management-body accountability for cybersecurity risk oversight.
Supply-chain security is an explicit requirement, not an implied best practice, meaning your vendor risk management program needs to be documented and defensible, not informal.
Entity classification (essential vs. important, and applicability confirmation), gap assessment against the risk-management measures, incident-reporting process design against the tight statutory timelines, and supply-chain security review.
Confirm essential/important entity status and jurisdiction-specific obligations.
Close gaps in risk-management measures and supply-chain security controls.
Stand up incident classification and reporting processes matched to statutory deadlines.
Risk-management measure documentation, supply-chain security assessments of critical vendors, incident classification and reporting records, and management-body cybersecurity oversight records.
Assuming NIS Directive compliance under the original directive automatically satisfies NIS2's expanded requirements; missing the 24-hour early-warning reporting deadline because incident detection and internal escalation aren't fast enough to meet it.
Confirm your NIS2 classification and see where your controls stand.
Request a Gap Assessment →