FAQ
NIS2, answered
Short, practical answers to the questions security and compliance teams ask most often.
Is NIS2 a law I have to follow directly?
NIS2 is an EU directive, so it takes legal effect through each member state's national transposition law. Your concrete obligations come from that national law — which must meet, and may go beyond, the directive's minimum standard.
How is NIS2 different from the original NIS Directive?
NIS2 widens the sectors and entities in scope, standardises the risk-management and reporting requirements, adds strict incident-reporting deadlines, introduces management accountability, and raises penalties significantly.
We're a small company — are we exempt?
Generally the rules target medium and large entities (50 or more staff, or above €10 million turnover or balance sheet) in covered sectors. But some providers are in scope regardless of size, and you may still be affected as part of a larger entity’s supply chain.
What counts as a "significant" incident?
One that causes or could cause severe operational disruption or financial loss to the entity, or affects others through considerable material or non-material damage. National guidance adds specific thresholds.
Can directors really be held personally liable?
Yes. Management bodies must approve and oversee the cybersecurity measures and can be held liable for breaches. Serious cases can lead to temporary bans from management functions.
Where do I report an incident?
To your national CSIRT or the competent authority designated in your country's transposition law, following the 24-hour, 72-hour and one-month reporting stages.
Still have questions about your obligations?
A quick readiness check is the fastest way to see where you stand.
Start free assessment →