NIS2 Directive: A Practical Guide for Multinational Businesses

NIS2 directive

The NIS2 directive sets cybersecurity and incident-reporting duties for organisations in specified sectors across the EU. If your business operates in several countries, supplies a covered organisation or relies on international IT providers, check both your legal scope and the rules in each relevant Member State.

NIS2 compliance starts by confirming whether your organisation is covered. The directive calls for a proportionate cybersecurity strategy addressing cyber threats, active management oversight, security measures and a working process for reporting significant incidents.

Key takeaways

  • NIS2 covers 18 sector groups, but sector and size tests must be applied together.
  • Essential and important entities share core security and reporting duties.
  • Incident reporting for significant incidents includes a 24-hour early warning, a 72-hour notification and a final report, generally within one month.
  • ISO 27001 can support compliance work, but certification does not prove NIS2 compliance.
  • Multinational groups need a clear view of local entities, regulators, suppliers and reporting routes.

What the NIS2 directive changes from NIS1

NIS2, formally Directive (EU) 2022/2555, updates the EU’s original 2016 Network and Information Security Directive. It came into force in January 2023, with member states required to transpose it into national law by 17 October 2024. The directive has applied through national implementing laws since 18 October 2024, although details and competent authorities vary by country.

The earlier framework covered fewer sectors and allowed more variation between national approaches. NIS2 widens the scope, sets more detailed minimum risk-management duties and strengthens supervision and enforcement. It also makes management bodies directly responsible for approving and overseeing cybersecurity measures.

For businesses operating across borders, the change is practical as well as legal. The directive sets a baseline across the European Union, but national implementing laws shape the regulatory landscape and determine competent authorities. A group may need to identify different regulated entities, national reporting channels and local requirements, rather than treating cybersecurity as a single head-office policy. The European Commission’s NIS2 overview sets out the directive’s broad purpose and sector coverage.

Who is in scope?

Sectors and size thresholds

NIS2 covers 18 sector groups. Annex I includes energy, transport, banking, financial market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space. Annex II covers postal and courier services, waste management, chemicals, food, manufacturing, digital providers and research.

In general, an organisation in one of these sectors is covered if it qualifies as a medium-sized or larger enterprise. The familiar “50 employees or €10 million turnover” summary is only a starting point. The EU enterprise-size test considers employee numbers and financial thresholds, including annual turnover or balance sheet, as well as links to partner or associated businesses.

Some providers, including essential entities identified by a Member State, can fall within scope regardless of size. A designation may reflect a role in critical infrastructure under applicable EU or national criteria, or the provision of a particular service. Check the relevant national law and regulator’s guidance rather than relying on a headcount estimate alone. The official NIS2 text sets out the full scope rules and sector definitions.

Essential and important entities

NIS2 divides covered organisations into two categories. Classification depends mainly on the organisation’s sector and size, with national authorities responsible for identifying and supervising entities as required.

Both categories must meet Article 21 risk-management requirements and Article 23 incident-reporting duties. The distinction mainly affects supervision and the financial penalty bands that may apply. An entity in the less strictly supervised category is not exempt from core obligations.

What NIS2 compliance requires

Article 21: risk management and supply chains

Article 21 requires appropriate, proportionate technical, operational and organisational measures. Organisations must take an all-hazards approach, with controls for cyber attacks and other cyber threats, as well as equipment failure, human error and disruption at suppliers.

The required areas include risk analysis, incident handling, business continuity and recovery, vulnerability management, security testing, network security, cyber hygiene, staff training and cryptography where appropriate. Supply chain security is a specific requirement: assess the security of direct suppliers and service providers, including their vulnerabilities and the quality of their security practices.

A useful first step is to map critical services and the systems, people and suppliers they depend on. Record who owns the security requirements, what evidence supports each control and how the organisation will respond if a supplier or system becomes unavailable.

Management oversight

Management bodies must approve the organisation’s cybersecurity measures and oversee their implementation. They must also undertake cybersecurity training. This makes security a governance responsibility for senior management, not a matter that can be left entirely to IT.

For a multinational group, clarify which board or executive team approves group-level controls and who is accountable for local entities. Keep evidence of decisions, training, risk reviews and follow-up actions. Personal consequences depend on national implementing law, so avoid assuming that NIS2 creates one uniform personal fine across the EU.

If you already hold ISO 27001 certification, use its risk register, audit records and control framework as useful information security evidence. Then run a documented gap assessment against NIS2, including scope, incident reporting, management duties and national requirements. Certification alone does not establish compliance.

Prepare for the 24-hour and 72-hour reporting deadlines

The sequence for incident reporting applies to a significant incident, not every security alert. Under Article 23, the clock starts when the organisation becomes aware of such an incident. Confirm in advance who can make that assessment and who has authority to contact the relevant national CSIRT or competent authority.

