Key takeaways:
- Scope test: NIS2 covers 18 sectors across Annex I and Annex II. Most organizations enter scope when they are medium-sized or larger under EU SME rules, but specific entity types can be covered regardless of size.
- Cloud, MSP and MSSP providers are covered under NIS2 categories, but they are not automatically in scope regardless of size. If they qualify as NIS2 entities, Commission Implementing Regulation (EU) 2024/2690 adds detailed technical and methodological requirements.
- Essential and Important entities implement the same ten Article 21(2) measures. They differ mainly in supervision and maximum penalties.
- Management responsibility is explicit. Under Article 20, management bodies must approve the cybersecurity risk-management measures, oversee implementation, and receive cybersecurity training.
- ISO 27001 provides substantial overlap with Article 21, but certification is not a presumption of NIS2 conformity. A NIS2-specific gap assessment is still necessary.
NIS2 may apply to your startup if you operate in one of the 18 sectors covered by Directive (EU) 2022/2555 and meet the applicable size threshold.
For most covered sectors, that means being a medium-sized or larger organization under EU SME rules. Some entity types, including DNS service providers and top-level domain name registries, can fall within scope regardless of size. Cloud providers, managed service providers (MSPs), and managed security service providers (MSSPs) are covered NIS2 sectors, but they are not automatically exempt from the size test simply because of the service they provide.
If you are in scope, the core obligations are: ten cybersecurity risk-management measures under Article 21, a staged incident-reporting process under Article 23, and management-body responsibility under Article 20. For certain digital infrastructure and digital-service providers, Commission Implementing Regulation (EU) 2024/2690 adds a more detailed technical layer that applies directly at EU level.
Even if NIS2 does not apply to you directly, it can still reach your startup commercially. In-scope enterprise customers have supply-chain security obligations and may pass NIS2-aligned requirements down through contracts, questionnaires, evidence requests, audit rights, and incident-notification clauses.
What is NIS2 and what it is not
NIS2, formally Directive (EU) 2022/2555, is the European Union's revised framework for the security of network and information systems. It entered into force in January 2023 and replaced the original NIS Directive, expanding coverage from 7 sectors to 18 and replacing much of the old case-by-case designation model with broader, harmonized scope rules.
The European Commission's NIS2 policy page describes the directive as the EU-wide framework for a higher common level of cybersecurity across critical sectors.
Now here’s what NIS2 is not:
NIS2 is not GDPR. GDPR governs the lawful processing and protection of personal data. NIS2 focuses on the security and resilience of network and information systems. They overlap in areas such as technical security and incident response, but compliance with one does not satisfy the other.
NIS2 is not ISO 27001. ISO 27001 is a voluntary international certification for an information security management system. NIS2 is a legal obligation for organizations that fall within its scope. ISO 27001 can provide a strong foundation, but it does not automatically establish NIS2 compliance.
NIS2 is not fully uniform across the EU. NIS2 is a directive, so Member States transpose it into national law. Article 21 establishes common EU obligations, but supervisory authorities, procedures, national enforcement and some definitions can vary. Cross-border organizations may therefore need to confirm requirements in more than one jurisdiction.
Does NIS2 Apply to Your Startup?
Start with two questions: what sector are you in, and how large is the organization under the EU SME rules? Then check whether a specific exception or national designation applies.
01. Sector
02. Size
For most entities, NIS2 applies when a company operates in a covered sector and qualifies as medium-sized or larger under the EU SME definition. In practical terms, the analysis commonly starts around 50 employees and the EUR 10 million turnover/balance-sheet thresholds, but the SME calculation can also involve linked or partner enterprises. The Commission's NIS2 FAQ is a useful starting point for the scope test.
Important exception: not every covered technology provider is size-independent. Under Article 3, qualified trust service providers, top-level domain name registries and DNS service providers are Essential entities regardless of size. Other exceptions and Member State designations can also bring smaller entities into scope. Cloud providers, MSPs and MSSPs are covered categories, but their classification still depends on the NIS2 scope rules rather than a blanket size exemption.
The supply-chain route into NIS2
A startup can feel NIS2 before it is directly regulated. Article 21(2)(d) requires covered entities to address security in their relationships with direct suppliers and service providers. Enterprise customers often operationalize that through procurement: security clauses, questionnaires, evidence requests, audit rights and incident-reporting commitments.
