Skip to main content
M516 Cyber Solutions

Governance, Risk & Compliance

NIS2: from directive to demonstrable compliance

Felix · 9 August 2026 · 1 min read

NIS2 raises the bar on management accountability, incident reporting and supply chain security. A practical route to evidence-backed readiness.

NIS2 changed the tone of European cyber regulation. It is no longer enough to hold a policy set; management bodies are accountable, reporting deadlines are tight, and supply chain security is explicitly in scope.

Confirm scope before you spend

Essential and important entity classifications differ in supervision, not in substantive duties. Many groups discover that a single subsidiary pulls the wider organisation into scope. Document the scoping decision and revisit it after any acquisition.

The obligations that bite

  • Risk analysis and information system security policies
  • Incident handling with 24-hour early warning and 72-hour notification
  • Business continuity, backup management and crisis response
  • Supply chain security, including direct supplier assurance
  • Vulnerability handling and disclosure
  • Cyber hygiene, training and multi-factor authentication

Management accountability is the real change

Senior management must approve risk measures and can be held liable for failures. That means board-level reporting with measurable indicators, not annual assurance summaries.

Incident reporting is a rehearsal problem

A 24-hour early warning is a process, not a document. Run tabletop exercises against the clock, with named decision makers, legal review and a pre-approved notification template.

Prove the supply chain

Supplier questionnaires answered once a year do not evidence continuous assurance. Tier your suppliers by impact, set contractual security requirements, and monitor the critical tier between reviews.

Compliance you can sustain means controls that keep producing evidence after the audit ends.

  • NIS2
  • resilience
  • supply chain

← All insights

Want this thinking applied to your supplier ecosystem?

A short, no-obligation discovery call to understand your risk profile and where to start.