Build the reporting timeline

  • Within 24 hours: Send an early warning. State whether unlawful or malicious activity is suspected and whether the incident may affect other countries.
  • Within 72 hours: Submit an incident notification with an initial assessment of severity and impact. Include indicators of compromise where available.
  • Within one month: Provide a final report. If the incident is still ongoing, provide a progress report and submit the final report after handling is complete.

These deadlines require a process, not merely a policy. Keep a current incident contact list, define escalation thresholds and prepare templates for the first two notifications. Also record when the organisation became aware of the incident, what facts were known at each stage and why it classified the event as significant.

Rehearse across borders

A multinational incident may affect systems or services in more than one country. Map which entity is affected, which national authority it reports to and whether local rules add requirements. A central security team can coordinate the facts, but local owners need clear instructions and access to the right reporting channel.

Make a multi-country compliance programme workable

A scope register is a practical first step towards NIS2 compliance. List each group company, its services, sector, size, Member State presence and likely classification. Record regulator correspondence, then ask local legal or compliance teams to validate the assessment.

Next, compare existing controls with the Article 21 requirements. A shared framework can reduce duplication, but local entities still need clear owners and evidence. Keep a central register of key suppliers, system access, security terms, incident contacts and continuity arrangements.

This is especially useful when procurement involves global IT support, international IT support or a provider delivering worldwide IT support. Ask whether contracts cover incident notification, vulnerability handling, audit evidence, subcontractors and recovery expectations. A multinational IT support model should clarify who acts when cyber threats affecting a supplier cross country or entity boundaries.

The same review applies to global IT services, international IT services and multi-country IT support. Organisations sourcing IT support for multinational companies or IT support for international businesses should identify which legal entity contracts for each service, and where the provider’s staff can access data or systems. That detail can shape the supply chain security assessment.

Finally, test the arrangements. A tabletop exercise can check whether local teams can escalate quickly, decision-makers can approve notifications, and remote IT support can isolate affected systems without disrupting other locations. Managed monitoring can help teams detect and investigate incidents. For example, Managed SIEM Services may support a wider security programme. An IT Security Audit can help identify gaps in controls and evidence.

For a business reviewing global technology support or broader IT support services, the aim is to make security responsibilities explicit across the whole service chain. Zero Through also offers Get IT Support for businesses with distributed operations.

Penalties, UK businesses and national rules

For essential entities, Member States must provide for maximum financial penalties of at least €10 million or 2% of worldwide annual turnover, whichever is higher. For important entities, the equivalent maximum level is at least €7 million or 1.4% of worldwide annual turnover, whichever is higher. These are maximum levels required under Member State law, not automatic fines for every breach. Authorities assess cases under national law.

NIS2 is an EU directive, so a UK-only organisation is not automatically covered simply because it trades internationally. The regulatory landscape differs between the EU and UK. For NIS2 compliance, UK businesses should assess whether an EU-established group entity or service falls within scope, or whether their supplier role creates contractual security requirements. Personal liability depends on the applicable national implementing law; NIS2 does not establish one uniform personal fine. Check the relevant Member State law and seek advice where the position is uncertain.

The consequences can also include corrective orders, audits and reputational harm. Keep records showing how risks were assessed, who approved controls and how incidents were handled. For a broader security review, Zero Through can help businesses Protect Your Business with practical cybersecurity services.

NIS2 FAQs

Does NIS2 apply to every company with 50 employees?

No. The size threshold does not apply in isolation. The organisation must generally operate in a listed sector and meet the relevant enterprise-size test, while certain entities can be covered regardless of size. Check group relationships and national implementation as well as the organisation’s own headcount and finances.

Does ISO 27001 certification mean we comply?

No automatic equivalence exists. ISO 27001 can provide useful evidence and controls, but organisations still need to map their arrangements against NIS2, confirm their scope and meet applicable reporting and management requirements.

What counts as a significant incident?

NIS2 defines significant incidents by their impact, including serious operational disruption or financial loss, and harm to others through considerable material or non-material damage. Establish an escalation process so qualified staff can assess impact promptly and preserve a record of the decision.

Turn NIS2 into an operational plan

NIS2 compliance starts with an accurate scope assessment, then depends on risk controls, management oversight and a tested reporting process. Multinational organisations should make responsibilities clear across entities, suppliers and countries, rather than assuming one policy covers every legal obligation.

If you need to identify control gaps or check whether your response plan is ready, Book a Security Review with Zero Through.

Tags

What do you think?

Related articles

CONTACT US

Robust IT support & Cybersecurity Services

Whether you operate from one location or across multiple countries, we can help you understand your technology and security priorities and identify the areas that require attention.

Speak to our team about your current environment, your challenges and your plans for growth.

Your benefits:
What happens next?
1

Schedule a call or a face to face meeting

2

We’ll review your current setup, requirements and security priorities

3

We provide a tailored proposal with clear and transparent pricing

Book a free security review