NIS2 makes cyber security a boardroom liability across 18 sectors
Europe's expanded cyber security directive brings tens of thousands of organisations into regulation for the first time — with management bodies personally accountable and penalties to match GDPR's seriousness.
- Transposition
- 17 October 2024 into member state law
- Who's in scope
- Essential & important entities across 18 sectors
- Reporting clock
- 24h warning · 72h notification · 1 month final
- Maximum fines
- €10m or 2% of global turnover
The highlights
NIS2 replaces the original NIS Directive with far broader scope, harmonised supervision and real teeth. If you sell into or operate in the EU, assume you need an answer.
Dramatically wider scopeArt. 2
Energy, transport, health, digital infrastructure, manufacturing, food, ICT service management and more. Size-cap rules pull in most medium and large entities automatically — no designation letter required.
Management accountabilityArt. 20
Management bodies must approve cyber risk measures, oversee implementation and undergo training. Individual executives can be held liable, and suspension of management duties is on the sanctions menu.
Baseline security measuresArt. 21
Ten mandated measure areas: risk analysis, incident handling, business continuity, supply chain security, secure development, cryptography, access control, MFA and more — an ISO 27001-shaped list, not coincidentally.
Three-stage incident reportingArt. 23
An early warning within 24 hours, a full notification within 72 hours, and a final report within one month. Significant incidents can also trigger a duty to notify affected service recipients.
Supply chain pressureArt. 21(2)(d)
In-scope entities must assess the security of their direct suppliers — meaning NIS2 requirements cascade contractually to companies nowhere near the directive's own scope. UK suppliers to EU customers: this is how it reaches you.

Where to start
- Determine scope entity by entity — group structures matter. Classify each EU legal entity as essential, important or out of scope — and identify your member state regulators.
- Gap-assess against Article 21 — the ten measure areas map cleanly onto ISO 27001:2022 controls, so an existing ISMS gets you most of the way there.
- Rehearse the 24-hour clock — your incident process needs a decision-maker, a template and a regulator contact route that works at 2am on a Sunday.
- Get the board formally engaged — minuted approval of the risk management measures and evidence of director training are explicit requirements, not good practice.
In scope, supplying someone who is, or just not sure?
Sentinel42 provides NIS2 applicability assessments, Article 21 gap analyses and executive training programmes — delivered across the UK and EU.