
- 01NIS2 dramatically expanded sector scope versus NIS1 — energy, transport, banking, health, water, digital infrastructure, ICT B2B services, public administration, manufacturing of critical products, food, chemicals, postal, waste, and research are now in scope.
- 02Article 21 enumerates 10 minimum measures — risk analysis, incident handling, business continuity, supply chain security, secure procurement, cyber hygiene + training, cryptography, HR + access control, MFA, vulnerability disclosure. Not novel, but now legally binding.
- 03Penalties reach €10M or 2% of global turnover for essential entities. NIS2 introduces personal liability for senior management — including temporary management bans for repeated serious violations.
- 04Many organizations still do not realize they are in scope. Run the size-cap and sector tests now: medium and large entities (50+ FTE OR €10M+ turnover) in any in-scope sector are essential or important by default.
The NIS2 Directive replaced NIS1 with a far broader scope, stricter security obligations, and meaningful penalties. Member-state transposition deadlines have passed; enforcement is active.
Sectors now in scope
- 01Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure
- 02ICT service management (B2B), public administration, space
- 03Postal and courier services, waste management, manufacture of certain critical products, food production, processing and distribution, chemicals, digital providers, research
The minimum measures
NIS2 Article 21 enumerates minimum security measures: risk analysis and information system security policies, incident handling, business continuity, supply chain security, secure procurement and development, basic cyber hygiene and training, cryptography, HR security and access control, MFA, secure communications, and vulnerability handling and disclosure.
The list is not particularly novel for mature programs — but it is now legally required, and management bodies are personally accountable for ensuring it is implemented.
Penalties and personal liability
Fines can reach €10 million or 2% of global turnover for essential entities. More notably, NIS2 introduces personal liability for senior management who fail to ensure compliance — including the possibility of temporary management bans for repeated, serious violations.


