Skip to content

European Union · Applies by law

NIS2 compliance

Network and Information Security Directive 2

Essential and important entities in the EU, including many cloud and managed service providers, with personal liability for management bodies.

The context

What it actually asks of you

NIS2 significantly widened the EU's cybersecurity regime, and it explicitly names cloud computing service providers, managed service providers and data centre services as in-scope sectors. Many SaaS companies that considered themselves outside EU cybersecurity regulation now sit inside it.

Two features make it different from what teams are used to. First, management bodies bear personal accountability for approving and overseeing risk management measures, with penalties that can attach to individuals. Second, the incident reporting clock is short: an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.

The Article 21 measures themselves will look familiar to anyone who has implemented ISO 27001, risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, cryptography and access control. If you have an ISMS, most of the work is mapping and evidencing rather than building.

The common mistake

What teams get wrong.

Cloud computing and managed service providers are named in scope. Incident reporting runs on a 24-hour early-warning clock, which is far shorter than most teams have planned for.

Our scope

What we do for NIS2.

  1. 01Scope and entity classification assessment
  2. 02Risk management measures under Article 21
  3. 0324-hour / 72-hour / one-month incident reporting runbook
  4. 04Supply chain security requirements
  5. 05Management body accountability and training
  6. 06Mapping onto an existing ISO 27001 ISMS to avoid duplicate work

innsecs provides security and compliance services, not legal advice, and we are not a law firm. We build the technical and organisational measures, evidence and processes these obligations require, and work alongside your counsel on legal interpretation.

Questions

NIS2 FAQ

It depends on your sector and your size. Cloud and managed service providers are listed sectors; whether you land in the essential or important tier turns largely on headcount and turnover thresholds. The classification changes your supervisory regime and your maximum penalties, so it is worth establishing properly.

Usually modest. The Article 21 measures overlap heavily with Annex A, so the incremental work concentrates on the incident reporting timeline, management body accountability and training, and demonstrating supply chain security specifically.

Only if the runbook exists beforehand, who declares an incident, who has authority to notify, and which CSIRT receives it. That is precisely what we build and rehearse, because 24 hours is not enough time to work it out from scratch.

Find out whether NIS2 binds you.

Bring your product, your users and your markets. We will tell you what applies, what does not, and what it takes to close the gap.

Book a scoping callsecurity@innsecs.com

No sales sequence. A scoping call and a written proposal cost nothing.