NIS2 hits the mid-market: what to do now
Many companies are covered by a cyber-security directive for the first time — often without knowing it. A clear five-step roadmap out of the uncertainty.
With NIS2, the EU drastically widens the circle of regulated companies. Suddenly it's not only large corporations and classic critical-infrastructure operators who are obliged, but also many mid-sized suppliers, service providers and manufacturers. The uncomfortable truth: most of those affected don't yet know they're meant.
Am I even affected?
What matters is sector, company size and turnover. If you operate in one of the “important” or “essential” sectors and exceed the thresholds, you're obliged — whether or not the word “critical infrastructure” was ever mentioned. As a supplier to an affected company you're drawn in via supply-chain requirements too.
NIS2 is not a pure IT task. The directive explicitly holds management accountable.
The five steps out of uncertainty
- Clarify exposure: assess sector, size and supply-chain links in a structured way — not by gut feeling.
- Gap analysis: mirror the current state against the requirements (risk management, reporting paths, continuity).
- Prioritise measures: start with the gaps that carry the biggest risk and the shortest deadline.
- Build continuity provisioning: document reporting processes, emergency plans and responsibilities — and rehearse them.
- Secure evidence: document everything in a fully traceable way so you can prove it to authorities and customers.
Waiting is the most expensive option
Experience shows: organisations that start early and structured need less external help and avoid last-minute panic. The first step is unspectacular but decisive — clarity about your own exposure. That's exactly what our free self-check is for.
Related from our offering
Keep reading
Emergency or crisis? Why the distinction decides your response
Server-room fire at 3 a.m.: emergency or crisis? Separating the two terms cleanly means alerting the right people, escalating in time — and preventing a manageable incident from becoming an existential threat.
5 common mistakes in emergency planning — and how to avoid them
Perfect on paper, useless when it counts: why emergency plans fail on vague instructions, missing upkeep, IT tunnel vision, untrained roles and slow alerting — with practical examples and concrete remedies.