SHORT ANSWER
NIS2 (Directive (EU) 2022/2555) covers medium and large organisations in 18 sectors, classed as essential or important entities. Article 21 sets ten minimum security measures, including supply-chain security and secure development. Article 23 requires a 24-hour early warning, a 72-hour notification and a one-month final report for significant incidents. Software vendors are affected directly as managed or digital service providers, and indirectly through customer contracts.
If your customers run energy grids, hospitals, banks or factories, you’ve probably already received a NIS2 security questionnaire. NIS2 (Directive (EU) 2022/2555) is the EU’s main cybersecurity law for organisations that keep the economy and society running. It replaced the first NIS Directive, widened the scope to 18 sectors and made company management personally accountable for cybersecurity. For software vendors and suppliers it matters in two ways: some are directly in scope, and almost all will have to prove their security to in-scope customers through supply-chain requirements. This guide is general information, not legal advice.
Who does NIS2 cover: essential and important entities
NIS2 applies to medium and large organisations (50 or more employees, or more than €10 million annual turnover and balance sheet) in the sectors listed in its annexes. It also covers some entities regardless of size, such as DNS providers, top-level domain registries and qualified trust service providers.
| Essential entities | Important entities |
|---|---|---|
Typical profile | Large organisations in Annex I high-criticality sectors: energy, transport, banking, health, drinking water, digital infrastructure, ICT service management (B2B), public administration, space | Medium organisations in Annex I, and medium and large organisations in Annex II: postal, waste, chemicals, food, manufacturing, digital providers, research |
Security measures | Article 21, all ten | Article 21, all ten |
Incident reporting | Article 23 | Article 23 |
Supervision | Proactive (ex ante): audits, inspections | Reactive (ex post): after evidence of non-compliance |
Maximum fine | €10 million or 2% of worldwide turnover | €7 million or 1.4% of worldwide turnover |
In the tech sector, managed service providers and managed security service providers fall under ICT service management, cloud and data centre providers under digital infrastructure, and marketplaces, search engines and social networks under digital providers. For these, Commission Implementing Regulation (EU) 2024/2690 spells out the technical measures and significant incident thresholds in detail.
What are the Article 21 security measures?
Article 21(2) | Measure | Typical evidence for a software supplier |
|---|---|---|
(a) | Risk analysis and information system security policies | Information security policy, risk register |
(b) | Incident handling | Incident response plan, on-call, post-incident reviews |
(c) | Business continuity, backup, disaster recovery and crisis management | BCP, tested restores, RTO and RPO targets |
(d) | Supply-chain security | Supplier assessments, security clauses, subcontractor list |
(e) | Security in acquisition, development and maintenance, including vulnerability handling and disclosure | Secure SDLC, code review, dependency scanning, SBOM, vulnerability disclosure policy |
(f) | Policies to assess the effectiveness of measures | Internal audits, penetration tests, metrics |
(g) | Basic cyber hygiene and training | Security awareness training, hardening baselines, patching |
(h) | Cryptography and encryption | Encryption at rest and in transit, key management |
(i) | Human resources security, access control and asset management | Joiner-mover-leaver process, least privilege, asset inventory |
(j) | Multi-factor authentication and secured communications | MFA everywhere, secure voice, video and emergency channels |
Measures must be proportionate to risk, size and cost. The management body must approve them, oversee how they’re applied and take cybersecurity training, and its members can be held liable for breaches.
What does supply-chain security mean for vendors?
Article 21(2)(d) and (3) require in-scope entities to consider each direct supplier’s vulnerabilities, the quality of its products and its secure development practices. In practice, customers pass these requirements down to you through:
Security questionnaires and audits during procurement and every year after.
Contract clauses on security measures, incident notification within hours, vulnerability handling, subcontracting approval and audit rights.
Evidence requests: ISO 27001 certificate and Statement of Applicability, penetration test summaries, SBOMs, patch timelines.
Secure development expectations: threat modelling, code review, static and dependency analysis, signed builds and separated environments.
Vulnerability disclosure: a public policy and a process to fix and communicate issues, which NIS2 links to coordinated disclosure through national CSIRTs.
