NIS2 in Practice: Registration, 24 Hour Reporting and Supply Chain Reality
NIS2 had an unusual rollout. The transposition deadline was 17 October 2024, and most Member States missed it. Two years later the picture is still uneven, which has given a lot of companies the impression that nothing much happened.
That impression is now wrong. National laws have landed, registration portals are open, and supervisory authorities have started asking questions. Germany opened its registration portal on 6 January 2026 with a statutory deadline of 6 March. The Netherlands brought its Cyberbeveiligingswet into force on 15 August 2026. Others followed through the year.
If you have been waiting for clarity, it has arrived, and the answer is that you are probably late rather than early.
Who Is in Scope
NIS2 replaced the original 2016 network and information security directive and widened the net considerably. Scope is determined by sector and by size.
Essential entities cover sectors of high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure, ICT service management, public administration and space.
Important entities cover other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of certain products including medical devices, computers, electronics, machinery and vehicles, digital providers such as online marketplaces, search engines and social platforms, and research organisations.
The size threshold is generally medium-sized enterprise or above, meaning 50 or more employees or annual turnover above 10 million euros. Some entity types are in scope regardless of size, including certain DNS providers, TLD registries, trust service providers and public electronic communications providers.
Germany's supervisory authority estimated roughly 29,500 entities in scope in that country alone. By the March 2026 statutory deadline about 11,500 had registered, rising to around 18,500 by the end of May. Read that as a warning rather than as reassurance. Slow registration by peers does not create an exemption.
Two things catch companies out. First, the sector list includes ordinary manufacturers, not just infrastructure operators. If you make machinery, electronics or medical devices at any scale, look carefully. Second, even if you are out of scope, your customers who are in scope will push their supply chain obligations onto you contractually. Being out of scope does not mean being unaffected.
Registration Is a Separate Obligation
Most Member States require in-scope entities to register with the national authority, and this is where the first failures are happening.
Registration typically means identifying the entity, its sector classification, its services, its contact points for security matters, and the Member States in which it operates. Deadlines vary by country, and the process is often more involved than a web form.
Do not assume you are exempt because the authority has not contacted you. NIS2 uses self-identification. It is your job to determine scope and register, not the regulator's job to find you.
The Reporting Timeline
Incident reporting is the most operationally demanding part of the directive, and the timings are tight.
- Within 24 hours of becoming aware of a significant incident: an early warning, stating whether the incident is suspected to be caused by unlawful or malicious acts and whether it could have cross-border impact.
- Within 72 hours: an incident notification, updating the early warning with an initial assessment, severity, impact and indicators of compromise.
- On request: intermediate status updates.
- Within one month: a final report with a detailed description, the type of threat or root cause, mitigation measures applied, and any cross-border impact.
A significant incident is one that has caused or is capable of causing severe operational disruption or financial loss, or has affected or is capable of affecting others by causing considerable material or non-material damage.
The 24 hour early warning is the hard part. Twenty-four hours is not enough time to investigate. It is a heads-up, and the directive expects it as a heads-up. Teams that wait until they understand the incident before reporting will miss the window every time.
If your organisation also handles personal data, you may be running a GDPR 72 hour breach notification in parallel to a different authority, with a different scope and a different threshold. Those processes need to be designed together, which we cover in our GDPR guide.
The Ten Measures
Article 21 requires risk management measures covering, at minimum, ten areas. In plain terms:
- Risk analysis and information system security policies. Documented, current, and actually referenced by the people running systems.
- Incident handling. Detection, response, recovery, and the reporting workflow above.
- Business continuity and crisis management. Backup management, disaster recovery, and a tested restore rather than a scheduled backup job.
- Supply chain security. Covered separately below because it is where most of the effort goes.
- Security in acquisition, development and maintenance. Secure development practices, vulnerability handling and disclosure.
- Effectiveness assessment. How you know your controls work. Testing, audits, metrics.
