The NIS2 Directive (Directive (EU) 2022/2555) is the EU's revised cybersecurity law. It replaced the original NIS Directive and had to be transposed into national law by October 2024, with member states enforcing it on different timelines since. Unlike GDPR, which is about personal data, NIS2 is about the resilience of the services themselves, and it brings a large part of the tech sector (cloud, data centres, managed services, and much of B2B software) under binding obligations for the first time. This article explains who is in scope, what Article 21 actually requires, how incident reporting works, what the penalties are, and how existing ISO 27001 and SOC 2 work maps onto it.
Who is in scope
NIS2 applies to entities in 18 sectors listed in its annexes, split into "essential" (Annex I) and "important" (Annex II). For the technology sector the relevant categories are:
- Digital infrastructure (Annex I): cloud computing service providers, data centre service providers, content delivery networks, DNS providers, TLD registries, trust service providers, electronic communications networks.
- ICT service management B2B (Annex I): managed service providers (MSPs) and managed security service providers (MSSPs).
- Digital providers (Annex II): online marketplaces, online search engines, social networking platforms.
- Manufacturing, finance, health, energy, transport and other sectors whose suppliers you may be, which matters for the supply-chain clauses below.
The size threshold is the key filter. In general, medium-sized and large enterprises (50+ staff or more than EUR 10 million turnover) in these sectors are covered; large ones in Annex I sectors are "essential", the rest "important". Some categories, including DNS, TLD registries, trust service providers and certain cloud and electronic-communications providers, are in scope regardless of size. Entities outside the EU that offer in-scope services within the Union must designate an EU representative and are subject to the rules too.
A typical B2B SaaS company is not named explicitly. In practice it is caught in one of three ways: it qualifies as a cloud computing service provider; it qualifies as a managed service provider; or, most commonly, it is a supplier to an in-scope customer, who must manage supply-chain risk under Article 21(2)(d) and pushes NIS2-aligned requirements into contracts. Many software vendors first encounter NIS2 as a clause in a bank's or hospital's procurement template.
| Category | Examples | Size rule | Supervision |
|---|---|---|---|
| Essential (Annex I) | Cloud, data centres, MSP/MSSP, DNS, trust services | Large; some regardless of size | Proactive: audits, inspections |
| Important (Annex II) | Online marketplaces, search, social platforms, manufacturing, postal | Medium and large | Reactive: after incidents or complaints |
| Supplier to an in-scope entity | Most B2B software vendors | No direct threshold | Contractual, via the customer |
The ten measures of Article 21
Article 21 requires "appropriate and proportionate technical, operational and organisational measures" based on an all-hazards approach. It then lists a minimum of ten areas that every in-scope entity must cover:
- Risk analysis and information system security policies. A documented risk assessment methodology and an overarching security policy approved by management.
- Incident handling. Detection, analysis, containment, recovery and lessons learned, with defined roles.
- Business continuity. Backup management, disaster recovery and crisis management, tested regularly.
- Supply chain security. Assessment of direct suppliers and service providers, including the security of their products and development practices.
- Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of the measures: internal audits, metrics, management review.
- Basic cyber hygiene practices and training for all staff, including management.
- Cryptography and, where appropriate, encryption policies.
- Human resources security, access control and asset management. Screening, joiner/mover/leaver processes, least privilege, inventories.
- Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications.
The directive also makes management personally accountable (Article 20): board members must approve the measures, oversee their implementation, attend cybersecurity training and can be held liable for breaches. For cloud and MSP providers, the Commission's Implementing Regulation (EU) 2024/2690 spells out these measures in considerably more detail, with specific requirements for logging, network security, patching timelines and supplier contracts.
Incident reporting: 24 hours, 72 hours, one month
Article 23 introduces a staged reporting regime for "significant incidents" (those causing, or capable of causing, severe operational disruption or financial loss, or considerable damage to others):
| Deadline | What | Content |
|---|---|---|
| Within 24 hours | Early warning | Whether the incident is suspected to be malicious and whether it could have cross-border impact |
| Within 72 hours | Incident notification | Initial assessment of severity, impact and indicators of compromise |
| On request | Intermediate report | Status updates while the incident is ongoing |
| Within 1 month | Final report | Detailed description, root cause, mitigation, cross-border impact |
Reports go to the national CSIRT or competent authority. Service providers must also notify affected customers where relevant. Note the interplay with GDPR: a single incident can trigger a 24-hour NIS2 early warning and a 72-hour GDPR breach notification to the supervisory authority, so the incident response plan must handle both clocks.
