Network Bridge Solutions
← All insightsThinking · 5 min read

Understanding NIS2: How to Tell if Europe's New Cybersecurity Directive Applies to Your Business

Scope has rules: establishment, sector and size. The honest test for whether Europe's cybersecurity directive reaches your business, directly or through your customers.

A wireframe map showing supply lines crossing the EU border into factories outside it.

Every business owner today is juggling multiple priorities: keeping clients happy, managing costs, and chasing growth opportunities. In the midst of this chaos, the last thing you want is yet another regulatory acronym to decode. Yet, here comes NIS2, Europe's upgraded cybersecurity directive, demanding your immediate attention.

But what exactly is NIS2? And does it even apply to your business? Let's break it down.

What Exactly is NIS2?

First things first, NIS2 stands for the Network and Information Security Directive 2, a revamped and significantly strengthened successor to the original 2016 EU cybersecurity legislation (NIS1). The intention behind NIS2 is clear and ambitious: to create a uniformly high cybersecurity standard across Europe, reducing vulnerabilities in critical sectors, supply chains, and the digital economy as a whole.

The old NIS Directive set a precedent but left major gaps. Enforcement was inconsistent, expectations unclear, and the scope was limited. Cyber threats rapidly outpaced these initial measures, leaving regulators scrambling to close loopholes.

NIS2 fixes these shortcomings by:

  • Significantly widening the scope to include more sectors and smaller entities.
  • Providing clearer obligations, like defined minimum security measures.
  • Enforcing tighter accountability among company leaders and boards.
  • Implementing uniform reporting and response requirements across the EU.

Simply put, NIS2 means business. Compliance is no longer optional or vague: it's clear, structured, and legally binding. Penalties are tiered: up to €10 million or 2% of global revenue for essential entities, and up to €7 million or 1.4% for important entities, the category most in-scope readers of this article would fall into.

Does NIS2 Apply to My Business?

This is the million-euro question, and it's where many misunderstandings arise. Many assume NIS2 is only relevant for massive corporations, infrastructure operators, or EU-based entities. But here's the critical insight: scope has rules, and they are narrower, and stranger, than the myths. Three things decide it: where you are established, which sector you are in, and how big you are. Plus one special case for certain digital service types selling into the EU from outside.

Step 1: Check Your Clients and Services

NIS2 classifies in-scope organisations as Essential or Important, and the category depends on sector and size together. The sectors are listed in two annexes: high-criticality sectors (energy, transport, banking, health, water, digital infrastructure, business-to-business ICT service management, which is where managed service providers sit, public administration, space) and other critical sectors (postal services, waste, chemicals, food, manufacturing, digital providers, research).

Three things worth knowing straight away:

Professional services (accountancy, legal advisory, general consultancy) are not NIS2 sectors. If that is your business, NIS2 reaches you only through your regulated clients' supply-chain requirements, not directly.

Size matters. The directive generally applies from medium-sized upwards: 50 or more people, or over €10 million turnover. Most smaller businesses sit outside it entirely, with a few named exceptions.

And a specific list of digital service types (DNS, cloud, data centres, CDNs, managed service providers, managed security service providers, online marketplaces, search engines, social platforms) are caught even without an EU establishment if they offer services into the EU at the same size thresholds, with DNS and top-level-domain registries in scope at any size, and must designate an EU representative there.

Holding data about EU citizens does not, by itself, put you in NIS2's scope. That is GDPR's territory, and the two are often conflated.

Step 2: Consider Your Digital Footprint

Here are the same three scenarios people worry about, with the line drawn where it actually falls:

Your accounting firm in Manchester manages VAT filings for a Berlin-based client through cloud software. NIS2 does not regulate you: accountancy is not an NIS2 sector. But your Berlin client may well be regulated, and their security questionnaire will reach you all the same.

Your MSP in London provides outsourced IT and security services to a French startup. Managed service providers are on NIS2's named list: at medium size or above, offering services into the EU brings you into scope, including the duty to designate an EU representative.

Your Leeds-based consultancy accesses sensitive financial data of a client headquartered in Milan. Not directly regulated, but contractually your client's obligations flow down to you.

One of these three is directly in scope. The other two feel the directive through their customers, which in practice can be just as demanding.

The Quick Applicability Test

Ask yourself these questions, in order:

  1. Are we established in the EU (a company, subsidiary or branch)?
  2. If yes: are we in one of the listed sectors, with 50 or more people or over €10 million turnover?
  3. Wherever we are established: are we one of the named digital service types (MSP, MSSP, cloud, DNS, data centre, CDN, marketplace, search engine, social platform) offering services into the EU, at the same size thresholds?
  4. Do we supply businesses that are themselves regulated by NIS2?

Yes to 1 and 2, or to 3, means direct scope: prepare properly. Yes only to 4 means the requirements arrive through contracts and questionnaires rather than law: just as real, and usually sooner.

Beyond Compliance: The Strategic Opportunity

Yes, ignoring NIS2 can be costly. But beyond avoiding fines and penalties, achieving NIS2 compliance positions your business strategically in a market where trust, data security, and resilience increasingly shape buying decisions.

Today, clients aren't just looking for vendors; they're looking for trusted digital partners. Being NIS2-compliant becomes a powerful differentiator, setting your firm apart from competitors who lag behind or overlook the importance of cybersecurity readiness.

Think about this practically:

  • Win new business by demonstrating a clear, documented approach to cybersecurity.
  • Strengthen client loyalty by proactively protecting their data and operations.
  • Enhance valuation and investor appeal by proving operational maturity and reduced risk.

Final Thoughts: Taking Action Now

NIS2 isn't a vague future risk; it's a current operational imperative. Waiting until you're questioned by clients, regulators, or insurers could lead to significant stress, fines, or reputational damage.

However, early action is surprisingly manageable:

  • Map your EU data footprint and assess your service delivery model.
  • Identify gaps against NIS2's minimum cybersecurity requirements.
  • Engage a trusted partner or MSP specialising in managed security baselines, such as Microsoft 365 Business Premium, to simplify and accelerate compliance.

Getting clarity now prevents costly surprises later. And remember, compliance isn't merely an obligation; it's your opportunity to build a safer, more trusted, and ultimately more successful business.

Prefer the conversation to the reading?

Thirty minutes on the alignment between your strategy and your technology. Not a sales pitch.

Book a discovery call