The NIS2 Directive became law in all EU member states in October 2024. For many organisations — particularly those that are newly in scope — the past eighteen months have been a grace period in practical terms. That period is ending. Supervisory authorities across the EU are issuing their first significant penalties and, more consequentially, establishing the precedents for management-level personal liability that NIS2 introduced for the first time.
This briefing covers what NIS2 actually requires, where enforcement attention is focusing in 2026, and how CISOs should prioritise if their programmes are not fully compliant.
Who Is In Scope
NIS2 expanded the scope of the original NIS Directive substantially. The essential entities and important entities categories now cover:
Essential entities (subject to stricter supervision and higher penalties):
- Energy (electricity, oil, gas, hydrogen, district heating)
- Transport (air, rail, water, road)
- Banking and financial market infrastructure
- Health (hospitals, laboratories, pharmaceutical manufacturers)
- Drinking water and wastewater
- Digital infrastructure (internet exchange points, DNS, TLD registries, cloud providers, data centres, CDNs, TSPs, electronic communications networks)
- ICT service management (managed service providers, managed security service providers)
- Space
- Public administration (central government)
Important entities (proportional supervision, lower penalties):
- Postal and courier services
- Waste management
- Chemical production and distribution
- Food production and distribution
- Medical device manufacturing
- Computer and electronics manufacturing
- Digital providers (online marketplaces, online search engines, social networks)
- Research organisations
The size thresholds (medium enterprises: 50+ employees or €10M+ turnover; large enterprises: 250+ employees or €50M+ turnover) mean many mid-market organisations are in scope for the first time. Crucially, NIS2 also imposes obligations on essential and important entities’ supply chains — creating downstream pressure on suppliers of all sizes to demonstrate security posture.
The Core Obligations
NIS2 Article 21 sets out the mandatory security measures. These are not optional or aspirational — they are the baseline against which supervisory authorities will assess compliance:
Risk management: A documented methodology for identifying, assessing, and managing cybersecurity risks, reviewed regularly and following material incidents.
Incident handling: Policies and procedures for detecting, classifying, responding to, and recovering from incidents. For essential entities, this includes tested response capabilities, not just documented ones.
Business continuity: BCM plans that cover cybersecurity incident scenarios, including backup restoration, crisis communications, and emergency operations. Plans must be tested.
Supply chain security: Assessment of the security of direct suppliers and service providers. For critical functions, this means contractual security requirements and evidence of their fulfilment — not just questionnaires.
Procurement and development security: Security requirements embedded in procurement processes, software development, and acquisition of IT/OT systems.
Security effectiveness assessment: Regular testing, vulnerability assessments, and — for essential entities — penetration testing.
Cryptography and encryption policies: Documented policies covering cryptographic standards for data at rest and in transit, with specific attention to quantum-readiness emerging as a supervisory expectation in 2026.
Personnel security and access control: Policies covering vetting, privileged access management, and training obligations.
Multi-factor authentication: MFA required for all remote access and for access to systems supporting critical functions. For essential entities, supervisory authorities are treating absence of MFA as a significant deficiency.
Asset management: Maintained inventory of network assets and information assets, with documented classification.
The Incident Reporting Obligation
NIS2 introduced a tiered incident notification requirement that is stricter than most national cyber notification rules it replaced:
- Within 24 hours: Early warning to the national competent authority when a significant incident is suspected. This is a suspicion notification, not a confirmed assessment.
- Within 72 hours: Initial incident notification with an initial assessment — severity, likely impact, indicators of compromise where available.
- Within one month: Final report covering full incident assessment, root cause analysis, mitigation measures taken, and cross-border impact where relevant.
A “significant incident” is defined as one that causes or can cause severe operational disruption or financial loss to the entity, or affects other persons through considerable damage. The threshold is deliberately broad. Supervisory authorities in Germany, Netherlands, and France have indicated they expect entities to notify even where the outcome of significance assessment is uncertain.
CISO action: Review your incident classification and escalation procedures against this timeline. Most organisations have a 72-hour internal escalation process that was calibrated to GDPR. NIS2’s 24-hour early warning requires earlier detection, faster internal escalation, and a prepared notification process. The bottleneck is typically the internal decision and approval process for regulatory notifications — not the technical detection capability.
Management Liability: The Personal Exposure
The most consequential change NIS2 introduced is management-level personal liability. Article 20 requires member states to ensure that management bodies of essential and important entities:
- Approve cybersecurity risk management measures
- Oversee implementation
- Can be held personally liable for infringements
Several EU member states — including Germany, Netherlands, and Belgium — have implemented provisions enabling regulatory authorities to impose personal fines on named executives, prohibit individuals from exercising management functions, and require certification of compliance by the responsible executive.
This is not theoretical. Germany’s BSI issued its first management-level notices under NIS2-implementing legislation in Q1 2026. The Netherlands’ NCSC has indicated its supervisory authority intends to use personal liability provisions as an enforcement lever in 2026.
Board implication: NIS2 compliance is not an IT programme that the CISO owns. It is a governance obligation that the board and senior management own, with the CISO as the accountable delivery lead. The paper trail matters: board minutes reflecting security risk discussions, documented risk acceptance decisions, evidence that management received and acted on compliance status reporting.
Penalties
Essential entities face penalties of up to €10 million or 2% of total global annual turnover (whichever is higher). Important entities face up to €7 million or 1.4% of global annual turnover. These are maximum figures; supervisory authorities have discretion to apply them proportionately. Early enforcement actions in 2026 have focused on systemic failures (absence of incident reporting capability, no risk management process) rather than technical control gaps.
Prioritisation for Organisations That Are Behind
If your organisation is materially behind on NIS2 compliance, the following sequencing reflects supervisory authority priorities and the highest-risk liability exposures:
First priority — Incident reporting capability: The 24-hour early warning and 72-hour notification obligations are the most operationally novel requirement. If you do not have a tested process for regulatory notification, this is the highest-urgency gap. A regulatory notification failure during an incident — after having had 18+ months to prepare — will attract a different level of supervisory scrutiny than a technical control gap.
Second priority — Board engagement and governance documentation: Establish the documented evidence trail that management is engaged with cybersecurity risk. This means board-level reporting, documented decisions on risk acceptance, and evidence of oversight. This directly addresses the personal liability exposure.
Third priority — Supply chain security: Identify your critical suppliers and begin the assessment process. Regulators are clear that “we haven’t assessed our suppliers” is not an acceptable position for an essential entity. Start with the suppliers whose compromise would have the highest impact on your critical functions.
Fourth priority — MFA and access control: Absence of MFA for privileged and remote access is a finding that supervisory authorities have indicated they will treat as significant in any inspection.
The remaining Article 21 obligations — risk management documentation, BCM, asset management, security testing — are important, but regulators are likely to be more understanding of a programme that is in progress than one that has not started. The four priorities above represent the gaps most likely to result in enforcement action if an incident occurs during an inspection period.
What Supervisory Authorities Are Looking For
Based on published supervisory priorities and early enforcement signals across the EU:
- Evidence of genuine board engagement, not just a CISO presentation slide deck
- A functional incident reporting process with named roles and tested procedures
- Actual supply chain security assessments, not questionnaires filed and forgotten
- MFA deployment status for critical systems and remote access
- Whether security risk management is integrated into business decisions or treated as a separate IT exercise
NIS2 supervisory authorities are not primarily looking for perfect technical compliance. They are looking for evidence that the organisation has genuinely implemented a risk management approach — that cybersecurity decisions are made deliberately, with appropriate governance. Organisations that can demonstrate this, even imperfectly, are in a materially different position than those that cannot.