CISO Tribune

Analysis

NIS2 for security leaders: what the EU directive actually demands

The NIS2 directive explained for CISOs: who is covered, the management accountability provisions, incident reporting timelines, and how to sequence compliance.

By CISO Tribune Editorial · Published April 21, 2026 · 2 min read

TL;DR: NIS2 widened Europe's security regulation from a narrow set of operators to most of the mid-size-and-up economy in covered sectors, put management bodies personally on the hook for overseeing security, and set a 24-hour/72-hour/one-month incident-reporting cadence. Member states had until October 17, 2024 to transpose it, and national enforcement details vary — so the compliance question is always "NIS2 as implemented where we operate."

Who is covered, and how do you know?

NIS2 replaces the original NIS directive with a much broader scope, splitting covered organizations into essential entities (e.g., energy, transport, banking market infrastructure, health, water, digital infrastructure) and important entities (e.g., postal services, waste, chemicals, food, manufacturing of critical products, digital providers). Coverage generally attaches by sector plus size — mid-size and larger — with some entities covered regardless of size. Because NIS2 is a directive, each member state transposed it into national law with local registration duties, authorities, and dates; multi-country operators owe compliance in each jurisdiction where they fall in scope.

What does it require operationally?

Article 21 sets the baseline measures every covered entity must take, proportionate to risk: risk analysis and security policies, incident handling, business continuity and crisis management, supply-chain security, secure development and vulnerability handling, effectiveness testing, cyber hygiene and training, cryptography policies, access control and asset management, and multi-factor authentication where appropriate. For most organizations with a serious program mapped to ISO 27001 or NIST CSF, the delta is less about new controls and more about evidence: NIS2 expects the measures to be documented, approved by management, and demonstrable to a supervisor.

What makes NIS2 different from every prior EU security rule?

Management accountability. Article 20 requires management bodies to approve the risk-management measures, oversee their implementation, and undergo training — and makes them liable for infringements. For essential entities, sanctions can include temporarily banning individuals from managerial functions. Fines scale to the greater of fixed ceilings or a percentage of global turnover (up to 10M EUR / 2% for essential entities). The design intent is explicit: move security from the IT department to the boardroom by making the board own it.

How should a CISO sequence the work?

Five steps, in order. Scope: determine entity classification and registration duties in every member state of operation — this is a legal analysis, done with counsel. Gap-assess against Article 21 using your existing framework mapping rather than starting fresh. Stand up the reporting pipeline: the 24-hour early warning is the hard one; it demands detection, an internal severity call, and a notification path that works on a weekend. Paper the governance: management approval of the security program, board training, minutes — the artifacts Article 20 assumes. Push supply-chain terms: NIS2 makes vendor security your regulated problem; contract clauses and assessment cadence follow. Treat the directive text as the floor and the national transposition as the binding spec.

Frequently asked questions

Who does NIS2 apply to?
Essential and important entities across sectors including energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing of critical products, and digital providers — generally mid-size and larger organizations operating in the EU, a far wider scope than the original NIS directive.
What are NIS2's incident reporting deadlines?
A staged timeline: an early warning to the relevant authority within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.
Can management be held liable under NIS2?
Yes. NIS2 requires management bodies to approve and oversee cybersecurity risk-management measures, mandates training for them, and provides that they can be held accountable for infringements — including, for essential entities, the possibility of temporary bans on exercising managerial functions.

Sources

CISO Tribune Editorial

Editorial Desk

The CISO Tribune editorial desk reports on security leadership: who holds the role, who is leaving it, and what the moves mean. Every appointment entry is verified against a primary source before publication.