Think NIS2 doesn't apply to you? A 3-step test
The new cybersecurity directive affects far more companies than most assume. In three minutes you'll know whether yours is one of them — and what to do.
NIS2 is a new EU directive that significantly raises cybersecurity requirements. Many companies assume it doesn’t concern them — and they’re wrong. Here’s a quick three-step test.
Step 1: Which sector are you in?
The directive covers a much broader range of industries than before — from energy, healthcare and transport to manufacturing, food and digital services. If you supply products or services to these sectors, you may fall under its scope as part of the supply chain.
Watch out for
- Do you operate in a regulated or critical sector?
- Do you have more than 50 employees or over €10 million in turnover?
- Are you a supplier to a company that falls under NIS2?
If you answered “yes” at least once, NIS2 probably applies to you.
Step 2: Are the basics covered?
The directive is about real resilience, not paperwork. The minimum it builds on:
- regular, tested backups,
- up-to-date systems and patch management,
- a properly configured firewall and network segmentation,
- multi-factor authentication (MFA) on access,
- an incident response plan.
Step 3: Can you prove it?
NIS2 requires not just measures but also documentation and the ability to report incidents within set deadlines. Company management is accountable — and real fines apply.
This is exactly where we help: from auditing your current state to putting measures and documentation in place. If you’re unsure where you stand, get in touch for a free consultation.
