Under NIS2, an organisation's sector, size and role can determine whether cybersecurity risk-management and reporting duties apply
Whether NIS2 applies to an organisation turns on what sector it is in, how big it is, and what role it plays.
It is not a general obligation and it is broader than its predecessor. The practical difficulty is that many organisations do not know whether they are in scope, and being a supplier to somebody who is can bring obligations indirectly. Note also that it does not apply in the UK, where the NCSC's Cyber Assessment Framework and separate legislation govern instead.
Checked against the primary source.
More on Regulation and law
- Regulatory scope is a security architecture questionThe rope follows the wire
- Incident reporting deadlines change response prioritiesThe clock starts with the incident
- DORA makes ICT third-party resilience a contractual and oversight responsibility for regulated financial entitiesThe work moves, the answering stays
- Breach notification and incident notification are different testsTwo holes, two different shapes
- Legal privilege does not make incident facts disappearIt seals the advice, not the facts
- Regulation can make suppliers part of your compliance systemTheir controls, on your sheet
