Skip to main content
NIS2

What Companies Need to Know About the NIS2 Directive

Why NIS2 matters now: Cyberattacks on companies, public authorities and critical infrastructures are increasing in number and sophistication. From data theft to ransomware and supply chain attacks – NIS2 raises the bar for security and risk management across Europe.

Srdan Manasijevic

Srdan Manasijevic

CEO

What Companies Need to Know About the NIS2 Directive

Why NIS2 Matters Right Now

Cyberattacks on companies, public institutions and critical infrastructures are increasing in both number and sophistication. Whether it is data theft, ransomware extortion or targeted attacks on supply systems – the threat landscape is real and affects organisations of all sizes. Against this backdrop, the European Union has created a new legal framework with the NIS2 Directive (Network and Information Security 2) to significantly strengthen cyber resilience in Europe.

The directive not only expands the scope of its predecessor (NIS1), but also tightens requirements for security measures, reporting obligations and risk management. For many organisations this means: action required. The NIS2 requirements must be transposed into national law by October 2024 at the latest – and they affect far more sectors and companies than before.

What Is the NIS2 Directive? The NIS2 Directive is the revised version of the original NIS Directive from 2016 and forms the new European legal framework for cybersecurity in companies and public institutions. It entered into force in January 2023 and must be transposed into national law by the EU Member States by 17 October 2024.

The aim of NIS2 is to ensure a high common level of security for network and information systems throughout the EU. The directive is a response to increasing digital connectivity and the growing dependence on IT systems in almost all areas of life and the economy.

Compared to the original NIS Directive, NIS2 goes significantly further:

  • It extends the scope to many more sectors and organisations.

  • It specifies security requirements, for example in risk management, supply chains and incident response.

  • It introduces stricter reporting obligations and significantly higher sanctions for non-compliance.

With NIS2, the EU wants to ensure that digital infrastructures and services continue to function reliably even in times of crisis – and that organisations do not only react to cyber risks but take proactive responsibility.

Who Is Affected? The NIS2 Directive covers significantly more organisations than its predecessor. While the original NIS Directive mainly addressed operators of critical infrastructures, NIS2 substantially broadens the scope.

Whether an organisation falls under NIS2 depends essentially on its sector, size and economic importance. As a rule of thumb, companies with more than 50 employees or an annual turnover of more than EUR 10 million are in scope – provided they operate in one of the relevant sectors.

Examples of affected sectors:

  • Energy, water, transport, healthcare, finance & insurance

  • Digital infrastructure (e.g. data centres, cloud providers)

  • Postal and courier services

  • Food production and distribution

  • Manufacture of certain critical goods such as medical devices or ICT products

In addition, some medium-sized companies that are part of a critical supply chain or are particularly important for public security can also fall under the directive.

If you are unsure whether your organisation is affected, you should clarify this at an early stage – for example using the online self-assessment tool announced by the German BSI. NIS2 not only widens the scope, it also significantly raises the level of responsibility.

What Obligations Arise for Companies? With the NIS2 Directive, cybersecurity requirements for organisations increase noticeably. The directive does not just state that appropriate technical and organisational measures must be taken – it also specifies what this means in practice. Going forward, organisations must establish systematic risk management and continuously review and improve their security measures.

Key obligations include:

  • Comprehensive security measures: Organisations must implement suitable safeguards to minimise risks to their network and information systems. This includes, for example, access controls, encryption, system hardening and regular updates.

  • Securing the supply chain: The security of IT service providers and suppliers is explicitly in focus. Organisations must also take their protection measures into account.

  • Incident management and reporting: Security incidents must be reported to the competent authorities (e.g. BSI) within 24 hours. Detailed information must be provided within 72 hours.

  • Training and awareness: Employees must be trained regularly – especially on cyber threats, secure behaviour and reporting channels.

  • Business continuity and backup: Organisations are expected to develop and regularly test plans to maintain operations in the event of IT disruptions.

  • Authentication and access control: The use of multi-factor authentication (MFA) and clear role and rights concepts becomes standard.

These obligations are not just theoretical. They must be implemented in a way that is verifiable and auditable. NIS2 is therefore not about isolated measures, but about a long-term security culture embedded in the organisation. Anyone who has neglected this so far should act now at the latest.

