The NIS2 (Network and Information Security) Directive represents the most ambitious overhaul of the European legislative framework for cybersecurity. Faced with the increasing professionalization of cybercrime and the growing digitalization of the economy, the European Union decided to massively expand the scope of its security rules, now affecting thousands of companies that were previously unregulated.

1. History: From NIS1 to NIS2

To understand the scope of NIS2, we need to look back at the limitations of the first iteration and the evolution of the threat.

Adoption of the NIS1 Directive

July 2016

First European legislation on cybersecurity. It targets only a limited number of Operators of Essential Services (OES) and Digital Service Providers (DSPs).

Evaluation and identification of limitations

2020 – 2021

The European Commission notes a fragmentation: transposition varies considerably between Member States. The scope of NIS1 proves too limited in the face of the explosion of ransomware attacks and supply chain vulnerabilities (e.g., the SolarWinds case).

Official adoption of NIS2

December 2022

The European Parliament and the Council adopt the NIS2 directive to harmonize security levels, expand the sectors concerned and strengthen sanctions.

European entry into force

January 2023

The directive officially enters into force, triggering the countdown for member states.

Transposition deadline

October 17, 2024

Deadline for Member States (including Belgium, under the leadership of the Centre for Cybersecurity Belgium – CCB) to integrate NIS2 into their national law.

2. The new scope: Who is affected?

The directive abandons the old classification system to create two new categories, based primarily on the size-cap . Generally, medium and large companies (more than 50 employees or more than €10 million in turnover) operating in the sectors concerned are automatically subject to the directive.

However, the major revolution of NIS2 is the domino effect on the supply chain. Even a small structure (VSE/SME) may be forced to align with these standards if it is a supplier or subcontractor of a subject entity.

CategorySectors concernedMaximum penalties
Essential Entities (EE)Energy, Transport, Banking, Financial Markets, Health, Drinking Water, Wastewater, Digital Infrastructure (Cloud Providers, DNS, Datacenters), Space, Public Administration.10 million euros or 2% of global turnover (whichever is higher).
Significant Entities (SE)Postal services, Waste management, Chemicals, Agri-food, Manufacturing of medical and electronic devices, Digital service providers (search engines, social networks).7 million euros or 1.4% of global turnover.

3. Compliance: Technical and organizational obligations

Article 21 of the directive details the risk management measures that companies must implement. The approach is no longer based on mere recommendations, but on an obligation to achieve results in terms of resilience.

A. Governance and Management Responsibility

Cybersecurity is no longer relegated to the IT department alone. Management bodies (C-Level, Board of Directors) must approve security measures, undergo specific training, and can be held personally responsible in the event of serious breaches (up to and including temporary suspension from management positions).

B. Risk Management and Technical Security

Companies must deploy a technical arsenal covering all information systems:

  • Access Control and Authentication: Systematic deployment of Multi-Factor Authentication (MFA) and strict identity management.
  • Cryptography: The use of encryption to protect data at rest and in transit.
  • Human resources security: Access policies, ongoing employee training to address threats (phishing, social engineering).
  • Network security: Network segmentation, firewall deployment and maintenance of security conditions (patch management).

C. Business Continuity and Crisis Management

An attack must not paralyze the entity indefinitely. The following is required:

  • The implementation of backup policies (immutable backups, tested regularly).
  • An operational Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
  • Clearly defined crisis management procedures.

D. Supply chain security

This is the key point of focus. Companies subject to these regulations must assess and manage the risks associated with their IT suppliers and service providers (managed services, cloud providers, software publishers). This translates into supplier audits and the inclusion of strict security clauses in B2B contracts.

E. Incident Notification

The reporting timeline to national authorities (such as the CCB) becomes extremely tight in the event of a major incident:

  • Early warning: Within 24 hours.
  • Full incident notification: Within 72 hours.
  • Final report: Within a maximum of one month.

4. Action plan: How should companies prepare for this?

To achieve compliance without disrupting production, companies must adopt a methodical approach:

  1. Perform a diagnostic (Gap Analysis): Map the current infrastructure, identify critical processes and measure the gap with NIS2 requirements. (In Belgium, the use of the CyberFundamentals is strongly recommended as a basis for evaluation).
  2. Mapping the information system: You can only protect what you know. It is vital to inventory all hardware assets (servers, workstations, network equipment) and software.
  3. Strengthen IT hygiene: Enable MFA everywhere, systematize offline/immutable backups, and automate the deployment of security updates.
  4. Auditing suppliers: Sending security questionnaires to key partners and reviewing contractual SLAs.
  5. Documentation: NIS2 compliance requires evidence. Every security process, recovery plan, and policy must be documented, tested, and updated.

In conclusion, the NIS2 directive transforms cybersecurity into a legal pillar of corporate governance. While the initial workload for achieving compliance is significant, it represents an essential investment to ensure the company's long-term viability in the face of increasingly systemic cyber risks.

Categories: