Skip to main content
NIS2 Compliance | NOVTRIQ
Home / Compliance / NIS2

NIS2 Compliance

Directive 2022/2555/EU on network and information security — cybersecurity obligations for essential and important entities across 18 critical sectors.

Get a compliance assessmentFree tools

Understanding NIS2

NIS2 (Directive 2022/2555/EU) is the EU's updated network and information security framework, replacing the original NIS Directive. It entered into force in January 2023 and required transposition into national law by October 2024.

NIS2 significantly expands the scope of cybersecurity obligations — covering 18 sectors and distinguishing between 'essential entities' (subject to stricter supervision) and 'important entities'. For the first time, large manufacturers, waste management companies, and food processors are explicitly within scope.

A key feature of NIS2 is its explicit applicability to operational technology (OT) and industrial control systems. Organisations with SCADA, BMS, or ICS infrastructure connected to IT networks must address OT-specific cybersecurity risks under Article 21.


Who is affected

Sectors and entity types within the scope of NIS2.

Essential Entities — Annex I

Energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space.

Important Entities — Annex II

Postal and courier services, waste management, chemical manufacturing and distribution, food production, manufacturing (medical devices, electronics, machinery, motor vehicles), digital providers.

OT-Exposed Organisations

Any organisation in scope that operates SCADA, PLCs, DCS, BMS, or other operational technology connecting physical and cyber systems.


Key requirements

The principal obligations imposed by NIS2.

Risk Management Measures

Organisations must adopt proportionate technical and organisational measures to manage cybersecurity risk — covering governance, incident handling, supply chain security, and OT security.

Incident Reporting

Significant incidents must be reported to the competent authority within 24 hours (early warning) and 72 hours (full notification). ENISA maintains the EU cybersecurity incident reporting database.

Supply Chain Security

Organisations must assess the cybersecurity posture of key suppliers and service providers — including software, hardware, and cloud services in scope.

Management Accountability

Senior management must approve and oversee cybersecurity risk management measures. Individuals can be held personally liable for non-compliance.

Enforcement & Penalties

Essential entities: fines up to €10M or 2% of global annual turnover. Important entities: fines up to €7M or 1.4% of global annual turnover.


How NOVTRIQ can help

Engineering services applicable to NIS2 compliance.

OT Cybersecurity Assessment — NIS2 Article 21-aligned OT security gap analysis — asset inventory, network architecture review, and prioritised remediation roadmap.

Incident Response Planning — OT-specific incident response plan, notification procedures, and tabletop exercise facilitation.

Supply Chain Security Review — Cybersecurity assessment of critical OT suppliers and service providers — aligned to NIS2 Article 21(2)(d).

Management Briefing — Executive-level NIS2 briefing and risk presentation — satisfying management oversight obligations under Article 20.


Relevant tools

Run preliminary assessments — no account required.

NIS2 OT CheckerBuilding Readiness
All tools

Key deadlines

Compliance milestones you need to plan around.

Jan 2023
NIS2 Directive enters into force
Directive 2022/2555/EU published and in force across EU.
Oct 2024
Transposition deadline
All EU member states required to enact national NIS2 legislation.
Oct 2024
Enforcement active
Competent authorities begin active supervision and enforcement of NIS2 obligations.
Ongoing
Incident reporting
24/72-hour reporting obligations for significant cybersecurity incidents are live.

Get a NIS2 compliance assessment

Our engineering team delivers structured compliance assessments with actionable remediation roadmaps.

Contact usJoin waitlist