Back to Field Notes
Compliance & Regulation/Field Note

NIS2 — Are You In Scope, and What Do You Owe?

If you operate in the EU and provide an essential or important service, NIS2 likely applies — and the penalties have teeth.

Author

Mark Velasquez

Principal Standards Architect

Published

January 14, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01NIS2 dramatically expanded sector scope versus NIS1 — energy, transport, banking, health, water, digital infrastructure, ICT B2B services, public administration, manufacturing of critical products, food, chemicals, postal, waste, and research are now in scope.
  • 02Article 21 enumerates 10 minimum measures — risk analysis, incident handling, business continuity, supply chain security, secure procurement, cyber hygiene + training, cryptography, HR + access control, MFA, vulnerability disclosure. Not novel, but now legally binding.
  • 03Penalties reach €10M or 2% of global turnover for essential entities. NIS2 introduces personal liability for senior management — including temporary management bans for repeated serious violations.
  • 04Many organizations still do not realize they are in scope. Run the size-cap and sector tests now: medium and large entities (50+ FTE OR €10M+ turnover) in any in-scope sector are essential or important by default.

The NIS2 Directive replaced NIS1 with a far broader scope, stricter security obligations, and meaningful penalties. Member-state transposition deadlines have passed; enforcement is active.

Sectors now in scope

  • 01Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure
  • 02ICT service management (B2B), public administration, space
  • 03Postal and courier services, waste management, manufacture of certain critical products, food production, processing and distribution, chemicals, digital providers, research

The minimum measures

NIS2 Article 21 enumerates minimum security measures: risk analysis and information system security policies, incident handling, business continuity, supply chain security, secure procurement and development, basic cyber hygiene and training, cryptography, HR security and access control, MFA, secure communications, and vulnerability handling and disclosure.

The list is not particularly novel for mature programs — but it is now legally required, and management bodies are personally accountable for ensuring it is implemented.

Penalties and personal liability

Fines can reach €10 million or 2% of global turnover for essential entities. More notably, NIS2 introduces personal liability for senior management who fail to ensure compliance — including the possibility of temporary management bans for repeated, serious violations.

#NIS2#EU#Critical Infrastructure

/WRITTEN_BY

Mark Velasquez

Principal Standards Architect · Alexa Cybersecurity