Network and Information Security Directive.
Does NIS2 apply to your company? Four questions, an indication in two minutes — against the same sector and size tests as our RegCheck assessments.
What NIS2 requires.
NIS2 dramatically expands the scope of EU cybersecurity regulation. It applies to essential and important entities across 18 sectors — and critically, it includes supply chain security obligations.
Companies must implement risk management measures, report incidents within tight timelines, and ensure their suppliers meet security requirements. Management bodies face personal liability for non-compliance.
Many companies don't realise they're in scope. NIS2 catches organisations that supply to essential entities, even if they themselves wouldn't traditionally be classified as critical infrastructure.
Why it's hard.
Scope uncertainty
The directive catches companies indirectly through supply chain obligations — many don't know they're affected.
Technical and organisational measures
Requirements span incident handling, business continuity, supply chain security and encryption.
Incident reporting timelines
24-hour early warning, 72-hour notification, 1-month final report — tight deadlines with real consequences.
Management liability
Board members and senior management face personal liability for ensuring compliance.
How Regweaver helps.
Scope assessment via RegCheck
Determine whether NIS2 applies to you — directly or through supply chain obligations.
Compliance framework
Structured implementation of required security measures with gap analysis and action tracking.
Supplier security management
Assess and monitor supplier security posture with standardised questionnaires and scoring.
Incident readiness
Pre-configured reporting workflows that meet NIS2 timeline requirements.
Who's affected.
You may not be in scope — but your customers are.
Companies in scope
Regulation impacts organisations — but execution happens across teams.
Teams responsible for compliance
Not sure if NIS2 applies to you?
Take the 2-minute check — four questions, an indication right away, against the same sector and size tests as our RegCheck assessments.