Regulatory primer
NIS2
Directive (EU) 2022/2555 — Network and Information Security Directive 2 · European Union · Transposition deadline 17 October 2024; in force in transposing member states
NIS2 is the EU's cybersecurity baseline for essential + important entities across 18 critical sectors. It expands NIS1's scope, harmonises risk-management measures, mandates incident reporting on tight timelines, and puts supply-chain security on the agenda. Transposition deadline was 17 October 2024 — most member states are now active.
What it is
NIS2 replaces the 2016 NIS Directive. The expansion is structural: NIS1 covered ~7 sectors; NIS2 covers 18. NIS1 left scope-determination to member states; NIS2 fixes scope at EU level via size + sector criteria. NIS1 had loose risk-management expectations; NIS2 fixes minimum measures in Art. 21.
Two regulated categories: 'essential entities' (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space) and 'important entities' (postal + courier, waste management, chemicals, food, manufacturing of critical products, digital providers, research). Essential entities face proactive supervision; important entities face reactive (ex post) supervision.
Size threshold: medium-sized enterprises (€10M turnover OR 50+ employees) in the listed sectors are in scope by default. Some sectors (e.g. critical digital infrastructure providers, qualified trust service providers) are in scope regardless of size.
Who's in scope
- Essential entities: energy, transport, banking, financial market infrastructure, health, drinking + wastewater, digital infrastructure, ICT service management (B2B), public administration, space.
- Important entities: postal + courier, waste management, chemicals, food production + distribution, manufacturing of critical products (medical devices, vehicles, electronics, machinery), digital providers (online marketplaces, search engines, social networks), research.
- Size threshold: medium-sized (€10M turnover OR 50+ employees) by default. Some sectors apply regardless of size.
- Financial entities subject to DORA are largely excluded (DORA acts as lex specialis for financial-sector cybersecurity).
- Cross-border + supply-chain dimension: even non-regulated entities supplying regulated customers carry indirect supply-chain risk-management expectations.
Key obligations
Art. 21 — cybersecurity risk-management measures
Appropriate + proportionate technical, operational, organisational measures. Minimum measures specified: risk-analysis + IS policies, incident handling, business continuity + backup, supply chain security (Art. 21(2)(d)), security in acquisition + development + maintenance, policies on effectiveness assessment, basic cyber hygiene + training, cryptography + encryption, HR security + access control + asset management, multi-factor authentication.
Art. 21(2)(d) — supply-chain security
Risk-management measures must include 'supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers'. The basis for cascading evidence demands to vendors.
Art. 23 — incident reporting (24h / 72h / 1 month)
Significant incidents must be reported to CSIRT or competent authority: early warning within 24h, incident notification within 72h, final report within 1 month. Affected recipients (where relevant) notified without undue delay.
Art. 24 — use of European certification schemes
Member states may require essential + important entities to use ICT products + services certified under the EU Cybersecurity Certification Framework (EUCC) for specific risk categories.
Art. 32 — management body liability
Management bodies of essential + important entities must approve risk-management measures + oversee implementation. Personal liability + accountability is in scope.
Timeline + applicability
- 16 Jan 2023NIS2 entered into force at EU level.
- 17 Oct 2024Transposition deadline for member states. Most transposed on time; a handful slipped.
- 18 Oct 2024NIS2 measures apply in transposing member states.
What's still being worked out
Areas where the regulation's interpretation is genuinely unsettled. Vendor pages skip this; we don't. Your counsel is the right venue for definitive guidance on your deployment.
- How 'supply-chain security' under Art. 21(2)(d) cascades — what evidence regulated entities must demand from non-regulated suppliers. National practice is forming.
- Boundary with DORA — financial entities have lex specialis treatment, but non-financial ICT providers serving them may still be NIS2-regulated separately.
- What counts as a 'significant incident' under Art. 23 — quantitative thresholds vary across member-state transposition.
- Public-administration scope — local + regional authorities are in scope unless excluded by member state. Practice varies.
- Penalty structure — Art. 34 sets minimum maximum penalties (essential entities: €10M or 2% turnover; important: €7M or 1.4%) but national implementations differ on aggravation factors.
Sectors most affected
Cybersecurity
Cybersecurity vendors are typically NOT directly regulated, but their regulated customers cascade Art. 21(2)(d) supply-chain demands.
Energy & Utilities
Energy is essential under Annex I. TSOs, DSOs, retailers, aggregators all subject to Art. 21 + Art. 23.
Fintech & Payments
Banking is in Annex I but DORA lex specialis applies. Non-DORA fintechs may still be NIS2-regulated.
Govtech & Public Sector
Public administration is essential when meeting thresholds. Govtech AI vendors cascade evidence demands.
Healthtech
Health sector is essential. Healthtech vendors selling into in-scope hospital + payer customers inherit supply-chain expectations.
Primary sources
Where Promethean fits
Promethean's L12 chain + audit-bundle export feed two NIS2 obligations directly: (1) Art. 21(2)(d) supply-chain assurance to customers — per-tenant audit bundle filtered to the customer's deployment gives them verifiable evidence of vendor AI behaviour for their own NIS2 compliance posture; (2) Art. 23 incident-timeline reconstruction — when an AI component is implicated in a significant incident, recordedAtIso + tamper-evident chain anchored to Bitcoin via OpenTimestamps provide an independently verifiable timeline.
What Promethean does NOT solve
- Broader cybersecurity controls (Art. 21 minimum measures other than the AI-component slice) — that's the operator's full security programme.
- Penetration testing / TLPT — specialist offensive security work.
- Business-continuity + disaster recovery planning.
- EUCC certification — that's a separate certification pathway.
- Management-body governance + training — organisational responsibility.
FAQ
Am I in NIS2 scope?
Two questions: are you in an Annex I (essential) or Annex II (important) sector, AND do you meet the size threshold (medium = €10M turnover OR 50+ employees)? Some sectors apply regardless of size (qualified trust service providers, DNS service providers, TLD name registries, critical digital infrastructure). Member-state transpositions vary; check your national implementing law.
What's the difference between essential + important entities?
Essential entities are subject to proactive (ex ante) supervision: CSIRTs + competent authorities can audit + impose measures. Important entities are subject to reactive (ex post) supervision: action follows evidence of non-compliance. Penalty caps differ — essential €10M or 2% global turnover; important €7M or 1.4% (Art. 34).
Does NIS2 apply to my SaaS vendor?
Directly: only if the vendor is in an Annex sector + meets the size threshold (or is a sector-regardless-of-size category like ICT service management). Indirectly: every regulated NIS2 customer carries Art. 21(2)(d) supply-chain obligations, which cascade vendor-assessment demands. Practically, vendors serving regulated customers should expect evidence requests even when not directly NIS2-regulated.
How does NIS2 interact with DORA?
Financial entities subject to DORA are largely excluded from NIS2 obligations — DORA acts as lex specialis on cybersecurity + ICT risk for the financial sector. But non-financial ICT vendors supplying financial entities can be NIS2-regulated separately. Vendor-side: be ready for both DORA Art. 28 evidence demands AND NIS2 Art. 21(2)(d) supply-chain demands from different customer-types simultaneously.
What's the management-body liability under Art. 32?
Management bodies of essential + important entities must approve risk-management measures + oversee implementation. Personal accountability is in scope: member-state transpositions can include personal sanctions (e.g. temporary prohibitions on holding management positions). The practical effect: AI + cybersecurity-evidence questions are now board-level governance issues, not just CISO-level operational ones.