Legalifi Logo
Back to blog
CybersecurityComplianceLegal Insights
June 26, 2026·9 min read

NIS2 Directive: Cybersecurity Obligations, Incident Reporting and Corporate Liability

A comprehensive overview of the NIS2 Directive, covering essential and important entities, cybersecurity risk management, management liability, incident reporting and its impact on non-EU suppliers.

Alperen Turhal

Alperen Turhal

Tech Lawyer

Abstract digital security matrix with encrypted connections, access-control checkpoints and incident alerts representing NIS2 cybersecurity governance and regulatory compliance.

What Is the NIS2 Directive?

The NIS2 Directive, formally adopted on 14 December 2022 as Directive (EU) 2022/2555, establishes a significantly expanded cybersecurity framework for organisations operating within the European Union and for certain businesses connected to the EU market.

Member States were required to transpose the Directive into their national legislation by 17 October 2024.

NIS2 substantially expands the range of sectors subject to cybersecurity requirements, introduces strict incident notification obligations and places greater responsibility on the management bodies of regulated organisations.

One of the most important features of NIS2 is the classification of organisations into two main categories:

  • Essential Entities
  • Important Entities

This distinction affects how organisations are supervised, the administrative sanctions they may face and the intensity of regulatory oversight.

The classification is generally based on the size of the organisation and the sector in which it operates.

As a general principle, micro and small enterprises below the relevant employee and financial thresholds may fall outside the Directive's scope. However, NIS2 also contains important exceptions, particularly where an organisation performs a critical function or provides certain essential services.

2. Which Organisations Are Essential Entities?

Essential Entities generally include larger organisations operating in sectors considered critical to the functioning of society and the economy.

Relevant sectors include:

  • Energy, including electricity, gas and oil
  • Drinking water and wastewater management
  • Healthcare
  • Hospitals and medical laboratories
  • Pharmaceutical manufacturing and research
  • Air, maritime, rail and road transport
  • Banking
  • Financial market infrastructures
  • Digital infrastructure

Digital infrastructure is particularly important under NIS2.

Organisations such as cloud computing service providers, data centres, Domain Name System providers, Content Delivery Networks and trust service providers may fall within the scope of Essential Entities depending on the applicable conditions.

Because these organisations support critical economic and social infrastructure, they are subject to a more intensive supervisory regime.

3. Which Organisations Are Important Entities?

Important Entities generally include medium-sized and large organisations operating in sectors that fall within the scope of NIS2 but are not classified under the stricter Essential Entity framework.

This category may include:

  • Digital service providers
  • Online marketplaces
  • Search engines
  • Social networking platforms
  • Postal and courier services
  • Waste management businesses
  • Research organisations

The manufacturing sector also represents an important part of this category.

Relevant activities may include the manufacturing of:

  • Computers
  • Electronic products
  • Optical equipment
  • Electrical equipment
  • Medical devices
  • Chemicals
  • Food products

The distinction between Essential and Important Entities does not mean that Important Entities are subject to insignificant requirements.

Both categories must comply with core cybersecurity risk management and incident notification obligations.

4. Differences in Supervision and Sanctions

The principal difference between Essential Entities and Important Entities relates to regulatory supervision and enforcement.

Both categories are required to implement the cybersecurity risk management measures set out in Article 21 and comply with the incident notification requirements under Article 23.

However, the supervisory approach differs.

Essential Entities are generally subject to a more proactive supervisory model.

Competent authorities may conduct inspections, audits and other supervisory activities even where there has been no prior complaint or reported breach.

Important Entities are generally subject to a more reactive supervisory model, where regulatory intervention is more likely to follow evidence, notification or indications of non-compliance.

The administrative penalty framework also differs between the two categories.

For Essential Entities, administrative fines may reach at least:

  • EUR 10 million, or
  • 2% of the organisation's total worldwide annual turnover from the preceding financial year,

depending on the applicable rules and whichever threshold results in the higher amount.

For Important Entities, administrative fines may reach at least:

  • EUR 7 million, or
  • 1.4% of total worldwide annual turnover,

subject to the applicable national implementation and enforcement framework.

