Not legal advice. We are engineers, not lawyers. This is a practical summary of Directive (EU) 2022/2555 written to help you work out whether you need to talk to someone qualified. The obligations that bind you are in your own country's implementing law, not in the directive.
The bit most people get wrong
The single most common thing we hear is "NIS2 is for critical infrastructure, we are too small". That belief is doing real damage, because the size threshold is much lower than people assume.
NIS2 generally applies from the medium-sized enterprise level upward within the sectors it lists. In EU terms that means roughly 50 or more employees, or annual turnover above €10 million. Not 250. Not 1,000.
A 60-person company in a listed sector is squarely in scope. So is a 40-person one turning over €12 million.
The sectors are set out in two annexes. Annex I covers what the directive calls high-criticality sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, managed ICT services provided business-to-business, public administration and space. Annex II covers other critical sectors including postal and courier services, waste management, chemicals, food production and distribution, several categories of manufacturing, research organisations, and digital providers such as online marketplaces, search engines and social platforms.
Two things worth noting about that list. First, "managed ICT service providers" is in Annex I — if you run IT or infrastructure for other businesses, you are in a high-criticality sector regardless of how modest that feels from the inside. Second, food and manufacturing are broader than most people expect, which catches a great many companies who have never considered themselves anything to do with cybersecurity regulation.
Some entities are in scope regardless of size: DNS service providers, TLD name registries, trust service providers, providers of public electronic communications networks or services, and any organisation identified as the sole provider of a critical service in its member state.
Essential or important
In-scope entities are split into two classes, and the difference is mostly about supervision and penalties rather than the security measures themselves.
- Essential entities — broadly, large organisations in Annex I sectors, plus the size-independent categories above. They face proactive supervision: authorities can inspect and audit without a reason to suspect anything is wrong.
- Important entities — most medium-sized organisations, and Annex II entities. Supervision is reactive: authorities act when they have evidence of non-compliance, typically after an incident.
A 60-person company is, in the ordinary case, an important entity. That is meaningfully better than being essential, and it is nothing like being out of scope.
The reporting clock
This is the part that has direct operational consequences, and it is the part we care most about, because it turns a security obligation into an on-call design problem.
For a significant incident — broadly, one that causes or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage to others — three deadlines run from the moment you become aware of it:
+72 h incident notification: assessment, severity, impact, indicators
+1 month final report: root cause, mitigations applied, cross-border effects
An intermediate report can also be requested at any point, and where an incident is ongoing at the one-month mark you file a progress report instead and the final one when it closes.
Read the first line again, because it is the one that matters at three in the morning: twenty-four hours from becoming aware. Not from deciding it was serious. Not from finishing the investigation. Not from the Monday morning meeting.
If you find out at 03:00 on a Saturday, your early warning is due by 03:00 on Sunday. There is no working-hours version of this clock.
Which produces an unglamorous but genuinely urgent question that has nothing to do with firewalls: who, specifically, is capable of filing that notification on a Saturday night, and do they know it is their job? In most 60-person companies the honest answer is that nobody has been told, and the person who would have to do it does not know the portal exists.
What you actually have to have in place
Article 21 lists the risk-management measures. Stripped of the legal phrasing, in-scope entities need to be able to show they have addressed:
- Risk analysis and information system security policies
- Incident handling
- Business continuity: backup management, disaster recovery, crisis management
- Supply chain security, including the security of your direct suppliers
- Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure
- Policies to assess whether the measures are actually effective
- Basic cyber hygiene practices and security training
- Policies on cryptography and encryption
- Human resources security, access control and asset management
- Multi-factor authentication, secured voice, video and text communications, and secured emergency communications
Most competent 60-person engineering organisations already do a decent proportion of this. What they almost never have is evidence — the written policy, the dated review, the record showing the backup restore was tested in March and by whom. Under NIS2 the doing and the documenting are equally required, and only one of them is visible to a supervisor.
The one that catches people out
Article 20 makes management bodies responsible for approving the risk-management measures and overseeing their implementation, and they can be held liable for failures. They are also required to undergo training, and encouraged to offer similar training to staff.
This is a genuine change of character. Cybersecurity stops being something delegated downward and becomes a board-level duty with names attached. For a small company that usually means a founder or two who have never signed off on a security policy in their lives and are about to have to.
Penalties, briefly
Because someone always asks, and because it is the number that unlocks the budget:
- Essential entities — a maximum of at least €10 million or 2% of total worldwide annual turnover for the preceding financial year, whichever is higher.
- Important entities — a maximum of at least €7 million or 1.4%, whichever is higher.
There are also non-financial powers that tend to concentrate minds more effectively than fines: authorities can order an entity to make an infringement public, and for essential entities they can temporarily suspend individuals from managerial functions.
In practice, a first-time important entity that reported properly and acted in good faith is not the target here. The exposure is for organisations that were told, did nothing, and then failed to report.
If you are out of scope, read this bit anyway
The supply chain provisions mean that in-scope entities must manage the security of their direct suppliers. They discharge that duty the way companies always have: by pushing requirements down through contracts.
So if you sell software or services to anyone in a listed sector, NIS2 is going to reach you as a questionnaire, a contract clause and an incident-notification obligation to your customer — often with a tighter deadline than the regulator's, because your customer has to file within 24 hours and needs to hear from you well before that.
We are now seeing supplier contracts that require notification to the customer within four hours of an incident being detected. That is not a policy problem. That is an on-call problem, and it lands on whoever is holding the phone.
National implementation
NIS2 is a directive, so it binds you through your own country's law rather than directly. Member states were required to transpose it by 17 October 2024, and a large number missed that deadline — this has been unusually messy across the EU, so the state of play in your jurisdiction may differ from your neighbour's.
In Poland, implementation runs through an amendment to the Act on the National Cybersecurity System (ustawa o krajowym systemie cyberbezpieczeństwa). Before acting on anything above, check the current status and text of your national act — the deadlines and sector definitions in the directive are the floor, and national law can be stricter or add sectors.
The short version
- Check the annexes properly against what you actually do. Do not rely on a summary blog post, including this one.
- If you are in scope, register with your competent authority. Some categories had a registration deadline as early as January 2025.
- Name the person who files the 24-hour early warning, and make sure they are reachable at 03:00 on a Saturday.
- Write down what you already do. Most of the gap is evidence, not practice.
- Get your management body trained and on record as having approved the measures.
- Read your customer contracts. The four-hour clauses are already circulating.
Point three is the one we can help with, and it is the one that most often has nobody's name against it.