- Cyber hygiene and training. Basic practices and awareness, including for management.
- Cryptography and encryption policies. Where encryption is used and how keys are handled.
- Human resources security, access control and asset management. Joiners, movers, leavers, least privilege, and an asset inventory that is current.
- Multi-factor authentication and secured communications. MFA or continuous authentication, secured voice, video and text communications, and emergency communications systems.
None of these are exotic. The gap in most organisations is not knowing what to do, it is evidence. NIS2 supervision is documentation-heavy, and an undocumented control is functionally an absent one.
Supply Chain Is the Real Work
The most consequential change in NIS2 is the emphasis on supply chain risk. In-scope entities must consider the security practices of their direct suppliers and service providers, including the quality of their products and their secure development practices.
Practically, this cascades. A hospital in scope pushes requirements onto its software vendors. Those vendors push requirements onto their hosting providers and their component suppliers. Companies well outside the formal scope end up answering NIS2-derived security questionnaires because their customer is in scope.
If you sell software or services into any of the listed sectors, expect:
- Security questionnaires as a standard part of procurement, before contract rather than after.
- Contractual security requirements including incident notification timelines that flow up to your customer's 24 hour obligation.
- Requests for evidence: penetration test summaries, SOC 2 or ISO 27001 status, vulnerability management process documentation, SBOMs.
- Audit rights.
The efficient response is to build the evidence pack once. Most of what customers ask for is the same across questionnaires, and the artefacts overlap heavily with the Cyber Resilience Act obligations. Build a software bill of materials pipeline, a documented vulnerability handling process and an incident runbook, and you have answered the majority of both.
Management Liability
NIS2 makes management bodies responsible for approving cybersecurity risk management measures and overseeing implementation, and Member States can hold them personally liable. Management is also required to follow training.
This is why NIS2 conversations have moved faster than most compliance topics inside companies. Personal liability changes how quickly a board approves a budget.
Penalties
For essential entities, up to 10 million euros or 2 percent of total worldwide annual turnover, whichever is higher. For important entities, up to 7 million euros or 1.4 percent. Authorities can also issue binding instructions, order the publication of non-compliance, and in serious cases suspend certification or temporarily prohibit individuals from exercising management functions.
Where to Start If You Have Not
A workable sequence for an organisation starting from close to zero:
Determine scope properly. Sector, size, and the Member States where you are established. Get this in writing from counsel, because everything else follows from it.
Register. Check your national authority's deadline and process. If it has passed, register anyway.
Build the asset inventory. You cannot manage risk on systems you have not listed. This is the single highest-leverage artefact and the one most often missing.
Write the incident runbook and rehearse it. Focus on the 24 hour path. Who declares, who assesses cross-border impact, who submits, and what happens at 3am on a public holiday.
Do the supplier review. List your critical suppliers, assess them, and get security terms into contracts at renewal.
Close the obvious gaps. MFA everywhere, tested backups, patch management, access reviews, logging. Unglamorous, and it is what an audit will look at first.
Document as you go. Not a policy binder written afterwards. Decisions recorded when they are made, with dates and owners.
An Honest Note on Effort
For an organisation with a functioning security programme, NIS2 is mostly a documentation and reporting exercise. For an organisation without one, it is a genuine build, measured in quarters rather than weeks.
The mistake is treating it as a compliance project owned by legal. The obligations are operational. They live with the people who run systems, and the artefacts only stay current if they are part of how the team works rather than something produced for an audit.
Getting Help
We build and operate software systems for companies across Europe, including the monitoring, logging, backup and supply chain visibility that NIS2 expects. Where we are useful is the engineering side: making the controls real and the evidence a by-product of normal work rather than a separate effort.
Get in touch at office@c9group.dev. Our 2026 EU digital compliance guide covers how NIS2 fits with everything else landing this year, and the legacy system maintenance service page describes the work that usually comes first.
We are not a law firm and we do not give legal advice. Scope determination in particular belongs with your counsel.