What changed from NIS1 to NIS2
NIS2 expands the scope of regulated sectors and introduces a harmonized, more stringent set of cybersecurity risk-management requirements compared to NIS1. It shifts from a flexible framework to mandatory obligations with strict enforcement mechanisms, including higher fines and personal liability for senior management.
What it means
The transition represents a shift toward systemic resilience across the EU. While NIS1 allowed significant variation in how member states implemented security requirements, NIS2 mandates specific areas of focus—such as supply chain security and incident handling—across all regulated entities to ensure a baseline level of protection regardless of geography.
Scope has broadened significantly. The distinction between "Operators of Essential Services" (OES) and "Digital Service Providers" (DSPs) is replaced by "Essential Entities" (EE) and "Important Entities" (IE). This brings in sectors previously excluded, such as waste management, food production, and postal services, based on their criticality to the economy and society.
Crucially, NIS2 elevates cybersecurity from a technical concern to a governance requirement. Senior management is now legally responsible for ensuring risk-management measures are implemented; failure to do so can lead to personal liability and professional sanctions.
How to meet it
- Perform a gap analysis comparing existing security controls against the expanded NIS2 risk-management requirements, specifically focusing on supply chain hygiene.
- Update asset inventories to include not only internal hardware and software but also critical third-party dependencies and service providers.
- Establish a formalized incident response workflow that supports the new, strict reporting timelines (e.g., an "early warning" within 24 hours of discovery).
- Implement a mandatory cybersecurity training program for all staff and specialized governance training for senior management to satisfy liability requirements.
- Develop or update business continuity and crisis management plans to ensure operational resilience during significant disruptions.
- Revise procurement processes and vendor contracts to include mandatory security standards and the right to audit critical suppliers.
Evidence an auditor asks for
- A documented risk assessment that explicitly identifies vulnerabilities within the supply chain and third-party dependencies.
- Timestamps and copies of incident notifications sent to the national competent authority or CSIRT.
- Training logs and completion certificates proving senior management has undergone cybersecurity governance training.
- Records of business continuity exercises, including "after-action reports" showing how plans were tested and improved.
- Signed security addendums or Service Level Agreements (SLAs) with critical vendors that mandate specific security controls.
Common pitfalls
- Assuming a certification like ISO 27001 provides automatic compliance without mapping the specific gaps in NIS2, particularly regarding reporting timelines and supply chain mandates.
- Treating implementation as an IT-led project rather than a corporate governance initiative, resulting in a lack of documented management oversight.
- Overlooking "Important Entity" status under the assumption that only large or highly critical organizations are subject to supervision and enforcement.