Fines and enforcement
Penalties are set at the GDPR level of seriousness:
- Essential entities: administrative fines up to EUR 10 million or 2% of global annual turnover, whichever is higher.
- Important entities: up to EUR 7 million or 1.4% of global annual turnover.
- Non-financial measures: binding instructions, orders to cease conduct, mandatory audits, public disclosure of breaches, and for essential entities the temporary suspension of certifications or of management's authority to exercise managerial functions.
Entities must also register with their national authority; in most member states that registration obligation has already passed, and the first supervisory audits of cloud and MSP providers are under way.
How ISO 27001 maps to NIS2
The good news for companies that already run an ISMS: NIS2 was written with ISO 27001 in view, and most national guidance explicitly points to it. The mapping is close:
- Article 21(2)(a) risk analysis and policies corresponds to ISO 27001 clauses 5 and 6 and the risk assessment process.
- Incident handling, continuity, supplier security, secure development, cryptography, HR security, access control and asset management each have a direct counterpart in the Annex A control themes of ISO 27001:2022.
- Assessing effectiveness corresponds to clauses 9 and 10: monitoring, internal audit, management review, continual improvement.
- Management accountability corresponds to clause 5 leadership requirements, though NIS2 goes further with personal liability and mandatory training.
What ISO 27001 does not give you automatically: the statutory 24/72-hour reporting workflow, registration with the authority, the specific contractual clauses for suppliers, and the detailed technical baselines in the implementing regulation for cloud providers. These are added as an overlay on the ISMS. An ISO 27001 certificate from an accredited certification body is also the most widely accepted evidence for an authority or a customer that the Article 21 measures are in place. The BALTUM group's accredited certification body issues ISO 27001 certificates; the consulting team prepares the ISMS with the NIS2 overlay built in.
How SOC 2 maps to NIS2
SOC 2 is a US attestation report rather than a European certificate, but its Trust Services Criteria cover much of the same ground: risk assessment (CC3), monitoring (CC4), logical access and MFA (CC6), system operations and incident response (CC7), change management (CC8), vendor risk and business continuity (CC9), plus the Availability criterion for resilience. A SOC 2 Type 2 report is therefore useful evidence for an in-scope customer doing supply-chain due diligence under Article 21(2)(d), especially if the customer also has US operations. It does not, on its own, satisfy NIS2 for an entity that is directly in scope; it has no statutory reporting, no registration and no management liability element. The practical approach for a European cloud or software provider selling into the US is one control set that supports ISO 27001 certification, SOC 2 attestation and NIS2 compliance at once. See SOC 2 vs ISO 27001 for how the two frameworks differ.
A practical roadmap
- Scoping. Determine whether you are essential, important, out of direct scope but a supplier, or a non-EU provider needing a representative. Check the national transposition in each member state where you operate.
- Gap analysis against the ten Article 21 measures and, for cloud and MSP providers, the implementing regulation.
- Governance. Management approval of measures, board training, named accountable roles.
- Control implementation within the ISMS: incident playbooks with the 24/72-hour clocks, supplier assessment, secure development, MFA, logging, continuity testing.
- Registration and reporting readiness with the national authority and CSIRT.
- Assurance. ISO 27001 certification and, where US customers require it, SOC 2, as external proof that the measures operate.
How BALTUM helps
Our EU-based consulting team runs the NIS2 scoping and gap analysis, builds or extends your ISMS with the Article 21 overlay and prepares the reporting procedures. ISO 27001 certification is then performed by the BALTUM group's accredited certification body, and SOC 2 reports by the group's US-registered CPA firm, each with separate teams to preserve independence. For companies that need all of it at once, see the SOC 2 + ISO 27001 + GDPR + Cyber Essentials + NIS2 package; details of the standalone service are on the NIS2 compliance page.
Unsure whether NIS2 applies to you, or a customer has just sent a NIS2 supplier questionnaire? Tell us what you provide and to whom, and we will determine your status, list the gaps and propose a plan. Request a consultation.