Regulations & Compliance
10 min read
January 5, 2026

NIS2 in Practice: What You Must Implement by October 2026

NIS2 in Practice: What You Must Implement by October 2026

The NIS2 Directive (Network and Information Security Directive 2) is the biggest regulatory change in European cybersecurity in years. It broadens the range of entities in scope, introduces heavy financial penalties, and mandates specific technical measures. Here is what you need to know to be ready.

TL;DR - Key takeaways

  • Who Does NIS2 Apply To?
  • Key Obligations
  • Incident Reporting
  • Penalties and Management Accountability

1. Who Does NIS2 Apply To?

NIS2 significantly broadens the range of entities compared to the first NIS directive. The new categories include, among others, cloud service providers, food producers, courier companies, the space sector, public administration, and ICT service providers.

Entities fall into two categories: "essential entities" and "important entities." The main difference is the level of oversight — essential entities are subject to proactive supervision, while important entities face reactive supervision (after an incident).

Heads-Up

If your company employs more than 50 people OR has a turnover above EUR 10 million and operates in one of the covered sectors, you are probably in scope for NIS2. It is worth verifying this as soon as possible.

2. Key Obligations

NIS2 requires organizations to implement proportionate cybersecurity risk-management measures. It is not only about technology — the directive places heavy emphasis on governance, processes, and the supply chain.

  • Risk analysis and an information-systems security policy.
  • Incident management — detection, response, reporting.
  • Business continuity — backups, disaster recovery, crisis management.
  • Supply-chain security — assessment of suppliers and partners.
  • Regular security testing and audits (including penetration tests).
  • Cybersecurity training for management and staff.

3. Incident Reporting

One of the most important NIS2 requirements is the obligation to report security incidents within strict time frames. Organizations must submit an early warning within 24 hours of detecting an incident, and a full report within 72 hours.

This means an organization must have an incident-response process in place with clearly defined roles, escalation procedures, and communication channels with the relevant CSIRT.

4. Penalties and Management Accountability

NIS2 introduces personal accountability for management in implementing cybersecurity measures. This is a landmark change — leadership can no longer delegate responsibility "down" the organization.

Financial penalties can reach EUR 10 million or 2% of annual turnover (for essential entities), or EUR 7 million or 1.4% of turnover (for important entities) — whichever amount is higher.

PWNONE Recommendation

Start with a gap analysis — compare your current security posture against the NIS2 requirements. This lets you estimate the budget and time needed to comply. Our team can run such an audit in 2–3 weeks.

Summary

NIS2 is not just another formality — these are real requirements, and failing to meet them carries serious financial and legal consequences. The key is to start preparing early and to treat compliance as a continuous process rather than a one-off project.

Need help implementing NIS2?

We help organizations work through the NIS2 requirements — from gap analysis, through policy implementation, to the regular penetration tests the directive requires.

Order a NIS2 audit