Entexia | Intelligent ecosystem
← Back to blog
Cybersecurity

NIS2 Directive Explained: What Every Business Must Know About Cybersecurity Compliance

The EU NIS2 directive tightened cybersecurity requirements across 18 sectors from October 2024. Learn which businesses are affected and what compliance steps to take now.

E
Entexia Team
·
·
8 min

What Is NIS2 and Which Businesses Does It Cover

NIS2 (the Network and Information Security Directive 2) is the EU's updated cybersecurity law, replacing the original NIS Directive from 2016. Member states were required to transpose it into national law by October 2024. The directive significantly expands the scope of covered sectors compared to its predecessor - from energy, transport, and healthcare to digital infrastructure, public administration, food production, and postal services.

Businesses fall into two categories: essential entities, which face stricter requirements and proactive supervision, and important entities, subject to lighter-touch regulation. The general threshold for inclusion is 50 or more employees or annual revenue exceeding 10 million EUR in a regulated sector. Some categories, such as DNS service providers and top-level domain registries, are covered regardless of size. Companies in the supply chain of an essential entity may also find themselves subject to requirements through contractual obligations.

What NIS2 Requires Your Business to Do

NIS2 mandates a risk-based approach to cybersecurity rather than prescribing specific technical measures. The required elements include: cybersecurity risk management policies covering network security, incident handling, and business continuity; supply chain security measures and supplier risk assessment; access management and multi-factor authentication; encryption of data at rest and in transit; employee security training and awareness; and incident reporting within 24 hours (initial notification) and 72 hours (interim report) to the competent national authority.

A significant feature of NIS2 is personal liability for senior management. Directors and board members are personally responsible for ensuring the organisation complies. This means cybersecurity can no longer be treated as a purely technical matter delegated to the IT team - the C-suite must be actively involved in risk governance and sign off on the cybersecurity programme.

What Are the Penalties for NIS2 Non-Compliance

NIS2 penalties are substantially higher than those under NIS1. Essential entities face fines of up to 10 million EUR or 2% of total global annual turnover, whichever is higher. Important entities face fines of up to 7 million EUR or 1.4% of turnover. In addition to financial penalties, NIS2 allows competent authorities to impose temporary bans on individuals from exercising management roles.

National authorities have powers to conduct announced and unannounced inspections, request evidence of implemented measures, and mandate independent security audits. Businesses that have taken no action are at significantly higher risk of enforcement action. The first wave of enforcement is expected to focus on essential entities in energy and digital infrastructure, but important entities should not delay their compliance programmes.

A Practical Starting Point for SME Cybersecurity Compliance

For most SMEs in regulated sectors, the recommended starting point is a risk assessment: inventory your key systems, data assets, and third-party connections, then identify the most significant vulnerabilities. From this baseline, build a prioritised action plan - starting with the highest-risk, easiest-to-implement controls such as multi-factor authentication, endpoint encryption, and documented incident response procedures.

Entexia includes a compliance and cybersecurity module that supports asset inventory, policy management, incident logging, and report generation for regulatory submissions. It is designed for businesses without a dedicated CISO who still need to demonstrate compliance to customers, auditors, and national authorities. Try it free for 7 days and see how it fits your compliance programme.

Try Entexia Compliance free for 7 days. NIS2 and GDPR tools included.

Start free →