EU Directive 2022/2555 · Cybersecurity

NIS2 compliance, without the guesswork

Advisory and monitoring tools built for NIS2 — meet EU cybersecurity obligations without building a compliance department from scratch.

18sectors in scope
24 hrsearly-warning deadline
€10M / 2%max fine, essential entities
NIS2 enforcement, in numbers
74% of member states
~20 of 27 EU states
now have national NIS2 law adopted or in force — with first enforcement actions starting in 2026.
Essential entities — max fine2.0%
Important entities — max fine1.4%
See where you stand
The basics

What NIS2 actually requires

The EU's revised cybersecurity directive — wider scope, tighter deadlines, and personal liability for management.

You're likely in scope if you...

  • Operate in 1 of the 18 Annex I / II sectors
  • Meet your national size / turnover threshold
  • Supply an organisation that's already in scope
  • Operate across more than one EU member state

Two tiers, two sets of stakes

  • Essential — on-site audits, up to €10M or 2%
  • Important — reactive checks, up to €7M or 1.4%
  • Same reporting clock, same Article 21 baseline
Article 21

The 10 measures every in-scope organisation needs

Proportionate to your size and risk — but every box needs an answer.

01

Risk analysis & security policies

A documented risk assessment and information-system security policy.

02

Incident handling

Detection, response and recovery processes that can hit the reporting clock.

03

Business continuity

Backup management, disaster recovery and crisis management planning.

04

Supply chain security

Ongoing assessment of suppliers and service providers, not a one-off review.

05

Secure acquisition & maintenance

Security built into how systems are bought, built and maintained.

06

Effectiveness assessment

Policies to test whether your controls actually work, on a regular cadence.

07

Cyber hygiene & training

Basic hygiene practices plus regular training, including for management.

08

Cryptography & encryption

Policies covering when and how encryption is applied.

09

HR security & access control

Access management, asset inventory, and HR security through the employee lifecycle.

10

Multi-factor authentication

MFA and secure voice/video/text communication where appropriate.

Where things stand in 2026

NIS2's rollout, at a glance

Uneven transposition across the EU — a moving target if you operate in more than one member state.

16 Jan 2023

Directive in force

Supersedes the 2016 NIS Directive.

17 Oct 2024

EU transposition deadline

Missed by most member states.

2025 – 2026

National laws phase in

~20 member states now in force.

2026 onward

Enforcement begins

First audits, plus a proposed amendment.

Why this reaches the board

Non-compliance is a governance risk, not just an IT one

Article 20 makes management bodies personally accountable — regulators want proof oversight happened, not just that controls exist.

Board-level exposure
LowModerateSevere
€10M / 2%
Max fine, essential entities
€7M / 1.4%
Max fine, important entities
24 hrs
To issue an early warning
Personal
Liability, Article 20
Software + advisory, one team

How Channel IT gets you there

Tooling and advisory in sync, not pulling in different directions.

Platform & tooling

Technology that keeps you audit-ready

  • Continuous risk & vulnerability monitoring
  • Incident detection & reporting workflows
  • Access control & MFA enforcement
  • Compliance evidence & audit trail
Advisory & managed services

Expertise for the parts software can't cover

  • Scope & gap assessment
  • Remediation roadmap
  • Supply-chain risk reviews
  • Board & staff training
Engagement model

From "are we in scope?" to audit-ready

Assess

Scope check & gap assessment

Remediate

Prioritised, budget-aware roadmap

Implement

Monitoring & reporting tooling deployed

Monitor & report

Ongoing oversight, always audit-ready

Why work with us

One partner, not a stack of disconnected vendors

Tooling and advisory, one team

The fix a consultant recommends is the one that gets deployed.

Vendor-neutral recommendations

Not locked to one platform — the solution fits your environment.

Built around Article 21

Maps to the ten measures regulators check first.

Support that continues after go-live

Compliance is a state, not a one-off deliverable.

Questions

NIS2, in plain language

Does the NIS2 Directive apply to my organisation?
NIS2 covers 18 sectors split into Annex I (essential entities — energy, transport, banking, health, digital infrastructure, and more) and Annex II (important entities — manufacturing, food, chemicals, digital providers, and more). Exact size thresholds are set by each member state's national law, so the same organisation can be in scope in one country and not another. A short scope check gives you a definitive answer.
What are the NIS2 incident reporting deadlines?
For a significant incident: an early warning within 24 hours of becoming aware of it, a fuller incident notification within 72 hours, and a final report within one month covering root cause and impact.
What happens if we don't comply?
Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher; important entities up to €7 million or 1.4%. Article 20 also allows management bodies to be held personally liable for infringements.
Has NIS2 been transposed into national law yet?
The EU-wide deadline was 17 October 2024, but most member states missed it. As of 2026, roughly 20 member states have national NIS2 laws adopted or in force, each with its own dates — and the first national enforcement actions are beginning.
We're not in one of the 18 critical sectors — are we still affected?
Possibly. NIS2's supply-chain security requirement means in-scope organisations must assess and monitor their suppliers, so vendors and service providers to essential or important entities are often pulled in indirectly through contractual security requirements.
How long does it take to become compliant?
It depends on your current maturity and scope. A typical path runs from a scope and gap assessment, through a prioritised remediation roadmap, to implementation and ongoing monitoring — most organisations phase this over one or two quarters rather than closing every gap at once.

Get a clear answer on where you stand

A free NIS2 scope and readiness assessment — no obligation, no jargon.

Get in touch

Book your free NIS2 assessment

A compliance specialist will follow up to schedule a call.

  • General NIS2 & DORA enquiries
  • 1 business day
    Typical response time
  • No-obligation scope check
    We'll tell you plainly if NIS2 doesn't apply to you

By submitting, you agree to be contacted by Channel IT about NIS2 compliance services. We don't share your details with third parties.

Book a free NIS2 assessment