Back to blogCompliance

How to prepare for the arrival of NIS2?

NRNicolas Renard·March 9, 2026· 10 min read

NIS2, adopted by the European Parliament and the Council in December 2022, replaces and extends the 2016 NIS directive, with a much broader scope: sectors previously out of scope (healthcare, waste management, manufacturing, digital services) now fall within it as soon as a company exceeds certain size thresholds. In France, ANSSI estimates that around 15,000 entities will be covered, compared with roughly 500 under the previous NIS1 regime — a thirtyfold expansion of scope. The directive was due to be transposed into national law by 17 October 2024 at the latest; France, like several other member states, missed that deadline, which led the European Commission to open an infringement procedure in late November 2024. That does not exempt covered organizations from preparing: the national transposition timeline does not change the level of cyber risk they face.

The directive imposes governance obligations (management's involvement in cyber risk management, with personal liability for executives), risk management obligations (proportionate technical and organizational measures), incident management obligations (24 hour notification for significant incidents) and business continuity obligations.

Blank whiteboard with markers ready to use, symbolizing methodical preparation for the NIS2 directive

Essential or important entity: a distinction that changes everything

NIS2 distinguishes two categories of organizations, with similar obligations but a different supervision and penalty regime. Essential entities (EE) — large companies in highly critical sectors such as energy, healthcare or transport — are subject to proactive supervision by ANSSI. Important entities (EI), covering a broader sectoral scope, are subject to reactive supervision, triggered after an incident or a report.

NIS2 Diagnostic·See a diagnostic preview

CriterionEssential entity (EE)Important entity (EI)
SupervisionProactive (regular checks)Reactive (after an incident or report)
Maximum financial penalty€10M or 2% of global turnover, whichever is higher€7M or 1.4% of global turnover, whichever is higher
Executive liabilityPersonal liabilityPersonal liability
Example sectorsEnergy, healthcare, transport, digital infrastructurePostal services, waste management, manufacturing, digital services

The ten domains of minimum measures

  • Risk analysis and information system security policy.
  • Incident handling (prevention, detection, response).
  • Business continuity and crisis management, including backup management.
  • Supply chain security, including relationships with each direct supplier.
  • Security in the acquisition, development and maintenance of systems, including vulnerability handling.
  • Policies and procedures to assess the effectiveness of risk management measures.
  • Basic cyber hygiene practices and cybersecurity training.
  • Policies and procedures regarding the use of cryptography and, where relevant, encryption.
  • Human resources security, access control policy and asset management.
  • Use of multi factor or continuous authentication solutions, secured communications and secured emergency communications.

Steps to assess your readiness

  1. Determine whether the organization falls within NIS2 scope, and if so, as an essential or important entity.
  2. Identify the competent authority and the associated reporting obligations (ANSSI in France).
  3. Map the gap between current practices and the ten domains of minimum measures.
  4. Prioritize corrective actions by risk and feasibility, starting with incident management and strong authentication.
  5. Formalize governance: who within management holds responsibility for NIS2 compliance.
  6. Document the approach to be able to respond to a review, even without a fully settled enforcement doctrine.

To assess its readiness, an organization must first determine whether it falls within scope, as an essential or important entity, a qualification that ANSSI, the competent authority in France, is clarifying as implementing texts settle. How this connects to existing efforts matters too: a company already certified to ISO 27001 or with a formalized ISSP has a solid starting base, since most of NIS2's ten minimum domains overlap with controls already covered by those frameworks.

Common mistakes to avoid

  • Waiting for final transposition into national law before acting, while the underlying cyber risk does not wait.
  • Underestimating the size criterion: many SMEs that act as suppliers to an essential or important entity will be indirectly covered through supply chain security requirements.
  • Treating NIS2 as a purely technical topic when personal executive liability makes it, above all, a governance issue.
  • Starting from scratch rather than building on existing ISO 27001 or ISSP work.

Unlike ISO 27001, NIS2 is a legal obligation, not a voluntary certification. The penalty regime, like the exact scope of entities concerned, is still being clarified in several countries: it is worth measuring the gap against these requirements now, rather than waiting for a settled enforcement doctrine before paying attention.

Ready to assess your organization?

Try for free