Definition
NIS2 is a European directive on network and information security. It requires organisations in designated sectors to take risk-management measures, to report serious incidents, and to attend to the security of their supply chain. A directive works through national law: each member state transposes it, and the precise scope and deadlines follow from that national law.
What it means for the calculation
For a machine shop this touches cost in two places. First as an obligation of its own, when the shop falls under a designated sector itself: that means measures, records and a reporting duty, and those cost hours and money. Second, and more often, through the customer: a client who falls under it has to look at its own suppliers too, and therefore passes requirements down in contracts and questionnaires. Filling in those questionnaires and making measures demonstrable is preparation work that belongs in the cost of the customer relationship, not in the per-piece time.
Where this comes up
In the purchasing conditions and supplier questionnaires of larger clients, and in the national law that transposes the directive. Whether a shop falls under it depends on sector and size under that national law, which is a question for a lawyer, not for a software supplier.
Common mistakes
Assuming the directive only concerns IT companies; the designated sectors are broader and include parts of manufacturing. Also assuming a supplier outside the scope will not notice it: requirements often arrive through the supply chain rather than through the law.
For a machine shop this touches cost in two places. First as an obligation of its own, when the shop falls under a designated sector itself: that means measures, records and a reporting duty, and those cost hours and money. Second, and more often, through the customer: a client who falls under it has to look at its own suppliers too, and therefore passes requirements down in contracts and questionnaires. Filling in those questionnaires and making measures demonstrable is preparation work that belongs in the cost of the customer relationship, not in the per-piece time.
Read the researchFrequently asked questions
Does my company fall under it?
That depends on sector and size under the national law that transposes the directive; have that checked legally.
What is the difference with the EU AI Act?
NIS2 is about cybersecurity and incident reporting; the EU AI Act is about the use of AI systems.
Why am I getting questionnaires about it from a customer?
Because clients who fall under it themselves also have to look at their suppliers' security.