NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity directive that requires "essential" and "important" entities across 18 sectors to manage cyber risk, secure their supply chains and report significant incidents, with personal accountability for management. It replaced the original NIS directive and dramatically expanded both who is covered and what non-compliance costs. Sector guidance and technical resources are published by ENISA.
Key facts:
- NIS2 covers organizations in sectors like energy, transport, health, digital infrastructure, manufacturing, food and public administration, generally from 50 employees or EUR 10M turnover, plus smaller entities in critical roles.
- Incident reporting is deadline-driven: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month of a significant incident.
- Management bodies are personally accountable for approving and overseeing cyber risk measures. Fines can reach EUR 10 million or 2% of global turnover for essential entities (verify current figures against official sources).
- The directive works through national law: each member state transposes it, so exact obligations and supervision arrive via national legislation.
Who is covered
Size matters but is not the whole rule: mid-sized and large entities in listed sectors are covered, and some smaller entities qualify because of their critical role. If your customers are covered, NIS2 also reaches you indirectly through their supply chain security obligations, which is how the directive cascades far beyond its formal scope.
The core requirements
NIS2's Article 21 requires risk management measures including: policies on risk analysis and information system security, incident handling, business continuity and crisis management, supply chain security, secure development and vulnerability handling, cyber hygiene and training, cryptography, access control and asset management, and multi-factor authentication. In practice, most successful attacks on covered entities start the same way everywhere: a phishing email, business email compromise or other social engineering reaching an employee. Email protection, detection and reporting capability is therefore foundational to several Article 21 measures, without being sufficient for any of them alone.
Where email security fits, honestly
No product makes an organization NIS2 compliant. Compliance is organizational: governance, processes, documentation and technology together. What an email security layer contributes:
This page is general guidance, not legal advice. Consult qualified counsel for your obligations under national NIS2 legislation.
Inside the incident reporting chain
NIS2's deadlines make incident reporting a race that starts before you know it has started: the 24-hour early warning requires knowing an incident happened, what it touched and whether it is likely significant, fast. For email-borne incidents, which is where most begin, that first mile is exactly what Sentaro provides: the detection that triggers the process, and the who/what/when/scope that the early warning and the 72-hour notification must contain. The organization owns the assessment and the submission; Sentaro makes sure the clock starts with evidence instead of an empty page.
Getting started
A pragmatic order: establish whether you are covered (sector, size, criticality, or customers who are covered), assign management ownership, map current measures against Article 21, close the largest attack-surface gaps first (email protection, MFA, backups, incident process), and set up the incident reporting workflow with its deadlines before you need it. For financial entities, note that DORA generally takes precedence where the two overlap.