NIS 2 (Network and Information Security Directive) – What It Means and Who It Affects
The NIS 2 Directive (Network and Information Security) is a European regulation requiring member states to enforce strict cybersecurity and risk management measures for certain types of companies. Unlike the first version (NIS 1), this updated directive significantly broadens the range of sectors it applies to and introduces clearer, tougher penalties for non-compliance.
Who does it apply to?
This is where many companies get confused.
“We’re not in IT.”
“We don’t sell digital services.”
“We’re too small.”
These are common assumptions—but NIS 2 is not just for big tech corporations.
The directive targets two main categories of entities:
- Essential entities – organizations operating in critical infrastructure such as energy, transport, healthcare, water, banking, digital infrastructure, and public administration.
- Important entities – a broader group that includes IT service providers, equipment manufacturers, courier companies, research institutions, the food industry, and e-commerce businesses.
Company size also matters. As a rule, NIS 2 applies to businesses with more than 50 employees or an annual turnover above €10 million.
However, there’s a crucial exception: smaller companies can also fall under the directive if they play a critical role in supply chains or manage key IT infrastructure.
For more details, see the link below:
What is the NIS 2 Directive and How Does It Affect Your Business in 2025?

