Who Is in Scope?
NIS2 applies to essential and important entities across 18 sectors. The size threshold is 50+ employees OR €10M+ annual turnover.
| Essential Entities | Important Entities |
|---|---|
| Energy (electricity, oil, gas, hydrogen) | Postal and courier services |
| Transport (air, rail, water, road) | Waste management |
| Banking and financial market infrastructure | Chemical manufacturing |
| Healthcare (hospitals, labs, pharma) | Food production and distribution |
| Drinking water and wastewater | Manufacturing (medical, electronics, machinery) |
| Digital infrastructure (DNS, TLD, cloud, data centres) | Digital providers (marketplaces, search, social) |
| ICT service management (MSPs, MSSPs) | Research organisations |
| Public administration | |
| Space |
IT service providers are in scope
If you provide managed IT services, cloud hosting, security services, or software to any entity in the 18 sectors, you are classified as an ICT service management provider — an essential entity under NIS2. This directly affects Genitco and similar IT consultancies.
The 10 Minimum Measures (Article 21)
NIS2 Article 21 mandates 10 cybersecurity risk management measures. These are not optional.
- Risk analysis and information security policies — Documented ISMS, regular risk assessments, board-approved security policy
- Incident handling — Detection, response, recovery procedures. Tested regularly.
- Business continuity and crisis management — BCP, DR plans, backup management, tested recovery
- Supply chain security — Assess supplier cybersecurity, contractual requirements, right to audit
- Security in network and information systems — Acquisition, development, maintenance with security by design
- Policies for assessing effectiveness — Regular vulnerability assessments, penetration testing, audit
- Cybersecurity hygiene and training — Awareness programmes for all staff, board-level training (mandatory)
- Cryptography and encryption policies — Documented use of cryptography, key management
- Human resources security — Background checks, access control tied to employment lifecycle
- Multi-factor authentication and secure communications — MFA for all privileged access, encrypted voice/video/text
Board Liability (Article 20)
NIS2 Article 20 requires management bodies to:
- Approve cybersecurity risk management measures
- Oversee their implementation
- Complete cybersecurity training (and ensure staff do too)
- Be held personally liable for non-compliance
Article 32 allows Member States to impose temporary management bans on individuals found responsible for breaches. This is not a corporate fine — it is personal liability for named directors.
Incident Reporting
| Deadline | Requirement | To Whom |
|---|---|---|
| 24 hours | Early warning — is this a significant incident? | CSIRT / competent authority |
| 72 hours | Incident notification — initial assessment, severity, impact, IoCs | CSIRT / competent authority |
| 1 month | Final report — root cause, remediation, cross-border impact | CSIRT / competent authority |
Penalties
| Entity Type | Maximum Fine | Additional |
|---|---|---|
| Essential | €10M or 2% global turnover (whichever higher) | Temporary management bans possible |
| Important | €7M or 1.4% global turnover (whichever higher) | Compliance orders, binding instructions |
Readiness Checklist
- ☐ Determine if your organisation is essential or important under NIS2
- ☐ Confirm board awareness and schedule cybersecurity training
- ☐ Review and update your information security policy (board approval required)
- ☐ Conduct a risk assessment against the 10 minimum measures
- ☐ Assess supply chain cybersecurity (all ICT service providers)
- ☐ Implement or verify MFA for all privileged access
- ☐ Test incident response procedures (tabletop exercise)
- ☐ Verify 24h/72h/1m reporting capability
- ☐ Test business continuity and disaster recovery plans
- ☐ Document encryption policies and key management procedures
- ☐ Register with national competent authority if required