Introduction
NIS2 is creating understandable concern among founders and operators. The challenge is that many businesses jump straight into solutions. The first step is understanding obligations. Not buying tooling.
Many companies spend money solving NIS2 before determining whether NIS2 applies. Vendors are happy to sell NIS2 readiness; lawyers are happy to advise on it; engineering teams are happy to build for it. None of that work matters if the regulation does not apply to your organisation in the first place.
This framework helps you decide whether NIS2 is your problem, which obligations actually attach to you, and the order in which the work should happen.
What it solves
What the right NIS2 work delivers
-
Legal clarity
Knowing whether NIS2 applies, and as what kind of entity, is the first deliverable. Without that clarity, every other decision is guesswork.
-
Defensible posture in incidents
When something happens, the question regulators ask is whether your controls were reasonable for your obligations. Documented, applied measures that match the obligation are far cheaper than retroactive justification.
-
Customer trust at the buying moment
Many B2B customers in essential or important sectors will not buy from suppliers without a defensible cybersecurity posture. NIS2 readiness, where required, is now part of the procurement conversation.
-
Smaller, smarter spending
Once obligations are clear, most organisations spend less on NIS2 than they expected. Vendors sell platforms; obligations require evidence. The two often do not overlap.
-
A reusable foundation
The risk-management, incident-handling and supply-chain measures NIS2 requires also serve ISO 27001, SOC 2, GDPR security expectations and basic operational hygiene. Done once, they pay back across many compliance conversations.
What it does not solve
What NIS2 readiness will not fix
-
Missing security basics
NIS2 assumes a baseline of security culture, patching, monitoring, access management, backups. Without that baseline, NIS2 documents are policy without practice. Build the basics first; NIS2 maps onto them.
-
A product nobody buys
Compliance is a hygiene factor, not a product. A perfectly NIS2-compliant company without customers is still a company without customers.
-
Bad incident processes
NIS2 mandates rapid incident notification. Without a working incident process, the documentation is meaningless and the team will miss the regulatory window.
-
Unclear vendor responsibility
Supply-chain risk is a major NIS2 theme. If your vendor map is incomplete, no amount of internal control work substitutes for it. Map the vendors first; the obligations follow.
-
Cybersecurity theatre
Spending heavily on tooling without changing behaviour produces a defensible-looking posture and a real-world failure. NIS2 evaluates outcomes, not invoices.
Decision tree
Six questions before you act
Run the obligation through these questions. Most companies discover that NIS2 either does not apply at all or applies more narrowly than they assumed.
- Question 01
Does NIS2 apply to the organisation?
No → Stop. Most organisations are not in scope. Confirm with a specialised lawyer or advisor before spending on tooling or controls.Yes → Identify the entity type, essential or important, and the relevant sector. The obligations differ meaningfully between them. - Question 02
Which services are provided?
No → Map services to sector definitions. Many companies in 'digital infrastructure' or 'managed services' assume they are in scope when only some of their services qualify.Yes → Document the in-scope services explicitly. Out-of-scope services do not need to be brought up to NIS2 standards. - Question 03
Which risks exist?
No → Conduct a basic risk assessment. NIS2 expects risk-management measures proportionate to the organisation's exposure, not maximum measures by default.Yes → Document risks and likelihood. Proportionality is the standard; documented risk justifies the measures you do and do not implement. - Question 04
What evidence must be maintained?
No → Identify required evidence: policies, incident logs, training records, supplier assessments, technical measures, board engagement. Without evidence, the controls do not exist for a regulator.Yes → Confirm the evidence is captured automatically where possible and reviewed at known intervals. Stale evidence fails audits even when controls work. - Question 05
What controls are actually required?
No → Start with NIS2's ten minimum measures: risk policies, incident handling, business continuity, supply chain security, secure development, vulnerability handling, training, cryptography, access control, asset management. Most of these overlap with hygiene already in place.Yes → Confirm each measure is operational, not aspirational. Operational means documented, applied and evidenced. - Question 06
What happens if we delay action?
No → Quantify it. Some NIS2 obligations carry deadlines, board accountability and personal liability for management. Others have softer enforcement timelines.Yes → Confirm timing with a specialist. Delay against a personal-liability deadline is different from delay against a documentation cleanup.
Common mistakes
Five common mistakes founders make
- 01
Assuming NIS2 applies
NIS2 scope is broader than NIS1 but still bounded by sector, size and service. Many companies assume they are in scope when they are not, and spend money on obligations that do not attach to them. A short conversation with a specialised lawyer at the start saves quarters of wasted work.
