NIS2 guide for companies

NIS2: which companies are obliged and how to prepare

The NIS2 Directive raises cybersecurity requirements in Europe. In this guide we explain who it may affect, what obligations it introduces and how to prepare a roadmap without duplicating work with ISO 27001 or ENS.

Reading: 8 minUpdated: 2026Cybersecurity · Compliance · Risks

· Editorial review: Blue Moon Cybertech

NIS2 is the new European cybersecurity directive that expands the scope of the previous NIS and requires many organizations to improve their governance, risk management, incident response and supplier control. Its objective is not to create more bureaucracy, but to reduce the impact of incidents in sectors essential to the economy and society.

For a company, the important question is not only “am I obligated?”, but also: What clients, contracts or suppliers can begin to require controls equivalent to NIS2?

Quick summary

NIS2 can directly affect essential and important entities, but also indirectly affect technology providers, industrial companies, SaaS, MSPs, consulting firms and organizations that are part of a critical supply chain.

What is NIS2

NIS2 is a European Union directive aimed at strengthening the security of networks and information systems. It replaces and expands the previous framework, incorporating more sectors, more obligations and greater responsibility of the management bodies.

In practice, NIS2 asks organizations to manage cybersecurity as a business risk: with those responsible, controls, evidence, continuity plans and a real capacity to respond to incidents.

Which companies may be bound by NIS2

Applicability depends on factors such as the sector, the size of the organization, the type of activity and the national regulations that transpose the directive. Even so, there are groups that should review their situation as soon as possible.

Essential entities

They usually include organizations from particularly critical sectors, such as energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, public administration or space.

Important entities

They may include other relevant sectors such as postal services, waste management, manufacturing, production and distribution of chemical products, food, manufacturing of certain critical products, digital suppliers, marketplaces, search engines or social networks.

Suppliers and supply chain

Even if a company is not directly included, it may be affected by contracts with customers that are subject to NIS2. For example: IT providers, software development, cloud, maintenance, cybersecurity, MSP, integrators or companies that access sensitive information of regulated clients.

NIS2 main obligations

The specific obligations will depend on the transposition and the specific case, but the key areas are usually:

  • Cybersecurity risk management and technical measures provided.
  • Information security policies and internal governance.
  • Incident management, escalation and notification.
  • Business continuity, backups and recovery.
  • Security in the supply chain and critical suppliers.
  • Security in acquisition, development and maintenance of systems.
  • Access control, authentication, encryption and asset protection.
  • Training and awareness for management and teams.

Relationship between NIS2, ISO 27001 and ENS

NIS2 is not the same as ISO 27001 nor that he National Security Scheme, but they have many points in common. That is why it is advisable not to treat them as separate projects.

ISO 27001 helps create a risk-based information security management system. ENS establishes measures for systems linked to the Spanish public sector. NIS2 strengthens governance, incident response and risk management in critical European sectors.

A well-designed roadmap can reuse asset inventory, risk matrix, policies, procedures, controls, evidence, training, supplier management and continuity plans.

How to prepare for NIS2 step by step

  1. Analyze applicability: sector, size, activity, clients, contracts and supply chain.
  2. Define scope: affected systems, services, headquarters, processes, suppliers and data.
  3. Assess gaps: Compare the current situation with the expected requirements.
  4. Prioritize risks: Identify what can disrupt business or impact critical customers.
  5. Implement controls: access, copies, continuity, incidents, suppliers, secure development and training.
  6. Prepare evidence: policies, records, responsible parties, reviews, reports and indicators.
  7. Periodically review: NIS2 is not a one-time document; requires continuous improvement.

Common mistakes when addressing NIS2

  • Wait for the client or the Administration to formally demand it.
  • Treat NIS2 as a legal-only project and not risk management.
  • Copy generic policies without real controls behind them.
  • Do not involve management, IT, legal, purchasing and operations.
  • Forget critical suppliers and technological dependencies.
  • Do not connect NIS2 with ISO 27001, ENS, GDPR or business continuity.

Initial checklist to know where to start

  • Do you know if your sector appears within the scope of NIS2?
  • Have you identified your critical services and main assets?
  • Is there an updated cybersecurity risk matrix?
  • Is there a clear incident procedure and those responsible?
  • Can you demonstrate backups and proof of recovery?
  • Do you evaluate the security of key suppliers?
  • Does management receive periodic information on cybersecurity risks?
  • Do you have sufficient evidence for an audit or client request?

More blog topics on regulations, BOE and cybersecurity

We have organized each standard and news in a separate entry so that you can consult its source, scope and practical application without mixing different frameworks.

Each entry includes a link to the official source—BOE or EUR-Lex—and a practical reading aimed at companies.

Conclusion

NIS2 is an opportunity to organize cybersecurity wisely: know what risks matter, what controls are necessary, who responds to incidents, and how to demonstrate that the organization is acting responsibly.

The most efficient way to prepare is to first conduct an applicability and gap diagnosis, and then build a roadmap that can align with ISO 27001, ENS, and other customer requirements.

Do you want to know if your company is affected?

At Blue Moon Cybertech we can review your situation, detect gaps and propose a realistic roadmap for NIS2, ISO 27001 and ENS.

Request NIS2 diagnosis →