Frameworks / EU
NIS2
NIS2 is the EU directive that turns cybersecurity into a regulated duty for entire sectors of the economy. Uniquely, it makes senior management personally accountable for the organisation's cyber risk-management measures.
What it requires
NIS2 replaced the original NIS Directive and had a transposition deadline of 17 October 2024, meaning the binding obligations arrive through each member state's national law. It divides in-scope organisations into "essential" and "important" entities, drawn from sectors listed in Annexes I and II, generally applying to medium-sized and larger entities, with supervision heavier for essential entities. Article 21 sets out the required cyber risk-management measures, including risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in the acquisition, development and maintenance of systems including vulnerability handling and disclosure, policies to assess the effectiveness of the measures, basic cyber hygiene and training, cryptography and encryption, human resources security, access control and asset management, and the use of multi-factor authentication and secured communications. Article 23 sets a staged reporting timetable for significant incidents: an early warning to the CSIRT or competent authority within 24 hours, an incident notification within 72 hours, and a final report within one month. Management bodies must approve the cyber risk-management measures, oversee their implementation, and can be held liable; they are also required to undergo training. Maximum administrative fines are set at up to €10 million or 2% of total worldwide annual turnover (whichever is higher) for essential entities, and up to €7 million or 1.4% for important entities.
NIS2 covers sectors including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space (Annex I, essential), plus postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers and research (Annex II, important). Size generally matters: the medium-size threshold applies as a rule of thumb, with some entity types in scope regardless. Israeli companies are not directly regulated, but reach NIS2 through supply chain security: an in-scope European entity is obliged to manage the security of its suppliers, and so it pushes the requirements down the chain contractually. If you sell software or services into European critical sectors, NIS2 arrives at your door as a supplier questionnaire with teeth.
The controls people actually fail
- The organisation never determined whether it is in scope, because scope depends on national transposition law and sector annexes. "We did not think it applied to us" is not a defence.
- Supply chain security under Article 21 is asserted but not operated: no supplier inventory, no security requirements in contracts, no assessment of the suppliers that matter most.
- The 24-hour early warning cannot be met because there is no on-call path from detection to a decision that an incident is significant.
- Management-body accountability is treated as a formality: the board signs a policy but receives no risk reporting, has had no training, and cannot demonstrate oversight.
- Business continuity and crisis management plans exist but have never been exercised, so recovery objectives are aspirational and untested.
- Vulnerability handling has no disclosure route and no SLA: vulnerabilities are found, ticketed and left, with no evidence of risk-based remediation timelines being met.
- Multi-factor authentication is deployed for staff but not for administrative access, remote access or third-party contractor accounts: the exact places it is required.
Does NIS2 apply to companies outside the EU?
NIS2 directly regulates entities established in, or providing certain services in, the EU. Non-EU companies (including Israeli ones) are most often affected indirectly but forcefully: Article 21 requires in-scope entities to manage the security of their supply chain and of their direct suppliers, so European essential and important entities pass the requirements into their vendor contracts. Certain digital service providers with EU customers may also fall in scope directly through the directive's jurisdiction rules and must designate a representative in the EU: whether you do depends on the service and on the national transposition, which is a question worth answering explicitly rather than assuming.
What are the NIS2 incident reporting deadlines?
Three stages under Article 23. An early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, indicating whether it is suspected to be caused by unlawful or malicious acts and whether it could have cross-border impact. An incident notification with an initial assessment, including severity, impact and indicators of compromise, within 72 hours. A final report within one month, covering a detailed description, the type of threat and root cause, mitigation measures applied, and any cross-border impact.
What is the difference between "essential" and "important" entities under NIS2?
Both must meet the same Article 21 cyber risk-management requirements and the same reporting obligations. The difference is supervision and penalty. Essential entities (Annex I sectors such as energy, transport, banking, health, digital infrastructure and public administration) are subject to proactive, ex ante supervision (regulators may inspect without cause) and face maximum fines of up to €10 million or 2% of global annual turnover. Important entities (Annex II sectors including postal services, waste, chemicals, food and manufacturing) are subject to ex post supervision, acting on evidence of a problem, with maximum fines of up to €7 million or 1.4%.
Can NIS2 hold management personally liable?
Yes. NIS2 requires management bodies to approve the cyber risk-management measures, to oversee their implementation, and to follow cybersecurity training, and it provides that they can be held liable for infringements of those duties. National transpositions implement this differently, and in some member states supervisory authorities can temporarily prohibit an individual from exercising managerial functions in an essential entity in cases of serious, persistent non-compliance. In practice this is what moves NIS2 out of the IT department and onto the board agenda.