NIS2
NIS2 compliance: what the directive requires and how to prepare
NIS2 compliance means meeting the obligations of Directive (EU) 2022/2555 as transposed into national law: cybersecurity risk-management measures under Article 21, approved and overseen by management, and incident reporting under Article 23 with a 24-hour early warning, a 72-hour notification and a final report within one month. It applies mainly to medium-sized and larger entities in 18 sectors, and to some entities regardless of size.
Free plan, no card required.
Who is in scope of NIS2?
NIS2 applies to entities of a type listed in Annex I (11 sectors of high criticality, such as energy, transport, health and digital infrastructure) or Annex II (7 other critical sectors, including manufacturing and digital providers) that are at least medium-sized under Recommendation 2003/361/EC and operate in the EU. Under that Recommendation, an enterprise is no longer small once it has 50 or more staff, or both its turnover and balance-sheet total exceed €10 million. Some entities are in scope regardless of size, such as trust service providers, DNS service providers and entities a Member State identifies as critical.
For product companies, check the Annex II manufacturing sector. It covers medical and in vitro diagnostic devices, and NACE Rev. 2 divisions 26 to 30: computer, electronic and optical products; electrical equipment; machinery and equipment not elsewhere classified; motor vehicles and trailers; and other transport equipment. A medium-sized maker of industrial controllers or robots can be an important entity under NIS2 and, separately, a manufacturer under the Cyber Resilience Act.
| Essential entities | Important entities | |
|---|---|---|
| Who (Article 3) | Large Annex I entities, some categories regardless of size, and entities a Member State designates | Other in-scope Annex I or II entities |
| Supervision | Inspections, random checks, regular and targeted audits (Article 32) | Ex post, on evidence or indication of non-compliance (Article 33) |
What are the ten NIS2 Article 21 risk-management measures?
Article 21(1) requires appropriate and proportionate technical, operational and organisational measures, taking into account the state of the art, relevant standards, the cost of implementation, the entity's exposure to risks, its size, and the likelihood and severity of incidents. Article 21(4) adds that an entity which finds it does not comply must take corrective measures without undue delay.
For certain digital infrastructure and digital service providers, such as cloud, data centre and managed service providers, Implementing Regulation (EU) 2024/2690 sets out the technical detail; for other entities, national law and the competent authority's guidance do. In every case, Article 21(2) requires an all-hazards approach, and the measures must include at least the following:
- (a) Policies on risk analysis and information system security.
- (b) Incident handling.
- (c) Business continuity, such as backup management and disaster recovery, and crisis management.
- (d) Supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers.
- (e) Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure.
- (f) Policies and procedures to assess the effectiveness of cybersecurity risk-management measures.
- (g) Basic cyber hygiene practices and cybersecurity training.
- (h) Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
- (i) Human resources security, access control policies and asset management.
- (j) The use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications and secured emergency communication systems within the entity, where appropriate.
What are the NIS2 incident reporting deadlines?
Article 23 applies to significant incidents: those that have caused or can cause severe operational disruption of the services or financial loss for the entity, or considerable material or non-material damage to others. Reports go to the national CSIRT or, where applicable, the competent authority, and recipients of the services must be informed where appropriate. If an incident is still ongoing when the final report is due, a progress report is sent instead, and the final report follows within one month of handling the incident.
| Stage | Deadline | Content |
|---|---|---|
| Early warning | Without undue delay, within 24 hours of becoming aware | Whether unlawful or malicious acts are suspected and whether there could be a cross-border impact |
| Incident notification | Without undue delay, within 72 hours of becoming aware | Update of the early warning, initial assessment of severity and impact, indicators of compromise where available |
| Intermediate report | On request of the CSIRT or competent authority | Relevant status updates |
| Final report | No later than one month after the incident notification | Detailed description, likely threat type or root cause, mitigation applied and ongoing, cross-border impact |
Management accountability and fines under NIS2
Article 20 makes cybersecurity a board matter. Management bodies must approve the Article 21 measures, oversee their implementation and can be held liable for infringements, and their members must follow training so they can identify risks and assess cybersecurity risk-management practices. For a small leadership team, that means a documented approval of the measures, a regular review on the agenda and training records for each member.
Article 34 sets a floor for fines for infringements of Articles 21 or 23. For essential entities, Member States must provide maximum fines of at least €10,000,000 or at least 2% of total worldwide annual turnover in the preceding financial year, whichever is higher; for important entities, at least €7,000,000 or 1.4%. National laws can go higher, so check each Member State where you operate.
