web analytics
AI Governance

NIS2 Directive

Directive (EU) 2022/2555. Where Directors Can Be Banned.

The one-paragraph answer

NIS2 (Directive (EU) 2022/2555) is the EU’s horizontal cybersecurity law, covering 18 sectors through two tiers: essential and important entities. It requires risk management measures including supply-chain security, and incident reporting on a 24 hours / 72 hours / one month clock. Fines reach €10 million or 2 percent of worldwide turnover. But the provision that changes behaviour is Article 20: the management body is personally accountable, must be trained, and for essential entities, executives can be temporarily banned from management functions. Not the company. The person.

The pain NIS2 is causing our customers

Most cybersecurity regulation threatens the balance sheet. A fine is a number, it gets modelled, and it gets absorbed. NIS2 threatens the individual. Under Article 20, management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held directly accountable for breaches. For essential entities, competent authorities can temporarily prohibit an individual from exercising management functions.

That is a different conversation in a boardroom. The board that received an annual security slide and signed off is exactly the board NIS2 was drafted against.

The second pain is scope. Companies assume that because they are not a utility or a bank, they are outside it. NIS2 covers 18 sectors including manufacturing of critical products, food, chemicals, waste management, postal and courier services, and ICT service management. And it reaches non-EU companies offering covered services into the EU, who must designate an EU representative.

What NIS2 actually requires

Article 21: risk-management measures

An all-hazards set: risk analysis and information system security policies, incident handling, business continuity and crisis management, supply chain security, security in acquisition and development, effectiveness testing, cyber hygiene and training, cryptography and encryption, access control and asset management, and multi-factor or continuous authentication. Measures must be appropriate and proportionate, taking account of the state of the art.

Supply chain security is where AI lands. An AI vendor with deep access to an essential entity is a supply-chain risk that Article 21 obliges the entity to assess. The SBOM and the vendor security review are the mechanism.

Article 23: the 24 / 72 / 30 clock

Early warning within 24 hours of becoming aware of a significant incident. Incident notification within 72 hours. Final report within one month. Significance is judged on operational disruption, financial loss, and material or non-material damage to others.

Article 20: the management body

Approve the measures. Oversee implementation. Be trained, and offer similar training to staff. Be personally accountable. For essential entities, face a temporary management ban.

Essential or important, and why it matters

Essential entities are broadly large organisations (250+ staff or over €50m turnover) in the Annex I high-criticality sectors. They face proactive supervision: audits and inspections, whether or not anything has gone wrong. Fines to €10 million or 2 percent of worldwide turnover.

Important entities are medium-sized entities in Annex I, and medium and large entities in Annex II. They face ex post supervision, triggered only by suspicion of a violation. Fines to €7 million or 1.4 percent.

Some entities are in scope regardless of size, including DNS providers, TLD registries, and qualified trust service providers.

The state of play, and why “we are still implementing” has stopped working

The transposition deadline was 17 October 2024, and most Member States missed it. The Commission opened infringement proceedings against 23 Member States in November 2024, sent reasoned opinions to 19 in May 2025, and by May 2026 had referred seven to the Court of Justice.

That history has made compliance teams complacent. It should not. The great majority of Member States have now transposed, several have layered their own national milestones on top, and the practical convergence point is autumn 2026. Supervisory patience is running out precisely as the last national laws land.

Where NIS2 stops: DORA is lex specialis

Article 4 gives way to sector-specific regimes of equivalent effect. For financial entities, that regime is DORA. If DORA applies to you, its ICT risk provisions displace the corresponding NIS2 obligations rather than stacking on top of them.

What the research says about NIS2 and supply chain security

Article 21’s supply-chain provision is not boilerplate. It is the response to where attacks actually come from.

“recent years have shown almost exponential growth in attackers leveraging these software artifacts”

SolarWinds, Log4j, xz utils. NIS2 Article 21(2)(d) is the EU’s legislative answer, and it puts the duty on the entity, not the supplier.

“99% of vulnerabilities in client programs are caused by their dependencies”

Which is why an entity that cannot enumerate its components cannot discharge Article 21, and cannot report on a 24-hour clock about a system it cannot describe.

How to comply with NIS2: a 5-step path

  1. Determine scope and tier, in writing. Which Annex, which sector, what size, essential or important. Then check your national transposition, because Member States have added their own thresholds and milestones. If you are non-EU and offer covered services into the EU, designate your EU representative.
  2. Get the board trained and on the record. Article 20 requires the management body to approve the measures and be trained. Minute the approval and the training. Silence in the minutes is what a supervisor examines, and for essential entities the sanction reaches the individual.
  3. Build the Article 21 evidence, including the supply chain. All ten measure categories, documented and tested. The supply-chain limb is where AI vendors, model providers, and API dependencies land. Enumerate them.
  4. Rehearse the 24-hour clock. Define what counts as a significant incident, who declares it, who files the early warning, who approves it, and who covers out of hours. An untested reporting process is not a process.
  5. Map, do not duplicate. ISO 27001 and NIST CSF controls map closely to Article 21, and several national regulators accept them as evidence. Reuse the work rather than running a parallel programme.

Frequently asked questions about NIS2

Does NIS2 apply to our US company?

Only if you are a specific covered entity type (cloud computing, DNS, online marketplace, social network, and similar) and you offer those services within the EU. Merely having EU users is not enough. If both apply, you must designate a representative in a Member State.

Does ISO 27001 certification make us NIS2 compliant?

No. ISO 27001 is voluntary certification; NIS2 is law with penalties. But the controls map closely to Article 21, and regulators in several Member States accept ISO 27001 evidence toward compliance. It is a large head start, not a substitute.

Can our directors really be banned?

For essential entities, yes. Competent authorities can temporarily prohibit an individual from exercising management functions. This is not theoretical drafting; it is the enforcement lever that distinguishes NIS2 from a fine schedule.

How does NIS2 relate to the Cyber Resilience Act?

They are complementary and frequently confused. The CRA regulates the product you place on the market. NIS2 regulates the organisation operating in a critical sector. A manufacturer can easily be subject to both, for different reasons, with different evidence.

Where does NIS2 fit in SRJ’s work?

Volume V produces the artefacts Article 21 expects: the AI Vendor Tier Map for supply chain, the Red Button procedure and incident response addendum for Article 23, and the Four-Page Board Pack for the Article 20 management-body record.

Primary sources on NIS2

Note that NIS2 is a directive: your binding obligations come from your Member State’s transposing law, not from the directive text. Read both.

Ready to see where you stand?

The AI Business Enablement Audit™ measures your organization against every framework in this library, including NIS2 Directive, and delivers a defensible governance dossier. Start or finish your audit below.

Start or finish your AI Audit →
Schedule a Free AI Consultation