What Are the Consequences of Non-Compliance? The NIS2 Directive provides for much stricter sanctions than its predecessor. Organisations that fail to meet their obligations face significant legal and financial consequences. The objective is to enforce compliance and to penalise negligent behaviour.

Possible consequences of non-compliance:

  • High fines:

    • For “essential entities”: up to EUR 10 million or 2% of worldwide annual turnover – whichever is higher.

    • For “important entities”: up to EUR 7 million or 1.4% of worldwide annual turnover.

  • Liability at management level: Top management is placed under greater responsibility. In cases of gross negligence, personal liability may be an issue.

  • Supervisory measures: Authorities can order remedial actions – for example to improve the security posture or temporarily restrict IT systems.

  • Reputational damage: Security incidents and sanctions are often made public and can lead to a loss of trust among customers, partners and investors.

Importantly, NIS2 significantly increases the impact on medium-sized businesses as well. Non-compliance is no longer a “manageable risk”. Meeting NIS2 requirements becomes a core business risk that must be actively managed.

How Can Organisations Prepare? Implementing NIS2 is not a one-off project but a continuous process. It is therefore essential to start preparing early – especially as national legislators must transpose the directive into domestic law by October 2024. Those who act now gain valuable time and avoid last-minute panic.

Recommended first steps:

  • Check if you are in scope: Clarify whether your organisation falls directly under NIS2 or indirectly through critical supply chains.

  • Perform a gap and status analysis: Which security measures are already in place? Where are there gaps in processes, technology and organisation?

  • Establish risk management: Systematic risk management is at the heart of NIS2 compliance and requires structured processes and documentation.

  • Clarify responsibilities: Who is responsible for cybersecurity, incident reporting and regulatory compliance in your organisation?

  • Modernise security concepts: Introduce or further develop an Information Security Management System (ISMS), for example according to ISO 27001 or BSI IT-Grundschutz.

  • Raise employee awareness: Regular training and awareness measures are mandatory and strengthen the organisation’s security culture.

  • Bring in external support: Many organisations benefit from working early with specialised consultants or ISMS tool providers.

These measures lay the foundation for a sustainable and auditable cybersecurity strategy that not only meets legal requirements but also protects the business effectively.

Act Now to Strengthen Cybersecurity The NIS2 Directive is more than “just another regulation” – it is a clear signal that cybersecurity is becoming a mandatory core task for organisations. Those in scope must act. Those currently out of scope still benefit from reviewing and improving their structures now.

Security is not a static state but an ongoing process. Organisations that start implementation early achieve more than just compliance: they build trust – internally and externally. At the same time, they strengthen their resilience against cyberattacks and secure business continuity in an increasingly digital world.

A practical and effective approach is to introduce an Information Security Management System (ISMS). For example, with a specialised solution such as the fuentis Suite. This tool helps organisations implement the requirements from NIS2, ISO 27001 or BSI IT-Grundschutz in a structured, transparent and efficient way. From risk assessment and control tracking to audit preparation, the fuentis Suite provides a central platform for all security-related tasks – without Excel chaos.

NIS2 FAQ

When will the NIS2 Directive apply in Germany? The NIS2 Directive must be transposed into German law by 17 October 2024 at the latest. From that point on, the new obligations apply to affected organisations.

How can I find out whether my organisation is affected? Whether your organisation falls under NIS2 depends on its sector, size and importance. The categories “essential” and “important” entities provide an initial indication. The German BSI also plans to provide an online self-assessment tool.

What happens if I do not implement NIS2? Non-compliance can result in fines of up to EUR 10 million or 2% of worldwide annual turnover – whichever is higher. Management can also be held personally accountable.

Do I need an ISMS to comply with NIS2? An ISMS is not a formal legal requirement, but in practice it is the most effective way to implement NIS2 obligations in a traceable and auditable manner.

How does a tool like the fuentis Suite support implementation? The fuentis Suite helps organisations manage all NIS2-related activities – such as risk management, control tracking, documentation and audits – centrally and efficiently. This makes implementation not only compliant, but also practical in day-to-day operations.

Srdan Manasijevic

Srdan Manasijevic

CEO

Expert in information security, data protection and risk management with extensive experience advising enterprises and public-sector organizations. Specialized in ISO 27001, BSI and advanced risk methodologies.

From reading to doing: your ISMS with fuentis

ISO 27001, BSI IT-Grundschutz, TISAX and NIS2 in one platform – the free/Basic plan is €0 for 12 months.