A Bigger Net Than the Original Rules
NIS2 is the EU’s updated cybersecurity directive, and it casts a much wider net than the rules it replaced. The original NIS Directive mostly covered large operators of essential services such as energy, banking and water. NIS2 extends that to a long list of additional sectors, including postal and courier services, waste management, food production and distribution, manufacturing of certain products, digital providers and managed IT services.
In Ireland, NIS2 is being given effect through the National Cyber Security Bill, with the National Cyber Security Centre (NCSC) as the lead authority. Whatever stage the legislation is at when you read this, the direction is clear, and many businesses that never thought about “cyber regulation” will need to.
Are You Directly in Scope?
As a rule of thumb, NIS2 applies directly to medium and large organisations operating in one of the listed sectors:
- Medium: 50 or more staff, or annual turnover and balance sheet above €10 million
- Large: 250 or more staff, or turnover above €50 million
Size isn’t the only test. Some organisations are covered regardless of size, such as DNS providers or businesses that are the sole provider of a critical service.
If you’re in scope, the obligations are real:
- Risk management measures: access control, MFA, backups, encryption, incident handling and supply-chain security
- Incident reporting: an early warning within 24 hours of a significant incident, a fuller notification within 72 hours, and a final report within a month
- Management accountability: directors are expected to approve and oversee cybersecurity measures, and can be held personally responsible
- Fines: up to €10 million or 2% of global turnover for “essential” entities, and €7 million or 1.4% for “important” ones
Too Small? You’ll Probably Still Feel It
Here’s the part most small businesses miss. Even if you have 15 staff and NIS2 doesn’t name you, your customers may be in scope, and NIS2 requires them to manage risk in their supply chain.
In practice, that means security questionnaires landing in your inbox. Expect contract clauses asking you to confirm MFA, backups and incident notification. Some customers will ask for evidence rather than a tick box. A supplier who can answer those questions quickly and honestly has an edge over one who can’t.
Where to Start
You don’t need a compliance department to get ahead of this. Focus on the controls that NIS2 and customer questionnaires ask about most:
- MFA on every account that touches email, remote access or admin tools
- Backups you’ve actually tested restoring, with at least one copy offline or immutable
- Patching on a schedule, not “when someone gets around to it”
- A one-page incident plan: who to call, how to isolate a machine, who reports what and when
- An asset list: you can’t secure devices and accounts you don’t know exist
The Practical Takeaway
If you’re a medium or large organisation in one of the listed sectors, it’s time to confirm your status formally and assign responsibility at board level. If you’re smaller, treat NIS2 as a preview of what your bigger customers will soon expect from you.
If a supplier questionnaire has already landed on your desk and you’re not sure how to answer it, send it to us. We fill these in with clients regularly and can tell you where the real gaps are.