Skip to content
UnifiedONE — Community Protection Intelligence

NIS2 compliance

NIS2 turns cybersecurity from a project into an obligation you have to prove.

NIS2 is the European Union's cybersecurity directive, and it now reaches far more organizations than the law it replaced. This is a plain guide to what NIS2 is, who it applies to, and what it asks of you, followed by how UnifiedONE turns those requirements into protection you can show on demand.

What is NIS2

What is NIS2?

NIS2 is the second Network and Information Security Directive, Directive (EU) 2022/2555. It sets a common cybersecurity baseline across the European Union and replaces the original 2016 NIS Directive with wider scope, stricter requirements, and real accountability for senior management.

The intent is straightforward: raise the level of cyber resilience for the organizations that society depends on. Where the old rules covered a narrow set of operators, NIS2 pulls in whole sectors and holds each organization to a documented standard of risk management, incident reporting, and supply chain security.

Scope

Who does NIS2 apply to?

NIS2 applies to medium and large organizations operating in one of its covered sectors, generally those with at least 50 staff or more than 10 million euro in annual turnover. Smaller organizations can still be caught when they play a critical role, and many are pulled in indirectly as suppliers to an in-scope customer.

The directive sorts organizations into essential entities (sectors such as energy, transport, banking, health, water, digital infrastructure, and public administration) and important entities (including postal services, waste management, chemicals, food, manufacturing, and digital providers). Both must meet the same security duties; the difference is mainly in how strictly they are supervised.

Obligations

What NIS2 requires

NIS2 is built around the risk management measures in Article 21, strict incident reporting duties, and the management accountability set out in Article 20. In practice it comes down to five things you have to do and be able to prove.

Risk management measures

Adopt technical and organizational measures across your networks and information systems: access control, MFA, encryption, patching, backups, and business continuity.

Incident reporting

Report significant incidents on a strict clock: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.

Supply chain security

Assess and manage the cyber risk your suppliers and service providers carry, because an attacker who arrives through a vendor is still your incident to report.

Management accountability

Senior management must approve and oversee the risk measures and can be held personally liable. Cybersecurity becomes a board responsibility, not just an IT task.

Continuous compliance

Keep evidence current. Supervisors can ask at any time, so posture, policies, and incident records have to be ready on demand, not assembled after the request.

Timeline and penalties

Deadlines, and what non-compliance costs

NIS2 entered into force in January 2023, and EU member states had to transpose it into national law by 17 October 2024. The obligations now apply, and national authorities are building out supervision and enforcement.

The penalties are meaningful. Essential entities can face fines up to 10 million euro or 2 percent of global annual turnover, whichever is higher; important entities up to 7 million euro or 1.4 percent. Beyond fines, supervisors can hold management personally accountable, which is why NIS2 has moved from an IT topic to a board one. For organizations in the financial sector, NIS2 sits alongside DORA and its own operational resilience requirements.

The operational model

How UnifiedONE turns NIS2 into continuous compliance

Reading the directive is the easy part. The hard part is proving, on any given day, that your measures are in place and working. UnifiedONE closes that gap.

Assess and harden your posture

Governance assesses your Microsoft environment against best practice, enforces one baseline across every tenant, and catches drift the moment a setting slips.

Report from evidence, on the clock

When a threat is validated, protection is applied and the event is recorded, so the 24 and 72 hour reporting duties start from evidence instead of a scramble.

Evidence on demand

Turn your live configuration into a current view of where you stand on NIS2, DORA, and GDPR, ready for a board, an auditor, or an insurer in minutes.

NIS2 questions, answered

What is NIS2?

NIS2 is Directive (EU) 2022/2555, the European Union's updated cybersecurity law. It replaces the 2016 NIS Directive with wider sector coverage, stricter risk management and incident reporting duties, and direct accountability for senior management.

Who does NIS2 apply to?

It applies to medium and large organizations (generally 50 or more staff, or over 10 million euro turnover) in covered sectors such as energy, transport, health, banking, digital infrastructure, water, public administration, manufacturing, and digital services. Smaller critical providers and many suppliers to in-scope organizations are also caught.

Does NIS2 apply to my company?

If you operate in a covered sector and meet the size thresholds, yes. If you are smaller but supply an essential or important entity, you are likely pulled in through their supply chain duties. When in doubt, a readiness check maps your obligations against your actual environment.

When did NIS2 take effect?

NIS2 entered into force in January 2023, and member states had to transpose it into national law by 17 October 2024. The obligations now apply and are enforced by national authorities.

What are the penalties for non-compliance?

Essential entities can be fined up to 10 million euro or 2 percent of global annual turnover, whichever is higher; important entities up to 7 million euro or 1.4 percent. Management can also be held personally liable.

How is NIS2 different from the original NIS Directive?

NIS2 widens the sectors and organizations in scope, standardizes security and reporting requirements across the EU, adds supply chain and management accountability duties, and raises penalties. It closes the gaps and inconsistencies the first directive left behind.

See where you stand on NIS2, before a regulator asks.

Start with a free readiness check. We map the NIS2 requirements against your real environment and show you the gaps, and the fastest way to close them.