The NIS2 Directive: a consultant’s guide to European cybersecurity compliance
Does NIS2 apply to you? We assess your situation in a 20-minute conversation, no commitment.
The NIS2 Directive (Network and Information Security 2, EU Directive 2022/2555) is now Europe’s most demanding cybersecurity framework, and it requires thousands of organisations across Europe to raise the bar on technical, organisational and governance measures. I have more than 30 years in regulated IT projects, I earned my MCSE with a specialisation in IT Security, and from that experience I help companies adapt to NIS2 in a practical way: risk analysis, a prioritised action plan and verifiable metrics.

What is the NIS2 Directive?
NIS2 is the evolution of the original 2016 NIS directive and strengthens the common level of cybersecurity across the European Union. Its aim is to protect digital infrastructure and essential services against a threat landscape that keeps growing. The supply chain and reliance on AI providers introduce new risk vectors the original directive did not contemplate.
Compared with the original NIS, the NIS2 Directive substantially widens the scope, tightens incident-notification obligations, introduces serious financial penalties and, above all, makes management directly accountable for the measures adopted. For more detail you can consult the portal of ENISA, the European cybersecurity authority.
Which companies does NIS2 affect?
NIS2 distinguishes two broad categories of obligated entities according to their size and the sector they belong to.
Essential entities under the NIS2 Directive
These are large organisations in critical sectors. They include energy, transport, banking and financial market infrastructure. Other included sectors are healthcare, drinking water and wastewater. Digital infrastructure and public administration also fall into this group. Rounding out the list are the space sector and managed ICT services.
Important entities under NIS2
This category includes postal services and waste management. It also covers the manufacture and distribution of chemicals. Food, medical products and electronic devices are within scope. Other sectors are motor vehicles and digital service providers. The key difference between the two categories lies in the intensity of supervision. The sanctions regime varies likewise.
Key deadlines and obligations of the NIS2 Directive
The NIS2 Directive was due to be transposed before 17 October 2024. In Spain, the process is moving forward with a specific bill that adapts NIS2 to the national framework and designates the competent authorities.
Every affected organisation must prove registration with the competent authority, designation of responsible officers and a risk-management measures plan. Added to this are incident-notification procedures with a 24-hour deadline for an early warning and 72 hours for a detailed notification. And finally, NIS2 mandates ongoing training and supervision of the supply chain.
Technical and organisational measures NIS2 requires
NIS2 also sets a minimum catalogue of measures. Every entity in scope must implement them in proportion to risk. Below are the four areas where my compliance projects have the greatest impact.
Risk management in the NIS2 Directive
It requires systematic analysis of threats, vulnerabilities and impacts, and alignment with frameworks such as ISO/IEC 27001, ENS or NIST CSF. Risk management stops being an appendix: it becomes the guiding axis of technical and investment decisions.
Incident notification under NIS2
The NIS2 Directive requires clear procedures to detect incidents. They must then be classified and reported to the competent authority. It also requires internal and external communication flows. These flows must be tested periodically.
Business continuity and resilience
NIS2 calls for business continuity (BCP) and disaster recovery (DRP) plans. Backup management and encryption are key. Access-control policies complete the set. These policies are based on least privilege and multi-factor authentication.
Supply chain in the NIS2 Directive
Finally, the NIS2 Directive covers the assessment of critical suppliers. Cybersecurity contractual clauses are mandatory. Another pillar is control over updates. Continuous supervision of outsourced services completes the block. This supervision includes AI providers and cloud services.
NIS2, DORA and the EU AI Act: the regulatory framework compared
NIS2 does not operate alone: it coexists with two other European regulatory pillars. The DORA Regulation governs the digital operational resilience of the financial sector (credit institutions, investment firms, fund managers, critical ICT providers), and the EU AI Act regulates artificial intelligence systems by risk level. A coherent strategy integrates all three frameworks at once, avoids duplication and takes advantage of synergies between controls.
In practice, the three overlap on risk management, governance, incident notification and the supply chain. If your organisation is a bank, insurer or fund manager, all three apply at once; if you are an industrial or healthcare company, NIS2 and the EU AI Act apply; if you only deploy AI in non-critical sectors, the EU AI Act applies. The practical question isn’t “which one do I comply with” but “how do I build a single management system that covers all three without tripling the work”.
I develop this in depth on my strategic cybersecurity page, where I explain how I map the overlap between frameworks.
How I approach a NIS2 compliance project
In practice, I combine IT project-management discipline, technical cybersecurity knowledge and experience in regulated sectors (banking, healthcare, public administration). The process I follow is organised into five phases.
- Initial diagnosis: identifying the scope of application, mapping critical assets and a GAP analysis against NIS2 requirements.
- Risk analysis: qualitative and quantitative assessment, prioritised by impact and likelihood.
- Cybersecurity master plan: prioritised roadmap with quick wins, structural projects and tracking metrics.
- Implementation: project management under agile methodologies (Scrum or Kanban). It also includes coordinating with suppliers and training staff.
- Mejora continua: periodic reviews, incident drills, internal audits and executive reporting.
Each project is tailored to the organisation’s sector, size and starting point. No two NIS2 compliance plans are alike: what a bank solves with an internal CISO may, in a small industrial company, require a different approach, leaning more on tools and external providers. If you’d like me to assess your specific case, write to me and we’ll look at it together.
Frequently asked questions about NIS2
When does NIS2 come into force?
The transposition deadline was 17 October 2024, but effective application in Spain remains subject to the approval of the transposition law and the implementing regulations that will designate the competent authorities and procedures.
What penalties does NIS2 provide for?
Fines reach up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1.4% of turnover for important entities. NIS2 also provides for the direct liability of members of the management body.
Does NIS2 replace the original NIS directive?
Yes. NIS2 repeals and replaces the original NIS (EU Directive 2016/1148), substantially widens its scope, tightens the required measures and harmonises criteria across member states.
Is it mandatory to appoint a CISO under NIS2?
NIS2 does not literally require a CISO, but it does require management to approve cybersecurity measures and oversee their implementation. In practice, it’s advisable to have an information security officer (in-house or outsourced): it’s the most effective way to demonstrate compliance.
How does NIS2 affect SMEs?
Generally, NIS2 applies to medium-sized and large companies, but an SME can be affected if it provides critical services to an essential entity. It’s wise to monitor the supply chain closely and pass contractual requirements downstream.
Do you need to bring your organisation into line with the NIS2 Directive?
If your organisation falls within the scope of NIS2 — or if you want to get ahead before it arrives — I can help you structure a realistic, prioritised plan aligned with your business objectives. Write to me and let’s talk about your specific case.
Next step
Book a 20-minute conversation
No commitment. You tell me how you are tackling NIS2, I tell you what is missing to evidence it and what I would do in the first weeks. If I am not the right fit, I will say so.