top of page

NIS2 Implementation Has Begun – Are You Ready?

WHAT IS NIS2
The NIS2 Directive, formally known as the Directive on security of network and information systems, is a European legislation aimed at improving the overall level of cybersecurity in the EU.
This directive builds upon the original NIS Directive and introduces more rigorous security requirements for EU member states, critical infrastructure sectors, and digital service providers.
TARGET OF NIS2
The NIS2 Directive aims to bolster cybersecurity resilience across the European Union by establishing clear compliance frameworks for the organizations in scope and enforces significant penalties for non-compliance, thereby emphasizing the importance of adhering to these enhanced security standards.
The central reform relates to Article 21 of NIS2, which mandates reporting on risk management and specifies minimum cybersecurity measures that must be implemented.
Through these measures, NIS2 seeks to create a more secure digital environment, ensuring that both public and private entities are better equipped to mitigate cyber threats and protect essential services.
CRITICAL SECTORS
Energy​
Transport
Banking
Digital Infra
Healthcare
Space
Water Treatment
Public Administration
HIGH-RISK SECTORS
Postal & Courier Services
Critical Product Manufacturing
Digital Services
Waste Management
Food Production & Distribution
Research Organizations
TIME FOR ACTION IS HERE
Member states were required to create or adjust their cybersecurity laws and frameworks in accordance with the NIS2 Directive by October 17th, 2024. Although some countries are delayed from this deadline, the entities in scope should, at the latest now, take proactive steps to understand their obligations and align their cybersecurity practices accordingly. As an example, see proposed legislation, approved on March 11th, 2025, for implementing NIS2 in Finland.
NIS2 TIMELINE
December 2020
The NIS2 Directive was adopted by the EU
Implementation status varies by member states
1. Adopted by deadline in certain states
​2. In progress (e.g., legislation proposed but not yet approved)
3. Delayed with unclear implementation timelines
1
2
3
0
October 17, 2024
The Transposition deadline:
-
Member states were required to incorporate it into national law
SANCTIONS FOR NON-COMPLIANCE
Penalties under the directive may include fines of up to 10 million euros or 2% of the organization's total global annual turnover, whichever is higher.
The amount of the fine depends on several factors, including the severity and duration of non-compliance, the harm caused to individuals or entities, the organization's cooperation during the investigation, and its compliance history. In addition to financial penalties, organizations may also face non-monetary sanctions such as operational restrictions, mandatory compliance measures, or exclusion from certain contracts.
1. Penalties for Non-Compliance
NIS2 introduces a range of sanctions for organizations that fail to comply with the directive. These sanctions can vary significantly depending on the severity of the non-compliance and the country's specific approach to enforcement.
2. Fines
Member states may impose administrative fines on entities that do not meet the NIS2 requirements. Fines may be substantial, intended to serve as a deterrent against non-compliance.
3. Regulatory Action
In addition to financial penalties, regulatory authorities may take other actions, such as issuing warnings, conducting audits, or imposing operational restrictions on non-compliant organizations.
4. Notification Obligations
Organizations subject to NIS2 are required to report significant cybersecurity incidents to their national authorities in a timely manner. Failing to report these incidents may also lead to sanctions.
5. Sector-Specific Regulations
Depending on the sector (e.g., energy, transport, healthcare), additional penalties may apply due to specific national laws aligned with the NIS2 provisions.
Due to the severe nature of the potential consequences, preparing for compliance should be a strategic priority for top management who are also held accountable for meeting NIS2 requirements.
Ready for NIS2 Directive? Contact Us to Ensure Your Compliance.
bottom of page