Where does NIS2 transposition stand?
NIS2 is a directive, so its obligations reach entities through national law. Member States had to adopt and publish their measures by 17 October 2024 and apply them from 18 October 2024 (Article 41). Transposition has not been uniform: on 8 July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the EU for failing to notify full transposition. On 20 January 2026 the Commission also proposed targeted amendments to NIS2; that is a proposal, not law.
How product scans support Article 21(2)(d) and (e)
Two of the ten measures are where product-level evidence helps. Point (d) covers supply chain security, and Article 21(3) asks entities to take into account the vulnerabilities specific to each direct supplier and the overall quality of their products and cybersecurity practices, including secure development procedures. Point (e) covers security in acquisition, development and maintenance, including vulnerability handling and disclosure. SBOMs, dependency and firmware scan results, and recorded decisions on each finding are the kind of records that show these measures working.
Implementing Regulation (EU) 2024/2690 shows what that looks like for the entities it covers: monitor vulnerability information, perform vulnerability scans where appropriate and record evidence of the results at planned intervals, and document why a vulnerability does not need remediation. ISO/IEC 27001:2022 is a common way to structure these measures in an information security management system, but NIS2 does not require it.
Available in KROMSE today
KROMSE is not a NIS2 compliance tool and certifies nothing, but its scans produce evidence for the vulnerability handling and supply chain parts of Article 21.
- Dependency, source code (11 languages), secret, misconfiguration and container image scans of the software you build.
- SBOM upload (CycloneDX, SPDX 2.2 and 2.3) for software your suppliers deliver, checked against OSV.dev automatically.
- Linux firmware image analysis, up to 512 MB, for devices you make or run.
- CISA KEV, FIRST EPSS, NVD and ENISA EUVD enrichment for findings with CVE IDs.
- VEX export, a CRA evidence pack (JSON or PDF) and a signed audit-log export that record what was found and what was decided.
Coming next
On the roadmap, not available yet. Dates are targets, not promises; this page changes the day a capability is live.
- Coming · Q1 2027 (January)NIS2 module. A NIS2 module will bring risk-management measures, incident timelines and evidence into one place in the product.
- Coming · Q1 2027ISO/IEC 27001 control evidence. Scan results and recorded decisions will be mapped to ISO/IEC 27001 controls as evidence for your audits.
- Coming · Q4 2026 (December)Monitoring on your schedule, with AI agents. Rescans will run on a schedule you set, with AI agents that watch for new advisories, triage what applies, propose fixes and draft the report for your review.
Frequently asked questions
Does NIS2 apply to small companies?
As a rule, no: NIS2 applies to entities in the Annex I and II sectors that are medium-sized or larger. Some are covered regardless of size, such as public electronic communications providers, trust service providers, DNS service providers, TLD registries and entities a Member State identifies as critical. Small companies can still feel NIS2 as suppliers to in-scope entities.
What is the difference between NIS2 and the Cyber Resilience Act?
NIS2 sets obligations for organisations: essential and important entities must manage cybersecurity risks and report significant incidents. The Cyber Resilience Act sets obligations for products with digital elements: manufacturers must meet essential cybersecurity requirements, handle vulnerabilities and report actively exploited ones. A company can be subject to both.
Is ISO 27001 certification enough for NIS2 compliance?
Not by itself. ISO/IEC 27001:2022 specifies requirements for an information security management system and is a common way to organise the Article 21 measures, but NIS2 does not require it. Certification also does not cover NIS2-specific duties such as the Article 23 reporting deadlines or management-body training under Article 20.
Can KROMSE make my organisation NIS2 compliant?
No. KROMSE does not certify compliance and does not decide whether NIS2 applies to you. It scans software, SBOMs, container images and Linux firmware and records results and decisions, which you can use as evidence under Article 21(2)(d) and (e). A NIS2 module is on the roadmap.
Related guides
Sources
- Directive (EU) 2022/2555 (NIS2), EUR-Lex
- European Commission: NIS2 Directive
- European Commission: referral of four Member States for failing to transpose NIS2 (8 July 2026)
- Commission Implementing Regulation (EU) 2024/2690, EUR-Lex
- Commission Recommendation 2003/361/EC (SME definition), EUR-Lex
- ISO/IEC 27001:2022, ISO