Skip to main content
Back to insights

Compliance

NIS2 and Beyond: Preparing for What's Next

Published 02 Apr 20263 min read
The European Union flag in front of a modern glass building

Practical actions organisations can take now to meet new regulatory expectations and strengthen resilience.

NIS2 widened the scope of European cyber security regulation substantially, and it did something more consequential than adding requirements: it attached personal accountability for management bodies and set expectations for incident reporting on timelines measured in hours.

For many organisations now in scope, this is their first encounter with binding cyber security obligations. For those already certified, the work is less about new controls and more about evidencing governance and reporting readiness.

First: establish whether you are in scope

Scope depends on sector, size and — importantly — on whether you supply an entity that is itself in scope. Many mid-sized manufacturers and service providers discover their obligations through a customer questionnaire rather than through their own analysis.

As a broad orientation, the Directive reaches medium-sized entities in the sectors it lists, generally from 50 employees or €10 million turnover, and divides them into essential and important entities — a distinction that affects supervision and penalties more than the underlying security obligations. Smaller organisations can still be pulled in where they are a sole provider of a critical service, and in practice many are pulled in contractually as suppliers regardless of their own headcount.

Transposition into national law varies across Member States, and Spain is a case worth watching closely: the draft Ley de Coordinación y Gobernanza de la Ciberseguridad was approved by the Council of Ministers in January 2025 but has not completed its parliamentary passage, and the European Commission issued a reasoned opinion over the delay. Until it enters into force, the previous framework under Royal Decree-Law 12/2018 continues to apply, with INCIBE-CERT handling private-sector notifications and CCN-CERT the public sector.

The practical implication is not to wait. The technical and governance measures are substantially settled by the Directive itself; what national law will fix is supervisory detail, penalties and reporting channels. Organisations that build the capability now will be adjusting a channel later rather than starting a programme.

Second: build one control framework, not four

NIS2, DORA, GDPR and the Cyber Resilience Act overlap considerably in what they require of governance, risk management, supplier oversight and incident handling. Organisations that build a separate programme per regulation multiply their evidence burden.

Mapping obligations onto a single control set — typically anchored on ISO/IEC 27001 — means one piece of evidence can satisfy several requirements, and one management review can serve several audiences.

One caution: overlap is not equivalence, and the differences are concentrated in the deadlines. A single incident can trigger a 72-hour personal data breach notification under GDPR and a 24-hour early warning under NIS2, to different authorities, on different clocks, assessed against different definitions of significance. A shared control set handles the preventive obligations well; the reporting obligations need to be mapped individually or the fastest clock will be missed.

Third: rehearse the reporting clock

The early-warning obligation is the requirement most organisations are least prepared for. It demands a judgement about significance, made quickly, by someone with authority, and submitted through a channel that has ideally been used before.

The sequence under Article 23 is staged: an early warning within 24 hours of becoming aware of a significant incident, flagging whether it appears malicious or may have cross-border effects; a fuller notification within 72 hours including an initial severity assessment and any indicators of compromise; and a final report within one month, covering root cause and mitigation, with a progress report at that point if the incident is still running.

The demanding part is the phrase "becoming aware". The clock does not start when the incident is confirmed, understood or contained — it starts when the organisation first knows enough to suspect something significant. Teams accustomed to investigating thoroughly before escalating are the ones most likely to submit late, because their instinct is to be certain first. Under a 24-hour obligation, a provisional early warning that is later withdrawn is a far better outcome than a well-evidenced report filed on day three.

Practise it. Run a scenario, draft the notification, and time how long it takes to get sign-off. The first attempt is always slower than expected. Decide in advance who can submit at three in the morning without waking anyone, register for the reporting channel before you need it, and keep a pre-drafted template that names the few facts an early warning actually requires.

What comes next

The Cyber Resilience Act extends obligations to products with digital elements, bringing security-by-design, vulnerability handling and SBOM expectations into scope for manufacturers. Organisations that treat NIS2 as a foundation rather than a project will absorb it far more easily.

Portrait of Olha Mann, Founder and Principal Consultant of LEONIS

Olha Mann

Founder & Principal Consultant

CISSP · CISM · CEH · ISO/IEC 27001:2022 Lead Auditor

Related insights