5. Corporate Governance and Management Liability

Article 20 of the NIS2 Directive places cybersecurity directly within the responsibilities of an organisation's management body.

Management bodies are required to approve the cybersecurity risk management measures adopted by the organisation and oversee their implementation.

Cybersecurity therefore becomes a corporate governance issue rather than a responsibility that can simply be delegated entirely to IT or security departments.

Senior executives are also expected to develop sufficient knowledge of cybersecurity risks to understand their potential impact on the organisation and its services.

Appropriate cybersecurity training for management is therefore an important component of the NIS2 governance framework.

The Directive also significantly increases accountability at management level.

A lack of technical expertise is not, by itself, sufficient to remove management responsibility for cybersecurity governance.

Where serious or repeated failures occur, competent authorities may take measures affecting individuals holding managerial responsibilities.

Depending on the relevant national implementation and enforcement procedure, this may include temporary restrictions on performing management functions until identified compliance failures have been remedied.

The result is a significant shift in corporate responsibility.

Cybersecurity under NIS2 is no longer merely a technical function. It is a board-level legal and governance obligation.

6. Cybersecurity Risk Management Measures and Technical Requirements

Article 21 forms the technical core of the NIS2 Directive.

Essential and Important Entities are required to implement appropriate and proportionate technical, operational and organisational measures to manage risks affecting the security of their network and information systems.

The framework is based on the concept of operational resilience.

The objective is not only to prevent cyberattacks, but also to ensure that organisations can continue providing critical services during an incident and recover effectively afterwards.

1. Risk Analysis and Security Policies

Organisations should identify critical assets and establish risk-based policies governing the security of information systems.

The organisation must understand which systems, information and services are most critical and what risks could affect them.

2. Incident Handling

Organisations need procedures capable of detecting, analysing, containing and responding to security incidents.

Incident response should not begin only after a major breach has occurred.

Appropriate monitoring and response capabilities should be established in advance.

3. Business Continuity and Crisis Management

Organisations should prepare plans for maintaining and restoring operations during serious incidents such as ransomware attacks or critical infrastructure failures.

Relevant measures can include:

  • Backup policies
  • Disaster recovery procedures
  • Off-network backups
  • Recovery testing
  • Crisis management procedures

Business continuity measures should be tested regularly rather than remaining purely theoretical documentation.

4. Supply Chain Security

NIS2 also places strong emphasis on supply chain cybersecurity.

An organisation's security risks are not limited to its own internal systems.

Software vendors, managed service providers, consultants, cloud providers, data centres and other third parties can introduce significant vulnerabilities.

Organisations should therefore assess cybersecurity risks throughout their supply chains.

5. Security in Development and Procurement

Cybersecurity should be considered when information systems are designed, developed, acquired or maintained.

Security should therefore be integrated into development and procurement processes rather than added only after deployment.

6. Vulnerability Handling and Disclosure

Organisations should establish processes for identifying, assessing and addressing vulnerabilities.

This can include continuous monitoring, vulnerability scanning and timely installation of security patches.

7. Evaluation of Security Measures

Cybersecurity measures should be regularly tested to determine whether they are operating effectively.

Testing methods may include:

  • Automated security assessments
  • Penetration testing
  • Internal reviews
  • External audits

The organisation should be able to demonstrate not only that controls exist, but also that they work in practice.

8. Cryptography and Encryption

Appropriate cryptographic and encryption technologies should be used to protect sensitive information.

This is particularly relevant for data:

  • At rest
  • In transit

Encryption policies should reflect the sensitivity of the information and the risks associated with unauthorised access.

9. Human Resources Security and Access Control

Access to systems and information should be managed throughout the employee lifecycle.

Organisations should apply the principle of least privilege, ensuring that users have access only to the information and systems necessary for their roles.

Access control should be integrated with effective identity and asset management practices.

10. Multi-Factor Authentication and Secure Communications

Multi-factor authentication is an important component of the NIS2 security framework, particularly for privileged or sensitive accounts.

Secure communication mechanisms and appropriate authentication controls should be implemented for both internal and external access.

7. Incident Reporting Process and Timeline

Article 23 establishes a structured notification process for significant cybersecurity incidents.

