Directive (EU) 2022/2555 raises the bar for cybersecurity across essential and important entities in 18 sectors, with management bodies personally accountable. We take you from readiness assessment to full implementation, including the 24 hour reporting clock.
The NIS2 Directive, Directive (EU) 2022/2555, is the EU's updated cybersecurity regime for essential and important entities across 18 sectors. It mandates risk management measures under Article 21, including incident handling, business continuity and supply chain security, makes management bodies accountable for oversight and training under Article 20, and imposes staged incident reporting under Article 23: an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month.
The directive entered into force in January 2023, with member state transposition due by 17 October 2024, and carries supervisory teeth: audits, binding instructions, and fines of up to EUR 10 million or 2 percent of worldwide annual turnover for essential entities. For leadership teams the practical questions are concrete: are we in scope, do our measures meet Article 21, could we actually make the 24 hour early warning, and can we evidence all of it to a supervisor?
Our consulting answers those questions in order, from scope determination and gap assessment through implementation of the measures to reporting readiness, governance and the exercised evidence trail, drawing on the same practice that builds continuity, cyber resilience and crisis capability, because NIS2 compliance is those capabilities, documented.
NIS2 is one instrument in a coordinated European architecture. Its twin, the CER Directive, governs the same critical entities' physical and organisational resilience; financial entities answer to DORA as lex specialis; aviation carries Part-IS; and Swiss operators sit under the Information Security Act in parallel. Our briefings cover each, and the compliance calendar puts every date on one timeline.
Essential and important entities across 18 sectors, from energy, transport, health, water and digital infrastructure to postal services, food, manufacturing of critical products and digital providers, generally medium sized and above, with some entities in scope regardless of size. Scope determination is the first step of every engagement.
Under Article 23, a significant incident triggers an early warning to the CSIRT or competent authority within 24 hours, an incident notification with an initial assessment within 72 hours, and a final report within one month. Meeting the first deadline requires a rehearsed detection and escalation path.
For essential entities, fines of up to EUR 10 million or 2 percent of total worldwide annual turnover, whichever is higher; for important entities, up to EUR 7 million or 1.4 percent, alongside audits, binding instructions and, in serious cases, personal consequences for management.
They are parallel regimes: Swiss critical infrastructure operators answer to the ISG and its 24 hour reporting duty to BACS, while their EU operations or customers may pull them into NIS2. We map both; see our German language ISG briefing.
No. Article 20 places accountability on management bodies, and Article 21 spans continuity, supply chain and crisis handling. It is an organisational capability with a legal deadline, which is why our delivery combines policy, implementation, training and exercising.
The five pillars of Regulation (EU) 2022/2554 implemented for financial entities and their critical ICT providers.
The risk you inherit from suppliers and shared platforms: mapped, assured, contracted and exercised, per ISO 28000, NIS2 and DORA.
Beyond prevention: the capacity to withstand, respond and recover while essential services keep running.
Confidentiality, integrity and availability protected through a living ISMS aligned to ISO 27001.
BIA, ISO 22301 aligned strategy, plans and validation: a continuity programme built to survive contact with a real disruption.
Doctrine, structures and communications that contain the peak and shorten the recovery, anchored on ISO 22361.
Tabletop, functional, cyber and full scale exercises that prove the plans and evidence ISO 22301, NIS2 and DORA.
The structure above the plans: risk, continuity, crisis, cyber and people on one governed foundation, per ISO 22316.
From risk universe to governed risk: identification, stress aware assessment, owned treatment and live monitoring.
The Airport Resilience Framework: five domains as one operating model across the aerodrome, powered by the 7A engine, in commercial, freight and business aviation editions.
Our proprietary decision centric operating model: exposure and decision confidence measured separately, for the board.
Governance wrapped around every layer of intelligent systems, from model behaviour to board accountability and ISO 42001.
Start with a NIS2 readiness assessment; you will know your gaps, your priorities and your distance to the 24 hour clock.
Book a consultation