The NIS2 Directive has significant implications for international companies operating within the EU, imposing cybersecurity obligations and responsibilities on those that fall within its scope.
Here is an overview:
1. Expanded scope and inclusion criteria
- The NIS2 significantly expands the range of sectors and entities subject to its provisions, going beyond the focus of the original NIS directive to include sectors considered critical due to their level of digitalization and their interconnection with the EU economy and society.
- International companies operating in sectors such as energy, transport, health, digital infrastructure, and others listed in Annexes I and II of the directive must assess whether they fall within the scope based on their activities and size.
- A fundamental change is the introduction of a size threshold. All medium and large enterprises in the specified sectors fall within the scope of NIS2. This means that international companies, regardless of their headquarters, must comply if they meet the size criteria for their sector within the EU.
- The directive also allows Member States to identify smaller entities with high-risk profiles that must comply with its obligations. This provision gives national authorities flexibility to address specific cybersecurity risks.
2. Jurisdiction and the “main establishment” principle
- For most entities, NIS2 jurisdiction falls under the Member State where they are established. If established in multiple Member States, each of these countries has jurisdiction, requiring cooperation and potential joint supervisory actions by the respective authorities.
- However, certain international companies providing cross-border digital services fall under the jurisdiction of the Member State where their “main establishment” in the EU is located. This includes providers of domain name systems, cloud computing services, data centers, content delivery networks (CDNs), online marketplaces, search engines, and social networking platforms.
- To ensure clarity, these companies must notify the competent authorities of their main establishment and other legal locations within the EU. If they do not have a unit in the EU, they must designate a representative within the EU, whose information must be provided to the authorities. This provision aims to simplify compliance for these companies, avoiding the need to deal with a complex set of different national regulations.
3. Cybersecurity risk management and incident reporting
- NIS2 requires companies within its scope to implement appropriate technical, operational, and organizational measures to manage cybersecurity risks related to their network and information systems. This risk-based approach requires a comprehensive cybersecurity strategy tailored to the specific risks faced by the company.
- The directive provides a list of ten essential security elements that companies must address, including incident management, supply chain security, vulnerability management and disclosure, and the use of encryption. These elements form a baseline for cybersecurity practices that all subject companies must follow.
- International companies must establish robust incident reporting mechanisms. They must promptly notify their national CSIRT or competent authority of any significant cybersecurity incident that impacts their operations in the EU. This includes incidents that significantly disrupt the provision of services or that may impact other entities, causing substantial material or non-material damage.
- The directive provides for a two-stage reporting process: an “early warning” followed by a more detailed report within 72 hours, including information on the impact of the incident, mitigation measures, and future prevention strategies. This standardized reporting framework facilitates timely response and cross-border collaboration on cybersecurity incidents.
4. Focus on supply chain security
- NIS2 emphasizes the security of supply chains and supplier relationships, requiring companies to address cybersecurity risks within these ecosystems. This includes assessing the security posture of critical suppliers and implementing appropriate controls to mitigate risks.
- This requirement highlights the interconnected nature of cybersecurity and the shared responsibility in risk mitigation. International companies must carefully assess their supply chains within the EU and ensure alignment with NIS2 requirements.
5. Strict enforcement and harmonized sanctions
- The directive grants national authorities enhanced supervisory and enforcement powers. This includes conducting regular audits and inspections, issuing binding instructions, imposing fines, and taking corrective actions.
- NIS2 introduces a harmonized sanctioning framework across Member States to ensure consistent and effective enforcement. This includes significant financial penalties, particularly for essential entities, which may face fines of up to €10,000,000 or 2% of their total global annual turnover.
- These strict enforcement mechanisms underscore the seriousness with which the EU views cybersecurity and the need for rigorous compliance by international companies operating within its borders. In Italy, the ACN has defined the deadlines and procedures for registration in the NIS2 list for obligated entities.
6. Implications beyond direct applicability
- Although NIS2 primarily targets medium and large enterprises, its impact indirectly extends to SMEs. Larger companies subject to the directive are incentivized to ensure that their supply chains meet the required cybersecurity standards, pushing SMEs to improve their cybersecurity posture to maintain business relationships.
- Furthermore, resources such as the European vulnerability database, established and maintained by ENISA, offer benefits to all stakeholders, including SMEs, by providing valuable threat intelligence and promoting best practices in vulnerability management.
What to do if your company falls under the NIS2 scope
International companies operating in the EU must carefully analyze their obligations under the directive and initiate a structured adjustment path. Understanding what the main objective of the NIS2 Directive is is the starting point for correctly setting priorities. Those who have already identified their scope of applicability can evaluate a NIS2 compliance path that covers risk analysis, technical and organizational measures, and incident management.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
