NIS2 for mid-market: what IT actually has to do

by
Dawid Winiarski
Last update:
July 17, 2026

The NIS2 Directive (EU) 2022/2555 is the European Union's current cybersecurity framework for critical and important sectors. It replaced the 2016 NIS Directive, widened the scope substantially, and added personal liability for management alongside mandatory security measures. The question you have been asked is practical: are we in scope, and if so, what do we need to do? Here is the answer without the legal abstractions: who it applies to, what the security measures actually require, how incident reporting works, and what IT needs to do to get from the current state to a defensible one.

  • NIS2 applies to organizations in 18 designated sectors that exceed 50 employees or EUR 10 million annual turnover. Certain digital infrastructure providers are in scope regardless of size.
  • Entities are classified as "essential" or "important." The Article 21 obligations are the same for both; supervision intensity differs.
  • Article 21 lists 10 mandatory risk-management domains. Access control, MFA, asset management, incident handling, supply-chain security, and business continuity are all explicitly named.
  • Incident reporting under Article 23 is a three-stage obligation: early warning within 24 hours, full notification within 72 hours, final report within one month.
  • Management is personally accountable under Article 20. Boards must approve cybersecurity measures, follow training, and can be held individually liable.
  • The penalty ceiling for essential entities is EUR 10 million or 2% of global annual turnover, whichever is higher.
  • Poland transposed NIS2 through the amended KSC Act (UKSC 2.0), in force 3 April 2026, with a staged rollout: self-identification by 3 October 2026, full implementation by 3 April 2027, first essential-entity audits from 3 April 2028.
  • In Poland the duty is to self-identify; there is no ministerial summons. A management board president who fails to register an in-scope company can face an individual sanction of up to 300% of their salary, separate from the company fine.

what NIS2 is and why it exists

The NIS2 Directive (formally Directive (EU) 2022/2555) entered into force on 16 January 2023. Member states were required to transpose it into national law by 17 October 2024. The directive replaced NIS1, which had been widely criticized for producing inconsistent implementation across member states.

NIS2 exists to raise the floor on cybersecurity across the EU economy. Its three core mechanisms are: mandatory security measures for a defined population of entities, incident reporting obligations that apply immediately when a significant incident occurs, and management accountability that ties personal liability to cybersecurity governance. The scope is substantially wider than NIS1. The European Commission estimated that the number of entities falling under NIS2 obligations would increase by a factor of roughly 10 compared to the previous directive.

who it covers: essential vs important entities, sectors, size thresholds

NIS2 covers organizations in 18 designated sectors that exceed a size threshold of 50 employees or EUR 10 million in annual turnover. Certain categories, including cloud computing service providers, public electronic communications networks, trust service providers, and top-level domain registries, are in scope regardless of size.

Essential entities operate in the 11 high-criticality sectors listed in Annex I: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space.

Important entities operate in the 7 sectors listed in Annex II: postal and courier services, waste management, chemicals, food production and distribution, manufacturing, digital providers, and research organizations.

Essential entities face proactive, ongoing supervision. Important entities are subject to reactive supervision, meaning regulators investigate when evidence of non-compliance arises. The obligations under Article 21 are identical for both categories. Large enterprises (250 or more employees or EUR 50 million or more turnover) in Annex I sectors are automatically classified as essential. Medium enterprises (50 to 249 employees) in the same sectors are generally important, with member states retaining the option to designate some as essential.

how to determine whether your organization is in scope

Step 1: Sector check. Is your organization's primary activity in one of the 18 sectors covered under Annex I or Annex II? If your primary activity falls clearly outside all 18 sectors, you are likely not in scope directly, though supply chain provisions may create indirect obligations if you serve in-scope customers.

Step 2: Size check. Does the organization exceed 50 employees or EUR 10 million in annual turnover? If no, the general threshold does not apply unless you fall into a size-exempt category.

Step 3: Registration, and who carries the duty. Some member states designate entities centrally. Others place the duty to self-identify and register on the organization itself. Poland is the second kind: under the amended KSC Act, you must assess your own status and register in the KSC list by 3 October 2026. There is no ministerial summons and no letter confirming you are in scope. Treating the absence of a notice as confirmation that you are out of scope is a mistake, and in Poland it carries a specific personal sanction.

If after these three steps the answer is uncertain, a legal assessment against the relevant national transposition is the appropriate next step. The IT function's role is to prepare for the operational obligations regardless, since the security measures required are sound practice independent of formal designation.

article 21: the 10 security measures in plain language

Article 21(2) lists the minimum domains that all essential and important entities must address. The measures must be appropriate and proportionate to the entity's size, risk exposure, and the potential impact of an incident. The directive sets the domain and leaves proportional judgment to the entity.

