NIS2 without panic
Sooner or later it arrives: an email from your consultant, a circular from your trade association, a large customer sending a security questionnaire. "Your company falls under NIS2." The reactions I see are two, opposite and equally wrong: panic, with a rush to buy anything with "cyber" in its name, and denial, "we are small, this is not about us". It is worth understanding what this piece of EU law actually asks, because the answer is less frightening than the panic and more serious than the denial.
What we are talking about
NIS2 is the European Union directive on cybersecurity, transposed into national law across member states. The core idea is simple: there are companies whose outage or breach causes damage beyond their own gates, and those companies must manage digital risk the way they already manage workplace safety. Each member state has a national authority supervising it.
The surprise, for many, is the scope: we are not talking about banks and giants. The sectors involved include waste management, chemicals, food, parts of manufacturing, transport, digital services. And the size threshold typically starts at the mid-sized company: roughly from fifty employees or ten million euro of turnover upwards, in the listed sectors. Across Europe, tens of thousands of mid-sized companies are in scope, and many do not know it yet.
A detail that owners underestimate: the directive addresses management bodies directly. Directors must approve the measures, train, and answer for omissions. It is not a file you hand to the IT supplier and forget.
What it actually asks
Stripped of legal language, NIS2 asks four things.
First: know you are in scope. Verify whether you fall under the rules and register with your national authority where required.
Second: manage risk with concrete measures. The technical list is long but the meaning is this: know what systems and data you have, control who accesses them and how (strong authentication, role-based permissions), have backups that actually work and a plan for when things go wrong, keep systems updated, protect data, and look at your suppliers too, because attacks often walk in through a neglected vendor.
Third: report significant incidents. On tight clocks: an early warning within twenty-four hours, the full notification within seventy-two. Which presupposes something non-trivial: noticing the incident, and knowing who does what when it happens.
Fourth: be able to prove it. Measures must exist and be documented: an inspection is not passed with words.
The good news nobody mentions
Here is the point that removes the panic: most of what NIS2 asks is what a healthy company should be doing anyway. Knowing what you own, controlling access, tested backups, an incident plan, suppliers chosen with care: none of this is invented bureaucracy. It is hygiene, which the law turns into an obligation. For many mid-sized companies NIS2 is the occasion, paid for by the legislator, to do the tidying up that had been postponed for years.
How to face it with method
I have been through this journey from the inside, for a company that qualifies as an "important entity" under the directive, and the method is the same one I use for digitalization: one building block at a time. You start with an honest gap analysis: the authority's specifications list the required measures, and for each one you answer without indulgence: done, partial, missing. Out comes the real map, which is almost never as disastrous as feared and never as rosy as hoped. Then you order by risk, and you remediate one piece at a time, with real deadlines.
And here is the point I care about most, because it is where compliance succeeds or fails: measures must live in the systems. "Access control" is not a paragraph in a document: it is strong authentication actually enabled, role-based permissions actually configured, logs actually recording. The document describes what the systems do, it does not replace it. A dossier written by someone who never touches the systems produces paper that protects from nothing, except from the feeling of having done nothing.
The objections I always hear
"We are small, it does not concern us." Maybe. But that is something to verify: sector and size can be checked in an hour. And even companies not directly in scope will get it second-hand: customers who are in scope must vet their suppliers, and the security questionnaires are already circulating. Being ready before a customer asks is a better position than chasing afterwards.
"We have a firewall and an antivirus." Good, but NIS2 does not ask for products: it asks for governance. Who decides, who is responsible, what happens when something goes wrong, how suppliers are chosen. Technology is perhaps a third of the work.
"We will hand everything to a consultant and stop thinking about it." The right consultant helps, but responsibility stays with management, by law. And a stack of documents bought by the kilo, without the systems changing accordingly, survives neither an inspection nor, above all, a real incident.
What to take home
Three steps to take this week. Verify whether you are in scope: sector plus size, an hour of work with someone who knows the rules. If you are, sort out the registration with your national authority. And start the gap analysis on the baseline measures, with one criterion to judge it when it lands: every measure must point to something that exists in the systems. If the remediation plan only produces documents, you are buying paper.
Want to find out whether your company is in scope, and where it stands? Let's talk.