
REGULATION — NIS2
NIS2 widens the EU cyber baseline to essential and important entities across energy, transport, water, health, digital infrastructure, public administration, manufacturing and more — and member states were required to transpose it into national law by 17 October 2024.
WHAT IT DEMANDS
NIS2 — Directive (EU) 2022/2555 — replaced the original 2016 NIS Directive. It pulls far more organisations into scope, classifying them as essential or important entities, generally where they cross a size threshold. If you sit in one of the covered sectors and clear that bar, the directive applies to you.
The shift that catches people out is governance. Management bodies must approve and oversee the entity's cyber risk-management measures, and can be held liable for failures. Senior management can face sanctions. Cyber is no longer something the board receives — it is something the board owns.
THE ARTICLE 21 BASELINE
THE REPORTING TIMELINE
An initial early warning to the relevant authority within 24 hours of becoming aware of a significant incident.
A fuller notification within 72 hours, updating and assessing the incident as understanding develops.
A final report within one month, setting out the incident, its cause, and the measures taken.
WHERE FIRMS TRIP
HOW WE HELP
01
Closing the gap between a NIS1-era posture and the Article 21 baseline — risk, incident handling, continuity and supply chain, built to hold.
02
Getting management genuinely engaged and equipped to approve, oversee and answer for cyber risk — because under NIS2 they are liable for it.
03
Access control, cryptography, MFA and supply-chain security designed into how the organisation runs, not bolted on afterwards.
Bring the board into the room, and the rest of NIS2 gets a lot easier.
Start a conversation