If you sell to European banks, healthcare providers, energy companies or large managed-service organizations, the commercial requirement may arrive before any regulator contacts you. That is why a 30-person SaaS startup can still end up doing much of the NIS2 work even when it sits below the usual direct-scope threshold.
Essential vs. Important: What's the Difference?
Both categories implement the same ten measures under Article 21(2). The key differences are supervision, enforcement and maximum administrative fines.
Classification is not something to infer from company size alone. National transposition and specific Article 2/3 provisions can matter, so confirm your status with the competent authority or qualified legal counsel in your main establishment.
The 10 Mandatory Cybersecurity Measures Under Article 21
Article 21(2) requires covered entities to implement appropriate and proportionate technical, operational and organizational measures on an all-hazards basis. For a startup, the question is not whether each topic exists on paper, but what evidence shows that it operates.
Article 21(3) makes supply-chain security more specific: direct-supplier vulnerabilities and the overall quality of supplier cybersecurity practices must be considered. That turns vendor risk into an ongoing process rather than a one-time questionnaire.
If you are an in-scope cloud, MSP, MSSP or digital provider, Article 21 is not the finish line
For specified digital infrastructure, ICT service management and digital-provider entities that are covered by NIS2, Commission Implementing Regulation (EU) 2024/2690 lays down detailed technical and methodological requirements for the Article 21 measures and further specifies when incidents are significant.
The Regulation applies to relevant NIS2 entities in categories including:
- DNS service providers and TLD name registries;
- cloud computing and data centre service providers;
- content delivery network providers;
- managed service providers and managed security service providers;
- online marketplaces, online search engines and social-networking platforms;
- trust service providers.
In June 2025, ENISA published Technical Implementation Guidance for the Implementing Regulation. The guidance provides practical implementation considerations, examples of evidence and mappings to standards and frameworks. ENISA also makes clear that the guidance is advisory rather than legally binding.
For a startup in one of these subsectors, that guidance is useful because it turns broad legal requirements into something closer to an implementation and evidence plan. The important caveat is scope: the Implementing Regulation does not make every cloud or managed-service company a NIS2 entity by itself. It applies to those providers once they are covered under NIS2.
Incident Reporting Obligations Under Article 23
Significant incidents trigger a staged reporting process. The operational challenge is that the clock begins when the organization becomes aware of a significant incident, so the reporting workflow needs to exist before an incident occurs.
Within 24 hours: Submit an early warning to the competent authority or CSIRT, including whether unlawful or malicious acts are suspected and whether cross-border impact is likely.
Within 72 hours: Submit an incident notification that updates the early warning and provides an initial assessment of severity, impact and available indicators of compromise.
No later than one month after the incident notification: Submit the final report with the incident description, likely root cause or threat type, mitigation measures and relevant cross-border impact.
The practical takeaway: your decision tree, authority contacts, internal escalation path, submission channel and authorized reporter should already be documented. Building the reporting process after a major incident begins is too late.
Management Accountability Under Article 20
Article 20 makes the management body responsible for approving the cybersecurity risk-management measures under Article 21 and overseeing their implementation. Management-body members must also receive cybersecurity training.
For founders, that changes the governance model. NIS2 cannot simply be delegated to an engineer and forgotten. Leadership should be able to show that cybersecurity risks were reviewed, measures were approved, responsibilities were assigned and management received the required training.
For Essential entities, the Directive also gives competent authorities significant enforcement powers. In cases of unresolved material non-compliance, certain temporary restrictions on managerial functions can ultimately be available, subject to the conditions and safeguards in the Directive. This is not an automatic penalty and should not be presented as one.
This is one place where a vCISO can be useful: not because NIS2 requires a vCISO, but because someone may need to translate technical control coverage into board-level risk decisions, prepare management reviews and maintain the governance evidence the regulation expects.
How NIS2 Maps to ISO 27001
If you already hold ISO 27001, you have a meaningful head start. Both frameworks are risk-based, require documented security governance, and overlap across many operational controls. But ISO 27001 certification is not a presumption of NIS2 conformity.
The most important residual gaps to test are:
If your organization is also subject to Implementing Regulation (EU) 2024/2690, use ENISA's mappings to identify which ISO 27001 controls already support the detailed technical requirements and where residual work remains.
Where NIS2 transposition stands
NIS2's transposition deadline was 17 October 2024, with national measures applying from 18 October 2024. But implementation has not progressed uniformly across all Member States.