What we’ve learned from our own ISO 27001 audits and client security reviews: the slow questions are rarely about firewalls. They’re about proof. Who approved this change, when was that dependency patched, which subcontractor can reach which system. Teams that record those facts as part of normal delivery answer questionnaires from their records. Teams that don’t end up reconstructing them from memory under a deadline.
Vendors of products with digital elements should also track the Cyber Resilience Act. Its reporting duties for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026, with a 24-hour early warning through ENISA’s single reporting platform. Its main product requirements apply from 11 December 2027.
What are the NIS2 incident reporting timelines?
Step | Deadline | Content |
|---|---|---|
Early warning | Within 24 hours of becoming aware of a significant incident | Whether it may be caused by unlawful or malicious acts and could have cross-border impact |
Incident notification | Within 72 hours | Initial assessment, severity, impact and indicators of compromise |
Intermediate report | On request of the CSIRT or authority | Status updates |
Final report | Within one month of the notification | Detailed description, root cause, mitigation, cross-border impact |
An incident at your company can become your customer’s significant incident. Agree on notification times, contacts and the facts you’ll provide before anything happens.
Where does NIS2 transposition stand in 2026?
NIS2 is a directive, so it applies through national laws, which differ in details such as registration deadlines, sector additions and fines. The transposition deadline was 17 October 2024, and most countries missed it. By September 2026 most Member States had laws in force, including Germany (6 December 2025), Italy, Belgium and Croatia. The Dutch law entered into force in August 2026, and Austria’s applies from 1 October 2026.
In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, and Ireland, Spain and France were reported as still without adopted laws in September 2026. In January 2026 the Commission also proposed targeted NIS2 amendments to clarify scope, add a small mid-cap category and harmonise measures. These are still being negotiated. Check each country’s authority for current rules.
Can ISO 27001 serve as your NIS2 framework?
ISO 27001:2022 doesn’t give you automatic NIS2 compliance, but its risk-based management system and 93 Annex A controls map to nearly every Article 21 measure. Starting from ISO 27001 lets you answer customer questionnaires consistently and reuse one set of evidence for NIS2, DORA and client audits. You then add the NIS2-specific pieces: registration, management training and 24/72-hour reporting. If you also serve banks or insurers, read our DORA guide for fintech software.
How RUBICON helps suppliers meet NIS2 expectations
We’re ISO 27001:2022 and ISO 9001:2015 certified, about 55 people with 40+ engineers, and we build software for clients across Europe and North America from Sarajevo, in the CET time zone. We can build new products to these standards or help your team add the logging, vulnerability management and documentation customers ask for. Our quality and information security policy and software engineering services show how we work.
If a customer questionnaire is sitting in your inbox, our architects can go through it with you.
Frequently asked questions
Does NIS2 apply to software companies?
It can. Managed service providers, managed security service providers, cloud computing and data centre providers are covered directly under digital infrastructure and ICT service management. Online marketplaces, search engines and social networks fall under digital providers. Both apply when the company is medium-sized or larger. Pure software product vendors are often not in scope themselves, but they must meet the NIS2-driven supply-chain requirements their customers set.
What is the difference between essential and important entities under NIS2?
Essential entities are generally large organisations (250 or more employees, or over €50 million turnover and €43 million balance sheet) in the high-criticality sectors of Annex I, plus some entities regardless of size. Important entities are the other in-scope medium and large organisations. Both follow the same security and reporting duties. Essential entities face proactive supervision and fines up to €10 million or 2% of turnover, important entities up to €7 million or 1.4%.
Has NIS2 been transposed in every EU country?
Not fully. The deadline was 17 October 2024. Most Member States had national laws by mid-2026, including Germany (in force since 6 December 2025) and Italy, and the Dutch law entered into force in August 2026. In July 2026 the Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice, and reports in September 2026 said Ireland, Spain and France still had no adopted law. Check the national authority for each country you operate in.
Is ISO 27001 enough for NIS2 compliance?
Not on its own, but it's the most practical base. ISO 27001:2022 and its Annex A controls cover most Article 21 measures, including risk assessment, supplier security, secure development, access control, cryptography and business continuity. You still need the NIS2-specific items: registration with the national authority, management body approval and training, and incident reporting within 24 and 72 hours.
More resources
