42 Rue Broca, 75005 Paris, France
The NIS2 Directive: technical and business challenges for responsible organisations
The NIS2 Directive marks a turning point in the management of cybersecurity in Europe. It requires a higher level of technical requirements, but above all the integration of cyber resilience into organisations’ business strategy and governance. Those in charge should view this regulatory constraint as an opportunity: to strengthen customer trust, secure growth, and position themselves as responsible players in an increasingly demanding market.
Successful NIS2 compliance is based on three pillars: management mobilisation, integrating security throughout the value chain, and continuous improvement of practices. Those who can anticipate and steer this transformation will emerge stronger, both operationally and commercially.
NIS2 Directive: Key takeaways
The European NIS2 Directive imposes new cybersecurity obligations on a wide range of organisations, far beyond critical infrastructures alone. It requires rigorous risk management, securing the supply chain, rapid incident notification procedures, and directly involves senior management, with severe penalties in the event of non-compliance. For businesses, NIS2 compliance is not just a technical constraint: it becomes a major business issue, determining access to markets and partner trust. Anticipating and managing this transformation is essential to remain competitive and resilient.
1. NIS2: origin, objectives and scope
From NIS to NIS2: why a new directive?
The first NIS Directive, adopted in 2016, aimed to improve the resilience of critical infrastructures (energy, transport, health, etc.) against cyber threats. However, its implementation revealed limitations: uneven implementation across countries, too narrow a scope, and a lack of clarity on obligations and penalties. NIS2 addresses these weaknesses by broadening the range of entities concerned and harmonising requirements at European level.
Strategic objectives of NIS2
- Raise the level of cybersecurity across the entire European economic fabric.
- Strengthen the resilience of supply chains.
- Ensure a coordinated and effective response to major incidents across the EU.
- Reduce national disparities in cybersecurity.
A broader, structured scope
Unlike NIS1, NIS2 applies to 18 sectors deemed critical or strategic, classified into two categories: essential entities (EE) and important entities (IE). This classification determines the level of supervision and potential penalties.
| Category | Examples of sectors covered | Main inclusion criteria |
| Essential entities | Energy, transport, health, digital infrastructure, public administration | Size, revenue, societal impact |
| Important entities | Industrial manufacturing, agri-food, digital services, waste management | Interdependence, role in the supply chain |
Small businesses (<50 employees and
2. Technical requirements: towards integrated cyber resilience
Risk management: the core of the framework
NIS2 requires a systematic approach to risk management: identification of critical assets, threat assessment (phishing, ransomware, supply chain attacks), implementation of appropriate security policies and a risk management plan (BCP/DRP).
Required technical and organisational measures
- Security of networks and information systems: segmentation, access control, encryption, continuous monitoring.
- Incident management: detection, response, remediation, documentation.
- Rehearsing restoration and service recovery exercises: regular practical exercises to validate the effectiveness of procedures and tools, and to test the disaster recovery plan (DRP) in line with standards such as Rempar25.
- Supply chain security: formalising cybersecurity requirements with suppliers contractually, regular audits, reassessment in the event of a change of provider.
- Training and awareness: direct involvement of management, mandatory training for executives, personal liability in the event of non-compliance.
Reporting and crisis management
Entities must notify any significant incident within a very short timeframe: an initial alert within 24 hours, a detailed report within 72 hours, and a final report within one month. This obligation aims to accelerate the collective response and limit systemic impacts.
3. Business impacts: constraints, risks and opportunities
Increased pressure on the supply chain
One of the major effects of NIS2 is accountability across the entire chain: a large company can no longer tolerate a non-compliant supplier, under threat of penalties and operational risks. SMEs, often the weak links, must therefore demonstrate their robustness through audits, penetration tests, and contractualising security requirements.
Consequences for SMEs and partners
- Need to invest in cybersecurity, even without being directly targeted by the directive.
- Risk of exclusion from tenders or contract termination in the event of non-compliance.
- Opportunity to stand out by demonstrating a higher level of cyber maturity than competitors.
Penalties and executive liability
The penalties provided for by NIS2 are dissuasive: up to €10M or 2% of global turnover for essential entities, €7M or 1.4% for important entities. Executives may be held personally liable and face a temporary management ban in the event of serious non-compliance.
Ongoing governance and improvement
NIS2 compliance is not a one-off state but a continuous process: recurring audits, adaptation to new threats, evolution of internal procedures, proactive supply chain management.
Collaboration and information sharing
NIS2 strengthens cooperation between Member States through the creation of European crisis response networks (EU-CyCLONe), harmonisation of practices, and information sharing on emerging threats.
Key recommendations to achieve NIS2 compliance
To meet the requirements of the NIS2 Directive effectively, it is essential to adopt a comprehensive, structured approach, whatever your profile (essential or important entity, SME, subcontractor, business management). Here are the priority actions to implement:
- Map critical assets and supplier dependencies to identify sensitive points and interconnections that could become risk vectors.
- Update cybersecurity and incident management policies to ensure alignment with NIS2 requirements and current threats.
- Contractualise cybersecurity requirements with all partners and subcontractors, including specific clauses on security, incident management and data backup.
- Train and raise awareness among all employees, from the executive committee to operational teams, to establish a cybersecurity culture at all levels of the organisation.
- Deploy automated monitoring and audit tools to quickly detect any anomaly, vulnerability or intrusion attempt.
- Regularly carry out technical audits (penetration tests, vulnerability scans) and cyber maturity assessments to measure the effectiveness of the measures in place.
- Develop and maintain a risk management plan tailored to the organisation’s size, sector and criticality.
- Anticipate customer requirements to remain competitive and avoid exclusion from strategic markets.
- Integrate NIS2 compliance into your commercial strategy: cybersecurity becomes a differentiating asset and a key selection criterion for customers and partners.
- Allocate a dedicated budget for compliance and increasing cyber maturity, including investments in technical solutions and training.
- Regularly assess exposure to supply chain risks and implement appropriate mitigation measures.
- Deploy a robust backup strategy: regular, offsite, encrypted and tested backups, ensuring geographic redundancy and rapid restoration.
- Organise and repeat crisis management exercises to test team responsiveness, validate incident response procedures, and ensure the real ability to restore data and resume operations within the timeframes imposed by NIS2.
Data Perspective, a recognised expert in backup and data protection, supports organisations with NIS2 compliance: auditing the current situation, defining suitable backup strategies (on-premise, cloud, hybrid), implementing automated, encrypted and offsite solutions, regular restoration tests, and support with documentation and team training.
By making backup a pillar of your NIS2 approach, you will secure your business sustainably and earn the trust of your partners.
Text based on ANSSI’s official resources and analysis of the technical and business impacts of the NIS2 Directive: https://monespacenis2.cyber.gouv.fr/directive/

