NIS 2
NIS 2: who is in scope and what it demands
The size-cap rule, and its exceptions
Essential vs important
| Essential entities | Important entities | |
|---|---|---|
| Who | Large organisations in Annex I sectors, plus designated providers | Medium organisations in Annex I, and medium and large in Annex II |
| Supervision | Proactive: audits, inspections, information requests at any time | Reactive: after evidence or indication of non-compliance |
| Maximum fines | €10M or 2% of global turnover | €7M or 1.4% of global turnover |
| Management | Approval, oversight, training; personal liability; possible temporary ban from management roles | Approval, oversight, training; personal liability |
The ten minimum measures (Article 21)
- Risk analysis and information system security policies.
- Incident handling.
- Business continuity: backup management, disaster recovery, crisis management.
- Supply chain security, including relationships with direct suppliers and service providers.
- Security in acquisition, development and maintenance, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of the measures.
- Basic cyber hygiene practices and cybersecurity training.
- Cryptography and, where appropriate, encryption.
- Human resources security, access control policies and asset management.
- Multi-factor or continuous authentication, secured communications and secured emergency communication systems.
Incident reporting: 24 hours, 72 hours, one month
Transposition and where you actually comply
NIS 2, answered
We are a SaaS company outside the EU. Does NIS 2 apply?
If you offer in-scope services in the EU, such as cloud computing, managed services or online marketplaces, you are in scope regardless of where you are established, and you must designate an EU representative.
Does ISO 27001 certification satisfy NIS 2?
Not automatically, but it covers most of the Article 21 measures. Member states may recognise certifications; the reporting duties and management obligations still apply separately.
Who is personally liable?
Members of the management body who approve and oversee the measures. For essential entities, authorities can temporarily prohibit individuals from exercising management functions after repeated failures.
How does NIS 2 relate to DORA?
DORA is lex specialis for the financial sector: financial entities covered by DORA follow DORA’s ICT risk rules instead of NIS 2’s equivalent provisions.