1. Risk analysis and information system security policies (a). A documented, maintained risk assessment process. Ad hoc risk awareness does not satisfy this; a written, periodically reviewed risk analysis does.

2. Incident handling (b). Policies and procedures for detecting, analyzing, containing, and recovering from security incidents, including roles, escalation paths, and documentation. Combined with Article 23, this requires both an internal incident response capability and a compliant reporting process.

3. Business continuity and crisis management (c). Backup management, disaster recovery, and crisis management procedures, with defined RTO and RPO targets for critical systems. Tested and documented, not a theoretical plan.

4. Supply chain security (d). Assessment of the cybersecurity posture of direct suppliers and service providers: vendor security assessments, contractual cybersecurity requirements, and a process for reviewing supplier risk. This extends to software providers, cloud platforms, and managed service providers.

5. Security in acquisition, development and maintenance (e). Vulnerability handling and disclosure, security requirements in procurement, and secure development practices. For most mid-market organizations, this primarily applies to the security of systems they buy and how they manage patching.

6. Assessing the effectiveness of measures (f). The entity must demonstrate its security measures work as intended through internal audit, penetration testing, and monitoring on a defined cycle, with findings actioned.

7. Cyber hygiene and training (g). Security awareness training for all personnel plus documented baseline hygiene practices. Both are required. A continuous, documented awareness process is more likely to satisfy this than an infrequent checkbox programme.

8. Cryptography and encryption (h). Encryption for data at rest and in transit where risk assessment justifies it, alongside documented cryptography policies covering key management.

9. HR security, access control policies, and asset management (i). The domain most directly connected to identity and access management. It requires access control based on need-to-know and least privilege, documented policies governing who can access what and why, an asset inventory, and personnel security measures including joiner-mover-leaver processes. Access reviews, privileged access controls, offboarding procedures, and service account management all map directly here.

10. Multi-factor or continuous authentication, and secured communications (j). MFA is explicitly required "where appropriate," which for an IT environment means administrator accounts, remote access, and access to systems processing sensitive or critical data.

article 23: incident reporting timelines

When a significant incident occurs, Article 23 imposes a three-stage reporting obligation to the relevant national CSIRT or competent authority. A significant incident is one that causes or has the potential to cause severe operational disruption, financial loss, or considerable damage to other persons.

Stage 1: Early warning, within 24 hours. A brief initial notification indicating that an incident has occurred, whether it is suspected to be malicious, and whether it could have cross-border impact. The clock runs from the moment the entity becomes aware, not from the start of the incident.

Stage 2: Incident notification, within 72 hours. An updated assessment including severity and impact, an initial understanding of root cause where available, and indicators of compromise where known.

Stage 3: Final report, within one month of the Stage 2 notification. A detailed account: what happened, how it was handled, the actual impact, and what steps prevent recurrence.

The reporting obligation requires that IT and security teams can detect, assess, and document incidents quickly. An organization that lacks the logging infrastructure to reconstruct what happened will struggle to meet both the timeline and the evidence requirements. For trust service providers, a stricter 24-hour notification timeline applies.

article 20: management accountability

Article 20 most changes the conversation at the board level. Management bodies must approve the cybersecurity risk-management measures their organizations take under Article 21 and oversee implementation. Members are personally liable for infringements if they failed to exercise appropriate oversight. The directive also requires that they complete training adequate to identify cybersecurity risks.

The penalty structure reflects this: fines for essential entities can reach EUR 10 million or 2% of global annual turnover, whichever is higher. For important entities, the ceiling is EUR 7 million or 1.4%. Individual directors can also be publicly reprimanded or barred from management roles. Germany's implementation (in force 6 December 2025) makes management bodies personally liable for damages from cybersecurity duty breaches, and that liability cannot be waived by the company.

transposition status across the EU and in Poland

NIS2 required transposition by 17 October 2024. Most member states missed that deadline. As of June 2026, 23 of 27 have transposed NIS2; France, Ireland, the Netherlands and Spain remain at draft stage (ECSO NIS2 Transposition Tracker, June 2026). The European Commission opened infringement proceedings in November 2024 and issued reasoned opinions to 19 member states in May 2025. Enforcement activity is already underway in Germany, the Netherlands, and France.

Poland (as of June 2026): Poland transposed NIS2 by amending the Act on the National Cybersecurity System (KSC), in the version commonly referred to as UKSC 2.0. The president signed it on 19 February 2026 and it entered into force on 3 April 2026. The rollout runs on a staged timeline:

  • 3 April 2026. UKSC 2.0 in force. Proactive supervision, ad hoc inspections, and the incident-reporting obligation all apply from this date.
  • 3 October 2026. Deadline for self-identification in the KSC register. Companies assess their own status and register themselves.
  • 3 April 2027. Full implementation of NIS2 obligations, as the transitional window for the substantive measures closes.
  • 3 April 2028. First mandatory audits of essential entities, the point at which audit-driven enforcement begins.

