The new European NIS2 directive also affects mid-sized companies. What does this mean for your organisation?
The NIS2 directive succeeds the original NIS directive from 2016 and substantially expands its scope. Where the first version mainly targeted large energy and telecom companies, NIS2 covers a much broader spectrum of organisations — including mid-sized companies in sectors such as manufacturing, food processing, waste management, digital services and even parts of the healthcare chain.
For the mid-market this is a significant shift. Many business owners assume compliance rules only apply to large players, but NIS2 uses a combination of sector relevance and size (from 50 employees or €10 million in revenue) to bring companies within scope. It is therefore essential to first determine whether your organisation falls within scope — and that determination is explicitly yours to make, not the regulator's.
The substantive requirements are significant. Organisations must apply a risk-based approach to information security, with demonstrable measures around access management, incident response, supply chain security, encryption and business continuity. There is also a mandatory reporting duty: serious incidents must be reported to the competent CSIRT within 24 hours, followed by a more detailed report within 72 hours and a final report within a month.
What sets NIS2 apart from earlier regulation is the personal liability of executives. Board members can be held personally accountable for gross negligence, and fines run up to €10 million or 2% of global annual turnover. That unmistakably makes cybersecurity a board-level topic, no longer a purely technical one.
For the mid-market this means you need to start taking stock now: which systems are critical, which suppliers touch your infrastructure, which processes grind to a halt during an incident? Many organisations discover at this stage that their documentation is outdated, that backups aren't tested, and that no clear incident response plan exists. These are exactly the basic requirements NIS2 targets.
A practical approach starts with a gap analysis: compare your current security measures against the NIS2 requirements, using ISO 27001 as a reference framework. Then set priorities based on risk and feasibility. Quick wins are often found in multi-factor authentication, structured patch management, network segmentation and setting up an incident reporting procedure.
The good news is that NIS2 doesn't prescribe specific technology. You're free to choose solutions that fit your size and risk profile — provided you can demonstrate they are effective. That gives the mid-market room to make pragmatic choices, together with an IT partner who understands both the technology and the compliance context. Waiting is no longer an option: the directive is in force and enforcement is ramping up.
Curious what this means for your organisation?
Book a strategy call with one of our specialists. We're happy to think along with you — no obligations.
Book a strategy call