NIS2: the European directive that changes the game for SME cybersecurity

Applicable since October 2024, the NIS2 directive significantly broadens the scope of companies subject to cybersecurity obligations. Are you affected? NIS2: what is it?: The NIS2 directive (Network and Information Security 2) is the major overhaul of the European cybersecurity framework. It replaces the NIS1 directive of 2016, deemed insufficient against the explosion of cyber threats. NIS2 extends the scope to 18 sectors (up from 7) and distinguishes two categories: essential and important entities. SMEs with 50+ employees or €10M+ revenue in these sectors are now covered. Affected sectors: Energy, transport, health, water, digital infrastructure, postal services, waste management, chemicals, food, medical devices, digital services (cloud, data centres, marketplaces, search engines), public administrations, space, and critical subcontractors. Concrete obligations: Governance: management must be trained and accountable for cyber risks. Risk management: technical and organisational measures (encryption, access control, business continuity). Incident notification: alert within 24h, interim report within 72h, final report within 1 month. Supply chain: assess and supervise the security of critical suppliers. Planned sanctions: For essential entities: fines up to €10M or 2% of global revenue. For important entities: up to €7M or 1.4% of global revenue. Directors can be held personally liable. How to prepare with Powehi: Our approach: 1) Scope diagnostic. 2) Gap analysis. 3) Pragmatic remediation plan. 4) Technical compliance deployment. 5) Documentation and training.

Key takeaways

  • NIS2 covers SMEs with 50+ employees in 18 sectors
  • Mandatory incident notification within 24h
  • Fines up to €10M or 2% of revenue
  • Directors are personally liable
  • Powehi offers NIS2 scope diagnostics