The practical warning for Polish companies: do not let the 2028 audit date lull you. Proactive supervision, ad hoc inspections, and incident reporting are live from 3 April 2026. Alongside the company-level fines, the management board president can face an individual penalty of up to 300% of their salary, for example where a company that was in scope failed to register.

what IT actually has to do: a readiness summary

This maps the Article 21 domains to concrete IT actions. It is a starting point, not a legal assessment.

Scoping and governance. Confirm whether the organization is in scope, check how your member state designates entities, bring NIS2 scope and obligations to senior management and the board (Article 20 makes board approval mandatory), and document the outcome.

Risk management. Establish or update a formal risk assessment process covering network and information systems, document it, and set a review cadence of at least annual.

Incident response. Define what constitutes a significant incident, document detection and escalation procedures, identify who handles each stage of the Article 23 reporting process, test the process with a tabletop exercise, and establish logging compatible with 24-hour reporting.

Business continuity. Document backup procedures and RTO/RPO targets, test restore procedures, and maintain a business continuity and disaster recovery plan.

Supply chain. Inventory critical third-party suppliers, assess their posture, include cybersecurity requirements in new contracts, and check vendor vulnerability disclosure practices.

Access control and asset management. Maintain a current asset inventory, document least-privilege access policies, run a joiner-mover-leaver process that closes access in SaaS applications too, run periodic access reviews, manage privileged access separately, and inventory and review service accounts.

Multi-factor authentication. Enforce MFA on all administrator accounts, remote access, and systems processing sensitive data, and check for gaps where new systems or service accounts lack equivalent protection.

Cyber hygiene, cryptography, and effectiveness. Deliver documented training on a defined cycle, review encryption for data at rest and in transit, and schedule periodic assessments with findings tracked and presented to management.

how identity, access, and SaaS hygiene map to article 21

Several of the Article 21 measures concentrate in the identity and access domain. This is not incidental: compromised credentials and excessive access are among the most common initial access vectors in incidents that trigger NIS2 reporting obligations.

Article 21(2)(i) directly requires access control policies and asset management: a current account inventory across systems not just the main directory, documented least-privilege policies, a working JML process that closes access in SaaS applications (offboarding that closes the Entra or Okta account but leaves SaaS app access open does not satisfy the requirement), and access review cycles with documented decisions.

Article 21(2)(j) directly requires MFA. For most mid-market environments, MFA gaps are the fastest path from zero to a credible control posture. SaaS hygiene connects to both Article 21(2)(i) and (d): shadow SaaS apps carry access IT cannot review, and OAuth grants can give external applications access to sensitive data without appearing in a standard access review.

common misunderstandings

"We are too small to be covered." The threshold is 50 employees or EUR 10 million in turnover, provided the organization operates in a covered sector. A company with 60 employees in the energy supply chain, financial services, or healthcare is likely in scope. Sector matters as much as size.

"Our sector is not listed, so we are not affected." Supply chain obligations under Article 21(2)(d) mean in-scope entities must impose security requirements on their suppliers. A company not directly covered that serves covered entities will face indirect obligations through contracts.

"We received no designation notice, so we are out of scope." National designation processes were still rolling out in many member states as of June 2026. The absence of a formal notice is not confirmation of out-of-scope status.

"NIS2 requires us to certify compliance." There is no NIS2 certification scheme. The directive requires demonstrable security measures and evidence they work. ISO 27001 provides substantial overlap but is not a substitute for national compliance.

"Incident reporting applies only to data breaches." Article 23 applies to significant incidents affecting availability, integrity, or confidentiality. Ransomware that disrupts operations without exposing personal data is in scope. The reporting scope is broader than GDPR's.

"The IT team can handle this without involving the board." Article 20 is explicit: management bodies must approve the measures, oversee implementation, and follow training. Personal liability attaches to management.

Subscribe to unshadowed.

Subscribe to receive the latest blog posts to your inbox and stay up to date with

By subscribing you agree to with our Privacy Policy.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

let's start with a conversation

Most first conversations start with not quite knowing what you have or where to begin. That's normal, and it's exactly where we're useful.

Tell us what prompted this. An upcoming audit, an incident, a client's security questionnaire, or just a sense that things have gotten messy.

We'll take it from there

Julian Machowski
Head of Technical Sales
+48 783 762 997
julian@unshadowit.com
Let's connect on LinkedIn
Message received. We'll be in touch soon.
Something failed. Try again or call us directly.