NIS2 raises the bar on management accountability, incident reporting and supply chain security. A practical route to evidence-backed readiness.
NIS2 changed the tone of European cyber regulation. It is no longer enough to hold a policy set; management bodies are accountable, reporting deadlines are tight, and supply chain security is explicitly in scope.
Confirm scope before you spend
Essential and important entity classifications differ in supervision, not in substantive duties. Many groups discover that a single subsidiary pulls the wider organisation into scope. Document the scoping decision and revisit it after any acquisition.
The obligations that bite
- Risk analysis and information system security policies
- Incident handling with 24-hour early warning and 72-hour notification
- Business continuity, backup management and crisis response
- Supply chain security, including direct supplier assurance
- Vulnerability handling and disclosure
- Cyber hygiene, training and multi-factor authentication
Management accountability is the real change
Senior management must approve risk measures and can be held liable for failures. That means board-level reporting with measurable indicators, not annual assurance summaries.
Incident reporting is a rehearsal problem
A 24-hour early warning is a process, not a document. Run tabletop exercises against the clock, with named decision makers, legal review and a pre-approved notification template.
Prove the supply chain
Supplier questionnaires answered once a year do not evidence continuous assurance. Tier your suppliers by impact, set contractual security requirements, and monitor the critical tier between reviews.
Compliance you can sustain means controls that keep producing evidence after the audit ends.
- NIS2
- resilience
- supply chain