Not Sure If NIS2 Applies to You?
Start with an applicability assessment — sector, size and service criticality all affect whether and how NIS2 applies to your organization.
The NIS2 Directive significantly expands EU cybersecurity obligations to over 160,000 entities across essential and important sectors, with national transposition and compliance obligations culminating around an October 2026 deadline. Cyberox helps organizations determine applicability and build toward compliance remotely.
Last reviewed: September 2026. Verify current requirements against the official regulator before acting — sources linked below.
NIS2 covers medium and large entities across 18 essential and important sectors including energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration and space — plus important-sector categories like manufacturing, food and digital providers.
National transposition into EU member-state law has proceeded unevenly since the original October 2024 deadline; by 2026, transition periods for many in-scope sectors have expired, with compliance obligations culminating around October 2026 across most member states.
In-scope entities must implement risk-management measures (policies on risk analysis, incident handling, business continuity, supply-chain security, and more), report significant incidents within defined timeframes, and ensure management-body accountability for cybersecurity oversight.
NIS2 places explicit emphasis on supply-chain and third-party risk — in-scope entities must assess and manage cybersecurity risk in their direct suppliers and service providers, not just their own environment.
NIS2 introduces personal accountability for management bodies, who must approve risk-management measures and can face liability for compliance failures — a material shift from earlier, more technical-only frameworks.
NIS2 requirements are transposed into each member state's national law with some local variation. Confirm your specific obligations against the relevant national transposition law and consult qualified EU legal counsel before finalizing a compliance program.
We start every NIS2 engagement by determining whether — and how — the directive applies to you, since scope, sector classification and entity size all affect your specific obligations.
The EU's parallel financial-sector resilience regulation — relevant if you're a financial entity or critical ICT provider.
Learn moreRelated EU regulatory obligations for data protection, product security and AI governance.
Learn moreISMS certification that provides a strong operational foundation for NIS2 risk-management requirements.
Learn moreStart with an applicability assessment — sector, size and service criticality all affect whether and how NIS2 applies to your organization.