Most companies first hear about NIS2 from a customer questionnaire or a nervous board member. By then the deadline is close and the work looks enormous. It doesn't have to be. NIS2 is broad, but the obligations are concrete, and once you treat them as an operating program instead of a compliance scramble, they become manageable.

This guide covers what the NIS2 directive is, who it applies to, the obligations that actually matter, how the Nordic countries are turning it into national law, and how OptiTech turns all of it into a living program of controls and evidence.

What NIS2 actually is

NIS2 is the EU's updated directive on the security of network and information systems. It replaces the original 2016 NIS directive, which most member states applied narrowly and unevenly. NIS2 widens the net, raises the bar on security measures, and puts real accountability on company leadership.

The goal is a common baseline for cyber resilience across the union. Because it's a directive and not a regulation, it doesn't apply directly. Each member state writes it into national law, which is where the Nordic detail comes in later.

Who's in scope

The biggest change in NIS2 is how many organizations it covers. The old directive touched a short list of operators. The new one pulls in whole sectors and the companies that supply them.

Essential and important entities

NIS2 sorts covered organizations into two tiers.

Essential entities operate in sectors the economy can't function without: energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, public administration, and space.

Important entities cover sectors that matter but carry slightly lower systemic risk: postal and courier services, waste management, chemicals, food, manufacturing of certain products, digital providers like online marketplaces and search engines, and research.

Both tiers face the same core obligations. The difference is supervision. Regulators watch essential entities proactively, while important entities are generally checked after something goes wrong.

Size thresholds

Sector alone doesn't decide it. NIS2 uses a size-cap rule. In general, medium and large organizations in the listed sectors are in scope: that's roughly 50 or more employees, or annual turnover above 10 million euro.

Smaller companies can still be pulled in when they play a critical role, for example a sole provider of an essential service or a link in a sensitive supply chain. If you sell into essential entities, expect their security requirements to flow down to you through contracts regardless of your own headcount.

Check scope early

Scope is the first thing to nail down, because it drives everything else. Map your sectors, your size, and your role in other companies' supply chains before you assume you're exempt. Many Nordic firms discover they're in scope indirectly, through the customers they serve.

The obligations that matter

NIS2 comes down to four things: manage your risk, secure your supply chain, report incidents on time, and make leadership own it.

Risk management measures

You have to put appropriate, proportionate technical and organizational measures in place. The directive names a baseline: risk analysis and security policies, incident handling, business continuity and backup, supply chain security, secure development and procurement, policies to test how well your measures work, cyber hygiene and training, cryptography, access control, and multi-factor authentication.

These aren't optional suggestions. They're the control set regulators will expect you to demonstrate, so each one needs an owner and evidence that it's actually running.

Supply chain security

NIS2 makes you responsible for the security of your suppliers and service providers, not just your own systems. You have to assess vendor risk and account for the security of the products and services you depend on. This is why the directive ripples far beyond the entities named directly: their obligations flow down to everyone in the chain.

Incident reporting on the clock

The reporting timeline is the obligation with the sharpest edges, and it runs in three stages:

  • Early warning within 24 hours of becoming aware of a significant incident. This is a short heads-up to the national authority, flagging that something serious is underway.
  • Incident notification within 72 hours, with an initial assessment: severity, impact, and any indicators of compromise.
  • Final report within one month, covering the full analysis, the root cause, and the mitigation measures you took.

A "significant" incident is one that causes serious operational disruption or financial loss, or affects other parties through the damage it causes. Hitting these deadlines while managing a live incident is impossible if you're inventing the process on the day. The timeline has to be built and rehearsed in advance.

Management accountability

This is the clause that changes behavior in the boardroom. Under NIS2, management bodies must approve the risk management measures and oversee their implementation. Leaders have to take relevant training, and they can be held personally liable for failures.

Compliance is no longer something the security team owns in a corner. It's a board-level duty with names attached.

How the Nordics are transposing NIS2

Because NIS2 is a directive, the exact rules land in national law. The Nordic countries are each writing their own transposition, and while the substance is shared, the detail and the supervising authorities differ.

Sweden is implementing NIS2 through a new cybersecurity act, with sector authorities and MSB playing central roles in supervision and incident handling. Finland, Denmark, and Norway are each running their own transposition, with national regulators named per sector and their own registration and reporting channels.

The practical takeaway: you'll register with a national authority, report incidents through national channels, and answer to a national regulator. If you operate across the Nordics, you may deal with several at once, which makes a single, consistent program far easier to run than country-by-country spreadsheets.

What the penalties look like

NIS2 borrows GDPR's approach to enforcement. Essential entities face fines up to 10 million euro or 2 percent of global annual turnover, whichever is higher. Important entities face up to 7 million euro or 1.4 percent.

Beyond fines, regulators can issue binding instructions, order audits, and in serious cases suspend certifications or temporarily bar individuals from management roles. Combined with personal liability for leadership, the incentives point in one direction: build the program and keep the evidence.

Turn NIS2 into an operational program

NIS2 reads like a list of demands. OptiTech turns it into a working system you can run and prove.

The directive's risk management measures map to a control framework in the OptiTech Console. Each measure becomes a control with an owner, a schedule, and the evidence that shows it's operating. Instead of a policy nobody reads, you get living controls you can point an auditor or a regulator to.

Incident reporting becomes a workflow with the 24-hour, 72-hour, and one-month clocks visible from the moment you log an incident. The timeline and every decision are recorded as they happen, so the final report writes itself from the trail you already captured.

Supply chain security lives as a vendor register, where each supplier links to their risk assessment and the controls that depend on them. Management accountability becomes reviews and approvals captured as evidence, so you can show leadership signed off. And because your data residency stays in the EU, in Stockholm and Frankfurt, one of the questions regulators and customers ask most is already answered.

Finally, the same program feeds your trust center, so buyers can see your posture without emailing your team. The work you do for NIS2 starts answering security reviews on its own.

Getting started

You don't have to solve everything at once. A realistic first pass looks like this:

  1. Confirm your scope. Check your sector, size, and supply chain role, and identify your national authority.
  2. Stand up your control framework from the NIS2 risk management measures, with an owner for each.
  3. Build the incident workflow with the 24h, 72h, and one-month clocks before you need it.
  4. Map your suppliers and connect their risk assessments to the controls that depend on them.
  5. Publish to a trust center so the work starts winning deals.

NIS2 rewards companies that treat security as an operating habit rather than a one-time filing. Build the controls once, keep the evidence current, and both your regulator and your buyers get the same clear answer.

Ready to turn NIS2 into a living program? Book a demo and see how OptiTech connects your controls, evidence, and reporting.