Quick answer
NIS 2 is the EU directive that applies essential cybersecurity protections to digital infrastructure and critical services: energy, transport, health, water, digital providers, manufacturing of critical products, and more, 18 sectors in total, implemented in Sweden through the Cybersecurity Act. It classifies organizations as essential or important entities, requires risk management measures and incident reporting, and puts personal responsibility on management. Sanctions reach 10 million EUR or 2 percent of global turnover. More than 10,000 Swedish companies are affected, many without knowing it.
Scope reaches further than the sector list
You can be in scope three ways:
- Directly: your activity is in an annex sector and you meet the size thresholds (generally 50+ employees or 10M+ EUR turnover, with exceptions where size doesn't matter).
- Through the supply chain: in-scope entities must manage supplier security, so their requirements flow into your contracts even if you're not listed. This is how most SMBs meet NIS 2 in practice: a customer's questionnaire arrives.
- As digital infrastructure: DNS, cloud, data centers, and managed service providers are in scope with particular attention, MSPs very much included.
What compliance requires
The measures are proportionate but concrete: risk analysis and security policies, incident handling, business continuity and backups, supply chain security, secure development and vulnerability handling, effectiveness evaluation, basic hygiene (MFA, access control) and training, cryptography policy, and HR security. Incident reporting runs on tight clocks: early warning within 24 hours, notification within 72 hours, final report within a month, to MSB in Sweden's case.
Management duties are explicit: boards must approve the risk measures, oversee implementation, and undergo training, and members carry personal liability for neglect. That's why NIS 2 lands in boardrooms in a way its predecessor never did.
The practical first steps
Confirm scope (a free scoping test settles it in minutes), classify your entity type, run a gap analysis against the measures, and get the incident flow rehearsed before you need it. For the full operational picture, see how OptiTech implements NIS 2.

Get a personalized walkthrough of automated compliance for your team. No commitment required.