On 8 July 2026, the European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify complete transposition measures. The Commission's July 2026 infringement package records those referrals.
For a startup operating across borders, this matters because national procedures determine the competent authority, reporting channel and supervisory process. Verify the current position with the authority in each relevant jurisdiction rather than relying only on a third-party transposition tracker.
What a startup should do next
1. Confirm the direct scope. Map your services to Annex I/II, apply the size test correctly, and check any Article 2 exceptions or national designations.
2. Check supply-chain exposure. Even if you are not directly in scope, identify enterprise customers likely to flow NIS2 requirements down through procurement.
3. Identify your entity category. If you are in scope, determine whether you are Essential or Important and which competent authority supervises you.
4. Run an Article 21 gap assessment. Map existing controls and evidence against all ten measures instead of treating NIS2 as a policy-writing exercise.
5. If applicable, assess against Regulation 2024/2690. Cloud, MSP, MSSP and other listed digital providers that are NIS2 entities should test against the detailed EU-level technical requirements.
6. Build Article 23 reporting before you need it. Document the 24-hour/72-hour/final-report workflow, contacts and decision authority.
7. Build the Article 20 governance layer. Management approval, oversight and training need to be evidenced.
8. Reuse ISO 27001 intelligently. Map what already exists, then remediate the NIS2-specific gaps rather than creating a separate compliance program from scratch.
How SecureLeap Helps Startups Navigate NIS2 Compliance
SecureLeap works with startups and growing companies on security and compliance programs that connect regulatory requirements with existing frameworks such as ISO 27001 and SOC 2.
For NIS2, that can include:
- scope and entity-classification support alongside qualified legal interpretation where needed;
- gap assessment against Article 21(2);
- mapping against Implementing Regulation (EU) 2024/2690 where it applies;
- Article 20 governance preparation for management approval, oversight and training evidence;
- Article 23 incident-response and reporting workflow design;
- supply-chain and vendor-risk improvements;
- vCISO support when the organization needs ongoing security ownership rather than a one-time project.
If you already hold ISO 27001, the fastest route is usually a structured gap assessment against the NIS2 obligations that apply to your entity, not a new security program from zero.
If you're uncertain whether NIS2 applies to your startup or how to approach it alongside your existing compliance program, book a free consultation.
Frequently Asked Questions
Does NIS2 apply to non-EU companies?
It can. Applicability depends on the covered service, establishment and jurisdiction rules, and some non-EU providers may need an EU representative. Non-EU vendors can also encounter NIS2 indirectly when European customers pass supply-chain security requirements down by contract.
Are cloud providers and MSPs in scope regardless of size?
Not automatically. Cloud computing providers, MSPs and MSSPs are covered NIS2 categories, but the standard size and scope analysis still applies unless another Article 2 exception or national designation brings the entity into scope. DNS providers and TLD registries are examples of categories treated as Essential regardless of size.
What is the difference between Essential and Important entities?
Both implement the same ten Article 21 measures. Essential entities face more proactive supervision and higher maximum administrative fines, while Important entities are generally supervised reactively after evidence or indications of non-compliance.
When did NIS2 start applying?
NIS2 entered into force in January 2023. Member States had until 17 October 2024 to transpose it, with national measures applying from 18 October 2024. Transposition and enforcement arrangements still vary by country.
Does ISO 27001 certification mean we are NIS2 compliant?
No. ISO 27001 provides substantial overlap and can reduce the amount of new work, but NIS2 adds legal and governance obligations that require a separate gap assessment.
What are the penalties for NIS2 non-compliance?
For Essential entities, Member States must provide maximum administrative fines of at least EUR 10 million or 2% of worldwide annual turnover, whichever is higher. For Important entities, the thresholds are at least EUR 7 million or 1.4%, whichever is higher.
Is there an EU-level technical standard for cloud and managed-service providers?
For specified digital and infrastructure providers that are covered by NIS2, Commission Implementing Regulation (EU) 2024/2690 sets detailed technical and methodological requirements. ENISA's June 2025 guidance provides non-binding implementation advice and evidence examples.
We are a 30-person startup selling to European banks. Are we in scope?
Possibly not directly if you are below the relevant size thresholds and no exception applies, but you can still be affected commercially. In-scope customers must manage supply-chain security and may require NIS2-aligned controls, evidence and incident commitments from suppliers.
