The assumption most organisations are making
When the original NIS Directive came into force, the list of organisations in scope was relatively narrow. Critical infrastructure operators. Essential services. A manageable number of entities that most IT leaders could look at and quickly decide: "that's not us."
NIS2 is a different matter. The European Union expanded the framework's scope significantly when it published the revised directive in December 2022. More sectors. Lower size thresholds. New categories of "important" entities alongside the traditional "essential" ones. And critically, supply chain obligations that can pull organisations into scope even when they would not otherwise qualify.
The Irish transposition is now in progress. When it lands, organisations that have been operating on the assumption that NIS2 does not apply to them will need to have their documentation, incident reporting procedures, and governance frameworks in place. That is not a quick exercise.
"The question is not whether NIS2 applies to your sector. The question is whether it applies to your organisation specifically. Those are two different assessments, and conflating them is where most planning errors begin."
Edge7 Networks, Compliance PracticeWho is actually in scope
NIS2 divides in-scope organisations into two categories: essential entities and important entities. The obligations are largely the same. The difference lies in supervisory regime and the severity of penalties for non-compliance.
Essential entities
Essential entities are organisations operating in sectors considered critical to societal or economic function. These include:
- Energy (electricity, gas, oil, district heating, hydrogen)
- Transport (air, rail, water, road)
- Banking and financial market infrastructure
- Health (hospitals, healthcare providers, pharmaceutical manufacturers)
- Drinking water and wastewater
- Digital infrastructure (DNS providers, TLD registries, IXPs, data centres, CDN and cloud providers, managed security service providers)
- ICT service management (B2B)
- Public administration (central and regional government bodies)
- Space
Important entities
Important entities cover a broader range of sectors, many of which did not feature in the original NIS Directive. These include:
- Postal and courier services
- Waste management
- Chemicals (manufacture and distribution)
- Food production, processing, and distribution
- Manufacturing of medical devices, computers, electronics, machinery, motor vehicles, and other transport equipment
- Digital providers (online marketplaces, online search engines, social networking platforms)
- Research organisations
The 50-employee / €10M rule
In most sectors, NIS2 applies to organisations with 50 or more employees, or an annual turnover and balance sheet total exceeding €10 million. For essential entities in certain high-criticality sectors, size thresholds do not apply at all.
Smaller organisations can also be pulled in scope if they are the sole provider of a service in a member state, or if disruption to their service could have a significant impact on public safety, security, or other in-scope entities.
The supply chain dimension
This is where many organisations are caught off-guard. NIS2 includes explicit obligations around supply chain security. In-scope entities must assess the cybersecurity practices of their key suppliers and service providers, and manage the risks those relationships introduce.
The practical consequence: if you supply technology, managed services, connectivity, or security capabilities to an in-scope organisation, your customer's NIS2 compliance programme is going to reach into your organisation. You will be asked for evidence of your security posture. You may be asked to meet contractual security requirements that reflect NIS2 obligations.
Some managed service providers and technology suppliers will find themselves effectively in scope via this route, even if they would not otherwise qualify. The organisations asking the questions are not being difficult. They are fulfilling a legal obligation.
You may be in scope without knowing it
Several Irish organisations will find themselves within NIS2's scope via the supply chain route, rather than through direct sector classification. If you provide services to healthcare, financial services, energy, or public sector customers, an assessment of your own security controls is prudent, regardless of whether you believe you qualify directly.
Key obligations for in-scope organisations
The core of NIS2 is a risk-based security obligation. In-scope organisations must take appropriate and proportionate technical and organisational measures to manage cybersecurity risks. The directive specifies ten minimum security measures that all covered entities must implement:
- Policies on risk analysis and information system security
- Incident handling procedures
- Business continuity, including backup management and disaster recovery
- Supply chain security, including security aspects of relationships with direct suppliers and service providers
- Security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure
- Policies and procedures to assess the effectiveness of cybersecurity risk management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies and procedures regarding the use of cryptography and, where appropriate, encryption
- Human resources security, access control policies, and asset management
- The use of multi-factor authentication or continuous authentication solutions, secured voice, video, and text communications, and secured emergency communication systems within the entity, where appropriate
Incident reporting
NIS2 introduces strict incident reporting timelines. In-scope organisations must notify their national competent authority of significant incidents within 24 hours of becoming aware (an early warning), followed by a more detailed notification within 72 hours, and a full report within one month.
A significant incident is one that causes or is capable of causing severe operational disruption or financial loss, or affecting other natural or legal persons by causing considerable damage. That is a broader definition than many IT teams are currently working to.
Management accountability
NIS2 places explicit responsibilities on senior management. Governing bodies of in-scope entities must approve cybersecurity risk management measures and oversee implementation. They can be held personally liable for infringements. This is a material change for organisations where security has historically been managed without board-level visibility.
"NIS2 is not a technical standard. It is a governance framework with teeth. The most significant shift for many organisations is not what they need to implement. It is who is now accountable for it."
Edge7 Networks, Compliance PracticeThe Irish transposition
Member states were required to transpose NIS2 into national law by 17 October 2024. Ireland, in common with a number of other EU member states, is still finalising its transposition. The relevant legislation is progressing through the Oireachtas.
The transposition process will designate the competent authority responsible for supervising compliance, confirm the national incident reporting mechanism, and specify any additional obligations that Ireland chooses to impose above the directive minimum.
Critically, once the Irish legislation is enacted, organisations will not be given a lengthy grace period. The obligations under NIS2 are already defined. Organisations that wait for the national legislation to be published before beginning their compliance work are likely to find themselves behind from day one.
What to do now
The practical starting point is a scope assessment. Before any security investment or governance change, organisations need to determine whether NIS2 applies to them, under which category, and what that means for their existing controls.
A structured scope assessment covers three questions:
- Sector classification. Does the organisation operate in a sector covered by Annex I or Annex II of the NIS2 Directive?
- Size thresholds. Does the organisation meet the employee or turnover thresholds for its sector? Are any threshold exceptions applicable?
- Supply chain exposure. Does the organisation provide services to in-scope entities in a way that creates indirect obligations?
If the organisation is in scope, the next step is a gap assessment against the ten minimum security measures. For most organisations, the areas requiring the most work are incident response procedures, supply chain security documentation, and management accountability structures, not the technical controls themselves.
Edge7 Networks works with IT teams across Ireland and the UK on NIS2 scoping, gap assessments, and implementation planning. If you are unsure of your position, a structured assessment is the right place to start.