The objective is to accelerate regulatory response, improve coordination between Member States and support collective cybersecurity awareness across the European Union.

The reporting structure is commonly associated with a staged notification model involving an early warning, a more detailed incident notification and a final report.

24-Hour Early Warning

Once an organisation becomes aware of a significant incident, an early warning must generally be submitted within 24 hours to the relevant national CSIRT or competent authority.

The purpose of this first notification is to communicate that a potentially significant cybersecurity event has occurred.

The initial notification may include information regarding:

  • The nature of the incident
  • Affected services
  • Initial response measures
  • The team managing the incident
  • Whether malicious activity is suspected
  • Potential cross-border impact

At this stage, organisations may not yet have complete information.

The main objective is rapid notification.

72-Hour Incident Notification

A more detailed notification is generally required within 72 hours.

At this stage, the organisation should provide updated information concerning the incident, including its severity and potential impact.

Relevant information may include:

  • Systems affected
  • Data compromised or encrypted
  • Duration of service interruption
  • Operational consequences
  • Indicators of compromise
  • Initial technical findings

Final Report

A final report is generally required within one month after the relevant incident notification process.

The report should provide a comprehensive assessment of the incident.

This may include:

  • Detailed description of the incident
  • Severity and impact
  • Root cause analysis
  • Type of threat
  • Mitigation measures implemented
  • Structural improvements planned
  • Cross-border consequences where applicable

This staged approach means that organisations need pre-established reporting procedures before an incident occurs.

A company that starts determining its internal responsibilities only after a serious cyberattack may struggle to meet the required deadlines.

8. How Does NIS2 Affect Companies Outside the European Union?

The impact of NIS2 is not limited to companies physically established within the European Union.

European Essential and Important Entities are required to manage cybersecurity risks associated with their suppliers and service providers.

This creates significant indirect effects for companies located outside the EU.

For example, European organisations may need to assess the cybersecurity practices of:

  • Software suppliers
  • Managed service providers
  • Managed security service providers
  • Cloud infrastructure providers
  • Data centre partners
  • Other technology vendors

This is particularly relevant for countries such as Türkiye, which maintain close commercial and technological relationships with the European Union.

A Türkiye-based company supplying software, technology, digital services or other critical services to an EU-based Essential or Important Entity may therefore face contractual cybersecurity requirements derived from NIS2.

Even where the Turkish supplier is not itself the direct addressee of the Directive, its European customer may require compliance with specific security standards.

If a vulnerability in a supplier's systems contributes to a cybersecurity incident affecting an EU organisation, the European organisation may face regulatory consequences.

Depending on the commercial contract between the parties, the European organisation may subsequently seek compensation or rely on contractual indemnity provisions against the supplier.

For Turkish technology companies serving European customers, NIS2 should therefore also be considered from a contractual, operational and commercial perspective.

9. Conclusion

The NIS2 Directive represents a significant change in the European cybersecurity regulatory environment.

Its impact extends beyond traditional IT security requirements.

Cybersecurity risk management, supply chain security, incident response, management accountability and operational resilience increasingly form part of the same regulatory framework.

Organisations within scope must therefore coordinate legal, technical, operational and management functions.

The Directive is also relevant for companies outside the European Union that provide technology, software, infrastructure or critical services to regulated European organisations.

For Türkiye-based businesses working with EU customers, NIS2-related expectations may increasingly become part of supplier assessments, contractual requirements and commercial relationships.

Considering both the technical requirements and the potentially significant consequences of non-compliance, organisations should evaluate their cybersecurity governance and operational processes before a serious incident occurs.

Legalifi supports organisations seeking to understand and manage cybersecurity and regulatory compliance requirements through multidisciplinary legal and technology-focused compliance projects.

Alperen Turhal

Written by

Alperen Turhal

Tech Lawyer

He graduated from the Ankara University Faculty of Law. He then completed his mandatory legal internship at a corporate law firm in 2025 and obtained his attorney’s license. Within Karakod, he actively works on the Legalifi RegTech software, focusing particularly on intellectual property law (trademarks), personal data protection, and AI law.