NIS2

NIS2 is the European directive that sets cybersecurity requirements for organisations in designated sectors, including parts of manufacturing.

Definition

NIS2 is a European directive on network and information security. It requires organisations in designated sectors to take risk-management measures, to report serious incidents, and to attend to the security of their supply chain. A directive works through national law: each member state transposes it, and the precise scope and deadlines follow from that national law.

What it means for the calculation

For a machine shop this touches cost in two places. First as an obligation of its own, when the shop falls under a designated sector itself: that means measures, records and a reporting duty, and those cost hours and money. Second, and more often, through the customer: a client who falls under it has to look at its own suppliers too, and therefore passes requirements down in contracts and questionnaires. Filling in those questionnaires and making measures demonstrable is preparation work that belongs in the cost of the customer relationship, not in the per-piece time.

Where this comes up

In the purchasing conditions and supplier questionnaires of larger clients, and in the national law that transposes the directive. Whether a shop falls under it depends on sector and size under that national law, which is a question for a lawyer, not for a software supplier.

Common mistakes

Assuming the directive only concerns IT companies; the designated sectors are broader and include parts of manufacturing. Also assuming a supplier outside the scope will not notice it: requirements often arrive through the supply chain rather than through the law.

What it means for your calculation · most relevant in How Blake works

For a machine shop this touches cost in two places. First as an obligation of its own, when the shop falls under a designated sector itself: that means measures, records and a reporting duty, and those cost hours and money. Second, and more often, through the customer: a client who falls under it has to look at its own suppliers too, and therefore passes requirements down in contracts and questionnaires. Filling in those questionnaires and making measures demonstrable is preparation work that belongs in the cost of the customer relationship, not in the per-piece time.

Read the research

Frequently asked questions

Does my company fall under it?

That depends on sector and size under the national law that transposes the directive; have that checked legally.

What is the difference with the EU AI Act?

NIS2 is about cybersecurity and incident reporting; the EU AI Act is about the use of AI systems.

Why am I getting questionnaires about it from a customer?

Because clients who fall under it themselves also have to look at their suppliers' security.