NIS2 Compliance: Who Must Comply (Incl. Non-EU Firms) | Arté
A plain-English guide to NIS2 scope: who is in scope, the reporting clock, penalties, why some non-EU providers are caught, and how consultants can manage NIS2
Arté Team · 2026-06-06
The deadline for EU member states to transpose the NIS2 Directive into national law passed on 17 October 2024. Yet ask most founders or IT leads whether NIS2 applies to them, and you'll get a shrug. That gap — between a binding legal obligation and "wait, does this affect us?" — is exactly where the risk lives. This is a plain-English guide to the question that comes before everything else: are you in scope, and if so, what do you actually have to do? (For the most recent changes specifically, see our companion post on the January 2026 NIS2 amendments.) What NIS2 is, in one paragraph NIS2 (Directive (EU) 2022/2555) is the EU's second-generation cybersecurity law, replacing the original 2016 NIS Directive. It widens the net dramatically — more sectors, more organisations, stricter obligations, and real penalties — and it applies across every member state, not any single country. The part many people miss: you don't always have to be in the EU Here's a detail that catches some companies off guard. For a specific set of digital service and infrastructure providers, NIS2 applies even if the company is established outside the EU — as long as it offers those services within the Union. Those providers must also designate a representative inside the EU (Article 26). The categories this covers are: DNS service providers, TLD name registries, domain-name registration services, cloud computing providers, data centre providers, content delivery networks (CDNs), managed service providers (MSPs) and managed security service providers (MSSPs), and providers of online marketplaces, online search engines and social networking platforms. So a non-EU cloud provider, MSP/MSSP, or online marketplace serving EU customers can fall squarely in scope, wherever it's headquartered. One important nuance, though: unlike GDPR, NIS2 is not a blanket "anyone who sells into Europe." If your company is established outside the EU and isn't one of those enumerated digital-provider types, NIS2 generally won't apply to you directly through this route. You may still feel it indirectly — your EU customers must manage their own supply-chain security, so they may pass NIS2-aligned requirements down to you contractually. Are you in scope? NIS2 sorts covered organisations into two tiers: Essential entities — larger organisations in high-criticality sectors (energy, transport, banking, health, drinking water, digital infrastructure, and more). Important entities — organisations in other critical sectors (postal and courier services, waste management, chemicals, food, certain manufacturing, digital providers such as online marketplaces and search engines, research, and others). Scope is generally driven by sector + size: as a rule of thumb, medium-sized organisations and above (broadly 50+ employees or €10M+ turnover) operating in a covered sector are caught — though some entities are in scope regardless of size because of how critical they are. Both tiers face the same core obligations; the main difference is supervision intensity and penalty ceilings. The honest takeaway: the sector list is long, and categories like "digital infrastructure" and "ICT service management" pull in many tech companies that never thought of themselves as critical infrastructure. What you actually have to do NIS2 comes down to three buckets: Cybersecurity risk-management measures. Appropriate, proportionate technical and organisational measures — risk analysis, incident handling, business continuity and backups, supply-chain security, secure development and procurement, vulnerability handling, cryptography, access control, and multi-factor authentication, among others. In practice, this looks like a real information-security programme. Incident reporting — on a tight clock. When a significant incident hits: Early warning within 24 hours Incident notification within 72 hours Final report within one month If you don't already know who would file those reports and how, close that gap now — not during an incident. Management accountability. This is the cultural shift. NIS2 puts cybersecurity on the boardroom agenda: management bodies must approve and oversee the measures, can be held personally liable for failures, and are expected to undergo training. Security is no longer something leadership can fully delegate and forget. Why it's worth taking seriously Penalties carry real weight. For essential entities, fines can reach €10 million or 2% of global annual turnover, whichever is higher; for important entities, €7 million or 1.4%. Combined with personal accountability for management, NIS2 stops being a "we'll get to it" item. The good news: you may be closer than you think If you already run an ISO 27001 or SOC 2 programme, you've done much of the heavy lifting. The risk-management measures NIS2 expects overlap heavily with controls you likely already have — access control, incident response, business continuity, supply-chain due diligence. NIS2 isn't asking you to start from zero; it's asking you to formalise, document, and prove good security, and to wire in the reporting and governance pieces. The challenge is rarely capability — it's visibility and evidence: knowing your posture across every requirement, tracking gaps, and being able to demonstrate readiness on demand. Where to start Determine scope — does your sector, size, or your services into the EU put you in scope? When in doubt, get a legal read. Run a gap assessment — map current controls against NIS2's requirements and find what's missing. Fix reporting and governance — make sure the 24h/72h/1-month reporting flow and management oversight actually exist. Document and maintain — compliance is an ongoing state you keep proving, not a one-time project. Managing NIS2 across many clients? (For vCISOs and consultants) If you're a virtual CISO, an ISO 27001 / SOC 2 consultant, or an MSSP, NIS2 isn't one compliance programme — it's one per client. Track each client's scope, controls, gaps and reporting readiness across separate spreadsheets and documents, and every new client multiplies the admin until growth becomes the bottleneck. That's the problem we're tackling next at Arté. We're opening an early partner programme for consultants who run compliance across multiple clients: One multi-client dashboard — every client's NIS2 (and ISO 27001, SOC 2, AI governance) readiness, gaps and open tasks in a single view. Under your own brand — white-label it with your logo and your client relationship; we stay in the background. Start clients free — onboard a client at no cost, prove the value, and grow from there. The goal is simple: serve more clients without drowning in spreadsheets, and turn compliance tooling into recurring revenue for your practice. If that's how you work, we'd like to talk. Get in touch to join the early partner programme → Where do you stand? Whether you're assessing your own organisation or managing it for clients, the fastest way to answer "where do we stand?" is to measure it. Arté's free NIS2 readiness self-check gives you an automated compliance score, a domain-level breakdown, and a prioritised list of your gaps — no credit card, no time limit. Create your free account and run your first NIS2 self-check today. This article is for general information and is not legal advice. NIS2 is implemented through national laws that vary by member state; consult a qualified professional for your specific situation. Related reading NIS 2 readiness for industrial and OT operators Run a free NIS 2 self-check