In short
NIS2 is a board-level governance obligation, not merely an IT security project — accountability cannot be delegated. Entities in scope need documented risk management measures, defined reporting paths on the 24-hour, 72-hour and one-month clocks, business continuity, and evidence that management approved and supervises those measures.
Table of Contents
What is NIS2 and Why Does It Matter for IT?
The Network and Information Systems Directive 2 (NIS2) is an updated EU cybersecurity regulation replacing the original NIS Directive from 2016. Adopted in 2022, its national transposition deadline expired on 17 October 2024. Germany transposed NIS2 through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG), in force since December 2025, with the registration deadline for affected entities passing in March 2026.
NIS2 applies to two categories: critical infrastructure (energy, healthcare, finance, water, transport) and important sectors (digital services, retail, logistics, postal). The regulation mandates minimum security standards, incident reporting, business continuity, and supply-chain security. What many IT teams miss: responsibility lies with the board and executive management, not just the security team. This makes NIS2 a governance problem, not just a technical one.
The five core NIS2 obligations are: (1) implement information security measures (access controls, encryption, patches), (2) report incidents within 24–72 hours, (3) establish business continuity and risk management plans, (4) manage supply-chain security, and (5) report to authorities. Non-compliance can result in fines up to €10 million or 2% of annual revenue. This is not a suggestion — it is mandatory.
Key insight for CIOs: NIS2 is non-negotiable. It is not an optional security framework you can implement gradually. Every IT department in scope must ask: Am I compliant today, or do I need a transformation? The answer for most organizations is transformation.
For a quick baseline first: the free NIS2 readiness check delivers a maturity score across 6 domains plus top actions in 3 minutes.
NIS2 is a governance mandate, not just a security project. Board-level accountability is not optional.
NIS2 Compliance Requirements: Five Core Domains
NIS2 structures compliance into five measurable domains. This framework helps IT teams translate governance into operations and measure compliance readiness. Vague requirements are not acceptable — NIS2 demands specificity.
Domain 1 – Information Security: Organizations must implement security measures: access controls (least privilege), encryption (in transit and at rest), patch management (regular updates), secure development practices, and security testing. Having a policy is not enough — security must be embedded in code and processes. Compliance means documented, tested, auditable security.
Domain 2 – Incident Response: Organizations must detect security incidents within 24 hours, report to authorities within 72 hours, and notify affected parties. This requires a documented incident management process: defined roles, escalation paths, secure communication channels. The 72-hour deadline is non-negotiable and strictly enforced. Germany uses meldestelle@bsi.bund.de for incident reporting.
Domain 3 – Business Continuity: Organizations must restore operations after critical system failures. This requires backup strategies, redundancy, failover systems, and annual recovery testing. For IT: RPO (Recovery Point Objective) and RTO (Recovery Time Objective) must be defined for all critical systems. Testing evidence is mandatory — theory alone does not suffice.
Domain 4 – Supply-Chain Security: Responsibility extends to third parties: cloud providers, integrators, hosting partners. NIS2 requires SLAs with security terms, audit rights, and incident notification obligations. You remain responsible for incidents at your vendors — you cannot delegate accountability.
Domain 5 – Governance and Reporting: The board must receive regular compliance reports from executives. IT must provide monthly or quarterly dashboards: patch rates, incident response times, audit findings, security training completion. This is not technical jargon — it is business risk reporting.
| Domain | Core Responsibility | IT Team Actions | Key Metrics |
|---|---|---|---|
| Information Security | Access, encryption, updates | Implementation + audits + docs | Patch %, control audit trails |
| Incident Response | 24h detection, 72h authority reporting | Monitoring, SIEM, escalation | MTTD, MTTR, reporting compliance |
| Business Continuity | RTO/RPO defined, backups tested | Backup infrastructure, failover testing | RPO/RTO in minutes, test success rate |
| Supply Chain | Vendor security audited | SLA review, vendor audits | Vendors audited, audit findings |
| Governance | Board reporting, KPIs | Metrics tracking, management dashboards | Reporting completeness, risk trends |
12-Month Implementation Roadmap
Many IT teams do not know where to start. Here is a structured, proven 12-month plan for organizations not yet NIS2-compliant.
Months 1–2: Baseline Assessment. Document current state: Which security controls exist? Which are missing? Is incident response documented? Does a business continuity plan exist? Score each 0–5. This assessment guides your remediation plan.
Months 3–4: Establish governance structure. Define roles (CISO, CIO, ops lead, incident response team). Write IT security policies. Set up management reporting (monthly dashboard). The executive team must understand: NIS2 governance flows top-down.
Months 5–6: Implement security baselines. Patch management (automated, tested), multi-factor authentication for privileged accounts, encryption of critical data, endpoint detection and response (EDR). These are non-negotiable. Budget: 10–15% of IT budget.
Months 7–8: Set up incident response. Document process, roles, escalation. Train the team (tabletop exercises). Test 72-hour notification capability to authorities.
Months 9–10: Define business continuity. Set RTO/RPO per system (target: ≤4 hours RTO for critical systems, ≤1 hour RPO). Implement backups (daily minimum), test recovery monthly. Document disaster recovery plans.
Months 11–12: External audit and proof of compliance. Hire auditor. Document control evidence (logs, policies, training records). Create compliance report for board. Plan regular reviews (at least semi-annual).
| Phase | Timeline | Deliverables | Budget |
|---|---|---|---|
| Assessment | Mo 1–2 | Gap analysis, prioritization | Low |
| Governance | Mo 3–4 | Policies, roles, reporting | Low |
| Security | Mo 5–6 | Patch mgmt, MFA, EDR | Medium |
| Incident Response | Mo 7–8 | Process, training, SIEM | Medium |
| Business Continuity | Mo 9–10 | Backup, RTO/RPO, DR tests | High |
| Audit + Proof | Mo 11–12 | Audit report, compliance evidence | Medium |
Key Takeaways
- NIS2 is a board-level governance obligation — not just an IT security project. Accountability cannot be delegated.
- Five compliance domains: information security, incident response (24/72-hour reporting), business continuity, supply-chain security and governance reporting.
- The reporting deadlines to the authority (24h early warning, 72h notification) are non-negotiable and strictly audited.
- Fines of up to €10M or 2% of global annual revenue turn non-compliance into a board-level risk.
- A realistic rollout takes 12 months: assessment → governance → security baseline → incident response → business continuity → audit evidence.
Related Assessment Templates
Continue Reading
COBIT vs. ITIL — Which Framework for IT Governance?
Read articleRegulatory Collision 2026: NIS2, DORA, CRA and the AI Act — a CIO Map
Read articleDORA vs. NIS2 — Which EU Resilience Rule Applies to You?
Read articleNIST CSF 2.0 Assessment Guide: Evaluate Your Cybersecurity Systematically
Read articleFrequently Asked Questions
If you operate critical infrastructure or an important sector (digital services, retail, logistics, postal, healthcare, energy, finance, water, transport), then yes. When in doubt, contact your sector regulator.
October 2024 for critical infrastructure (passed), October 2025 for important sectors. Authority audits begin afterwards, and non-compliance carries significant fines.
NIS2 requires a person accountable for IT security. This can be the CIO, a dedicated CISO, or an external firm — but the accountability itself is not delegable.
For small organizations with stable infrastructure, possibly. For large organizations with legacy systems, no — 12 months is realistic for comprehensive compliance.
You can outsource implementation (Managed Security Services), but accountability remains yours. The vendor is a service provider, not a replacement for non-delegable accountability.