- 02
Buying tooling too early
GRC platforms, SIEM tools, vulnerability scanners, all become useful at a specific stage. Buying them before obligations are clear means paying for capabilities that may not be required, and that the team cannot operate effectively yet.
- 03
Solving hypothetical requirements
NIS2 expects proportionate measures. Implementing the maximum interpretation of every clause produces a defensible-looking posture and a permanently overbuilt programme. Match controls to documented risk; do not engineer for the worst-case interpretation.
- 04
Ignoring documentation
Controls that exist but cannot be evidenced do not exist for a regulator. NIS2 is heavy on documentation: risk assessments, incident records, training logs, supplier reviews, board engagement. Build the documentation alongside the controls, not afterwards.
- 05
Confusing legal advice with implementation
A lawyer can tell you what NIS2 requires; they cannot ship the implementation. Both roles matter, and conflating them produces neither. Use specialised legal counsel for scope and obligations; use specialised engineering and operations for the controls and the evidence.
Alternatives
Patterns for proportionate NIS2 work
Four patterns that get most of the readiness benefit without overbuilding.
-
Scope first, control second
Settle the applicability question, identify entity type and in-scope services, document the answer. Almost every other decision becomes easier, or unnecessary, once scope is clear.
-
Risk-led implementation
Conduct a lightweight risk assessment, link each control to a documented risk, implement controls in priority order. Avoids both the 'we did everything' overbuild and the 'we missed the obvious' underbuild.
-
Reuse existing hygiene
Most NIS2 minimum measures map onto controls a competent team already runs: patching, backups, access management, basic monitoring. Document what already exists; build only what is genuinely missing.
-
Annual external review
An external advisor for one or two days per year catches drift, identifies the next required step and produces evidence of ongoing attention, without permanent compliance staff.
Ronald's rule of thumb
Understand the obligation before implementing the solution.
NIS2 is a regulation, not a product. Vendors sell solutions; the regulation requires obligations. The two often look similar from the outside and differ sharply in practice. Get clear on the obligation, entity, sector, services, risk, before buying tooling, hiring a CISO or signing a vendor contract. The cheapest NIS2 work is the work you do not need to do.
, Ronald · YourStartup.Expert
Summary
Summary
Most NIS2 conversations should start with the applicability question, not the implementation question. The six questions above sort that out: entity type, services, risks, evidence, controls and timing. Many organisations discover that NIS2 either does not apply, or applies more narrowly than vendors implied, and the right work programme shrinks accordingly.
When NIS2 does apply, scope it carefully, document the risk basis, reuse existing hygiene where possible and build the documentation alongside the controls. Done in that order, NIS2 readiness becomes a foundation for other compliance work rather than a permanent drag on engineering capacity.
Common questions
NIS2, answered.
The questions founders ask before they start an NIS2 programme.
- What is NIS2?
- The EU's updated Network and Information Security directive, effective from late 2024 and being transposed into national law across member states. It widens the scope of regulated entities, raises cybersecurity expectations and introduces personal liability for senior management. NIS2 covers risk management, incident handling, business continuity, supply chain security, secure development, training, cryptography, access control and asset management, proportionate to the organisation's exposure.
- Does NIS2 apply to startups?
- Sometimes, and most often partially. NIS2 scope depends on sector (essential or important entity categories), size and the specific services provided. Many startups in 'digital infrastructure', managed services, healthcare or finance fall under some obligations; many more assume they do and discover otherwise after a proper scoping conversation. A specialised lawyer or advisor can settle the question in a few hours and avoid quarters of misdirected work.
- How do I know if NIS2 applies?
- Three filters, in order. First, sector: does the organisation operate in a NIS2-covered sector? Second, size: does it cross the relevant employee or revenue thresholds (or fall under exceptions for critical infrastructure regardless of size)? Third, service: which specific services are in scope, and which are not? Confirm in writing with a specialised lawyer before allocating budget. Many in-scope companies discover that only part of their offering qualifies.
- What happens if I ignore NIS2?
- If NIS2 applies and you ignore it, the regulation provides for significant administrative fines (up to 2% of global annual turnover for essential entities), management liability and reputational risk. Enforcement timing varies by member state, but the trend is toward active supervision rather than reactive enforcement. The cost of ignoring NIS2 is asymmetric, most organisations never get audited, the ones that do face large consequences, and the cost of complying proportionately is moderate.
- What should I do first?
- Settle scope. Ask a specialised lawyer or advisor whether NIS2 applies and as what kind of entity. If it does, identify the in-scope services and conduct a lightweight risk assessment to set the proportionality basis. Only then implement controls, prioritising the ones that map onto risks you have already named. Tooling, certifications and large engineering programmes come later, after the obligation is understood and the existing hygiene is documented.