A clear starting point for applicability, governance, incident processes, and supplier security.
Confirm applicability with the right facts
The EU’s NIS2 Directive applies to categories of essential and important entities. Sector, entity size, establishment, and national implementing measures all matter. Multinational groups should examine which legal entities and services fall within scope, and where responsibilities sit.
Start with a concise applicability record that lists assumptions, legal entities, sectors, relevant countries, and decisions requiring counsel. Avoid treating a broad sector label as a final legal conclusion. The European Commission provides a central overview, while national law governs local obligations.
Give management a decision role
NIS2 places emphasis on governance and cybersecurity risk management. Boards and senior management need a view of material cyber risks, the measures being taken, and the gaps accepted or funded. A dashboard that lists technical tasks without business impact will not support that role.
Map the existing security program against the Directive’s risk management areas. Reuse effective ISO 27001 or other controls where they fit, then close gaps around topics such as incident handling, business continuity, supply chain security, and secure development.
Rehearse incident escalation before an event
Reporting obligations are time sensitive and depend on whether an incident meets relevant thresholds. The practical work is to define detection, triage, severity assessment, ownership, legal review, and the route to competent authorities. Test the decision path with scenarios that cross operations, communications, legal, and leadership.
Preserve the facts used to make each reporting decision. In a fast-moving event, a clear decision log is as important as a polished incident playbook.
Bring suppliers into the operating model
Critical service providers and technology dependencies often shape the organization’s exposure. Identify which suppliers support in-scope services, evaluate their security commitments, and define escalation when a supplier incident affects operations.
NIS2 readiness is ongoing. National implementations and EU-level developments may change details, so legal interpretation and program maintenance should remain connected.
Put it into practice
- Map legal entities, services, sectors, and countries before concluding applicability.
- Assign an executive owner to the risk management and reporting program.
- Test the incident classification and escalation path with a realistic scenario.
- Identify suppliers that support in-scope services and how their incidents reach your team.
Primary sources
Normstone resources are general information, not legal advice or an independent assessment.