Scope and entity type
We look at your sector, your size and where you provide services. You get our view on whether NIS2 is likely to reach you, which entity type fits and which Member State's law applies, for your counsel to confirm.
NIS2 compliance consultant
Your sector, your size and where you provide services decide whether the EU's NIS2 Directive treats you as an essential entity, an important entity or neither. If you are in scope, Article 21 sets your security measures and Article 23 your incident reporting, unless you are a financial entity under DORA. We advise remotely from India.
What we do
Three things, in this order. The rest of this page explains each one.
We look at your sector, your size and where you provide services. You get our view on whether NIS2 is likely to reach you, which entity type fits and which Member State's law applies, for your counsel to confirm.
We advise on the security measures Article 21 asks for, across the six areas listed below. Your management body approves them.
We advise on the Article 23 reporting clocks, including who in your incident response plan sends the early warning. For a financial entity, we advise on where DORA applies instead.
Scope first
Whether the Directive covers you, and whose national law applies, are two separate questions.
NIS2 covers public and private organizations that pass three tests. Your answer can be no.
Even if the answer is no, Article 21 makes in-scope customers weigh their suppliers' security practices, so you may still be asked about yours.
NIS2 is a directive. Each Member State turns it into national law, and those national laws are what bind you. You generally answer to the Member State where you are established. Listed digital providers, from managed service and cloud providers to online marketplaces, answer to the Member State of their main EU establishment.
A listed provider that serves the EU without being established there must designate a representative in a Member State it serves. That duty is separate from the GDPR Article 27 representative, which our GDPR compliance page covers.
Entity type
Article 3 sets the label the rest of the Directive works from, including how high fines can go. Find the row that describes you.
| Your organization | Where NIS2 puts it |
|---|---|
| Annex I sector, larger than a medium-sized enterprise | Essential entity |
| Annex I sector, medium-sized | Important entity, unless named essential |
| Annex II sector, medium-sized or larger | Important entity, unless named essential |
| Telecom, trust service, top-level domain (TLD), domain name system (DNS) or domain registration firm | Covered whatever its size |
| Financial entity that DORA covers | DORA's matching rules apply instead |
| Small or micro, and not a listed exception | Outside the Directive's scope |
Operating in the UK, or established in Ireland? NIS2 is not UK law, and Ireland had not transposed it as of mid-September 2026. The questions below explain where each stands.
Article 21 minimum
If NIS2 reaches you, Article 21 sets the minimum your measures must cover, grouped here into six areas. Because it is a minimum, ticking every item does not by itself show compliance.
Policies on analyzing risk and on information system security, plus policies and procedures to assess whether your measures work.
Incident handling, business continuity such as backup management and disaster recovery, and crisis management.
This includes the security side of your relationships with direct suppliers and service providers. For how we check suppliers, see third-party risk management.
Security in buying, developing and maintaining systems, including vulnerability handling and disclosure.
Basic cyber hygiene, cybersecurity training, human resources security, access control policies and asset management.
Policies and procedures on the use of cryptography and, where appropriate, encryption. Multi-factor or continuous authentication and secured communications, where appropriate.
Want the measures run as an ongoing program, with a named owner for each risk? See GRC as a Service and risk management.
Article 23 reporting
These are the Directive's own reporting clocks for a significant incident, from first judgement to final report.
Under NIS2 an incident is significant if it caused or could cause severe disruption of your services or financial loss to you, or considerable material or non-material damage to others.
Without undue delay, and by the end of the 24th hour after you become aware. Your incident response plan should name who sends it.
By the end of the 72nd hour after you become aware, with an initial assessment of severity and impact, and indicators of compromise (the technical traces an attack leaves) where available.
The national computer security incident response team (CSIRT) or the competent authority can ask for an intermediate status report. The final report is due no later than a month after the notification, not the incident. If the incident is still going on at that point, you send a progress report then, and the final report follows later.
Limits of any adviser
The Directive keeps some duties with your board, and it issues no certificate.
Article 20 makes your management body, such as your board, approve the risk-management measures and oversee how they are put in place. Under national rules, the management body can be held liable for breaches of Article 21.
The Directive creates no such certificate, though Member States may require certified information and communications technology (ICT) products or services under EU schemes. Ireland's National Cyber Security Centre (NCSC) says certification under the CyFun scheme is optional and does not by itself establish compliance.
Each report to the CSIRT or competent authority goes out in your organization's name. The legal view on whether NIS2 reaches you comes from your own counsel.
Where SecWiz sits. We work as a NIS2 compliance consultant remotely from India, where our registered office and postal address are, and we also advise on GDPR and DORA. We provide advisory services, not legal advice.
FAQ
Companies outside the EU, the UK, Ireland, DORA, fines and key dates. For anything else, ask us directly.
It can reach organizations of its listed types and sizes that provide services or carry out activities in the EU. A listed digital provider, such as a managed service or cloud provider, serving the EU without being established there must designate a representative in a Member State it serves. If it names none, any Member State it serves may take legal action against it for breaching NIS2. Whether you count as established in a country depends on real activity there through stable arrangements, not on your legal form.
Not as UK law. The UK's Network and Information Systems Regulations 2018 remain in force, and under them an operator of essential services must report a NIS incident by the end of the 72nd hour after becoming aware of it. The Cyber Security and Resilience (Network and Information Systems) Bill would add medium and large managed service providers, but as of September 15, 2026 it had not become law.
Not as of mid-September 2026, when Ireland's NIS2 bill was still unpublished. The Government aimed to publish the National Cyber Security Bill in autumn 2026 and said it expected to notify the EU of transposition by the end of 2026. On July 8, 2026 the European Commission referred Ireland to the Court of Justice of the EU for failing to notify full transposition. Meanwhile S.I. No. 360 of 2018, Ireland's original NIS rules, remains in full effect.
DORA, for the financial entities it covers. NIS2 itself names DORA, Regulation (EU) 2022/2554, as the sector-specific law for those entities, so the matching NIS2 rules should not be applied to them. DORA has applied directly from January 17, 2025, and its incident deadlines, set in Delegated Regulation (EU) 2025/301, differ from NIS2's.
Each country sets its own maximum fines. The Directive only sets a floor: how high those maximums must at least be. For essential entities that breach the security or reporting duties, national law must allow maximum fines of at least EUR 10 million or 2% of the worldwide annual turnover of the undertaking they belong to, whichever is higher. For important entities the floor is EUR 7 million or 1.4%.
NIS2 was adopted on December 14, 2022, and Member States had to apply their national laws from October 18, 2024, when the original NIS Directive was repealed. Those national laws bind organizations. As of September 15, 2026 the Directive had not been amended, and two Commission proposals to change it were still pending.
Let's talk
Name your sector, the EU countries you serve, your staff numbers and turnover, and any financial regulator. We start with whether NIS2 reaches you at all. We reply within one working day.