TL;DR
- NIS2 scope is not just a sector-and-size question; supply chain obligations can pull you in even if the directive does not apply directly.
- The EU deadline was 2024, but national laws, registration windows and enforcement activity are landing through 2025 and 2026.
- Essential and important entities face the same Article 21 security obligations; the main difference is supervision model and maximum penalty.
- Organisations selling into EU critical sectors should expect NIS2-driven contract clauses, questionnaires, and evidence requests from customers.
- 6clicks helps teams confirm obligations, map Article 21 to existing controls, collect evidence continuously, and manage supplier risk in one place.
The EU deadline was 2024. The obligations that actually bind you only went live in 2025 and 2026, which is exactly why this is a 2026 problem.
17 October 2024 was the date Member States were supposed to have NIS2 in national law. Most missed it. NIS2 is a directive, so it creates no direct obligations until each country passes its own statute, and that has only happened recently:
The first step is knowing whether, and how, NIS2 applies to you. The rest of this page walks you through it.
| Annex I. Sectors of high criticality | Annex II. Other critical sectors |
|---|---|
|
Energy (electricity, district heating and cooling, oil, gas, hydrogen)
|
Postal and courier services Waste management Banking Food (production, processing, distribution) Digital providers (online marketplaces, search engines, social platforms) Research organisations |
Note: Not in either column? Go to Step 4. You may still be in scope.
| Annex I sector | Annex II sector | |
|---|---|---|
| Large (250+ staff, or turnover above €50m and balance sheet above €43m) | Essential entity | Important entity |
| Medium (50 to 249 staff, or turnover above €10m) | Important entity | Important entity |
| Below medium | Check Step 4 | Check Step 4 |
| Essential | Important | |
| Supervision | Proactive. Regulators can inspect and audit without an incident | Reactive. Supervision follows evidence of non-compliance or an incident |
| Maximum fine | €10m or 2% of global annual turnover, whichever is higher | €7m or 1.4% of global annual turnover, whichever is higher |
| Security obligations | Same ten measures under Article 21 | Same ten measures under Article 21 |
| Reporting obligations | Same. Early warning at 24 hours, notification at 72 hours, final report at one month | Same |
Note: The obligations are identical. Only the supervision model and the penalty ceiling differ. Being classified as important is not a lighter compliance burden.
Size thresholds do not apply if any of these are true:
Not in scope directly? Your customers still are.
Article 21(2)(d) requires in-scope organisations to manage security risks in their supply chain and across supplier relationships. In practice, that obligation moves down the chain as contract clauses, security questionnaires, and evidence requests.
If you sell into energy, health, transport, public administration, or digital infrastructure in the EU, NIS2 will reach you through procurement whether or not it reaches you through the annexes.
NIS2 is a directive, not a regulation. It takes effect through each Member State's national law, and transposition has been uneven. Your specific thresholds, registration deadlines, and reporting channels are set by the country you operate in, not by the directive text.
Operating across several Member States means several sets of national rules.
Scope tells you whether the obligations apply. Article 21 tells you what they are. Ten security measures, each requiring evidence that they work in practice, with management personally accountable for approving and overseeing them under Article 20. See how the ten Article 21 measures map to ISO 27001 controls you may already have.
Scope is step one. 6clicks runs the rest. Once you know whether you are an essential entity, an important entity, or pulled in through the supply chain, the work is proving you meet the ten Article 21 measures, and keeping that evidence current. 6clicks brings scoping, controls, evidence, and reporting in one place.
| What NIS2 asks for | How 6clicks helps |
|---|---|
| Confirm your classification and obligations | Built-in Content Library with NIS2 mapped alongside ISO 27001, DORA, CMMC and more, so you assess once and reuse across frameworks |
| Implement the ten Article 21 security measures | Prebuilt control sets and dedicated registers to assign owners, track implementation and close gaps against Article 21 |
| Show the measures work in practice | 6clicks iGRC (Intelligent GRC) moves you from point-in-time compliance to continuous assurance: automated evidence collection through no-code integrations, an evidence register with freshness alerts that flag stale evidence before an audit does, and Hailey AI validating evidence against each test and reasoning across linked controls, assets, and frameworks via the GRC Knowledge Graph, with management oversight and visibility through configurable dashboards for Article 20 accountability |
| Meet 24h / 72h / 1 month reporting deadlines | Incident management workflows to log, triage, and report within statutory timeframes |
| Manage supply chain risk (Art. 21(2)(d)) | Centralized third-party register with vendor assessments and security scanning to push and evidence requirements down the chain |
| Operate across several Member States | Sovereign GRC infrastructure that runs where your data lives, with reusable assessments across entities and regions |
See how 6clicks maps the ten Article 21 measures to controls you may already have.
Speak with our team.