Skip to main content

Getting Started with NIS2

The NIS2 Directive (EU 2022/2555) expands EU cybersecurity obligations to a much wider range of sectors than the original NIS Directive. Member states were required to transpose NIS2 into national law by October 17, 2024. If you are an essential or important entity, you are now subject to enforceable cybersecurity requirements — including mandatory incident reporting and potential personal liability for management. Matproof maps NIS2 requirements to a set of controls, policies, and incident workflows so you can demonstrate compliance to your national competent authority (NCA).
Activate NIS2 under Settings → Frameworks → NIS2. Your control set will be pre-populated and mapped to the 10 minimum security measures under Article 21.

Am I in Scope?

NIS2 distinguishes two tiers of entities:

Essential Entities (EE)

Subject to proactive supervision and higher penalties (up to €10M or 2% of global annual turnover, whichever is higher):
  • Energy (electricity, oil, gas, hydrogen, district heating and cooling)
  • Transport (air, rail, water, road)
  • Banking (credit institutions)
  • Financial market infrastructures
  • Health (hospitals, laboratories, pharma manufacturers)
  • Drinking water supply and distribution
  • Wastewater collection, disposal, and treatment
  • Digital infrastructure (DNS, TLDs, cloud computing services, data centres, CDNs, trust services, IXPs, electronic communications networks and services)
  • ICT service management (MSPs, MSSPs)
  • Public administration (central government)
  • Space

Important Entities (IE)

Subject to reactive supervision (lower penalties — €7M or 1.4% of global annual turnover, whichever is higher):
  • Postal and courier services
  • Waste management
  • Chemicals manufacturing and distribution
  • Food production and distribution
  • Manufacturing (medical devices, computer/electronic products, electrical equipment, machinery, motor vehicles, other transport equipment)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research
Size thresholds apply: medium enterprises (50+ employees or €10M+ turnover) or large enterprises (250+ employees or €50M+ turnover) in these sectors are in scope. Smaller entities may be in scope if they are sole providers of critical services. Note: medium-sized entities in Annex I sectors are generally classified as Important entities, while large entities (250+ employees) in Annex I sectors are classified as Essential entities.

The 10 NIS2 Minimum Security Measures

Article 21 requires essential and important entities to implement these 10 measures:

Management Accountability

NIS2 introduces management accountability with potential personal liability. Governing bodies:
  • Must approve cybersecurity risk management measures
  • Are liable for infringements by the entity
  • Must undergo cybersecurity training
  • The scope of personal liability depends on national transposition of the Directive.
Document management sign-off on your NIS2 risk management measures and policies. Matproof tracks policy approvals with timestamps — this is your evidence that management has approved and reviewed the program.


Incident Reporting Quick Reference

Use the Incidents module to track timeline, auto-generate draft notifications, and attach evidence to each report.

Key Differences from NIS1

If you were already compliant with the original NIS Directive:

Next Steps

  • Incidents — configuring NIS2-compliant incident classification and multi-stage reporting
  • Vendor Risk — supply chain security assessments and monitoring
  • People Module — employee training records and access management
  • Risk Management — risk assessments proportionate to your sector