Advisory Topic

NIS2 Directive Readiness

NIS2 — Directive (EU) 2022/2555 — is the European Union's upgraded cybersecurity law. It reaches further than its predecessor, places accountability directly on management bodies, and carries material penalties. vCyberBoard Advisor helps boards meet NIS2 not as a paperwork exercise but as a governance posture.

Who is in scope

NIS2 covers essential and important entities across energy, transport, health, digital infrastructure, public administration and space — and now reaches many supply-chain and managed-service providers. We help the board determine whether and how the organisation is in scope, including across subsidiaries and the supply chain.

Governance and accountability obligations

Management bodies must approve cybersecurity risk-management measures, oversee their implementation and can be held personally liable for failures. We help boards evidence approval, oversight and training — the governance records a regulator will ask for.

Risk management measures

NIS2 requires measures around incident handling, business continuity, supply-chain security, secure development, access control and training. We map these to your existing controls and to ISO/IEC 27001 so a single programme satisfies multiple obligations.

Incident reporting timelines

Significant incidents trigger early warning (24 hours), formal notification (72 hours) and final report timelines. We help design the reporting chain, roles and templates so the board and management can meet those deadlines under pressure.

Your NIS2 Advisor

Scope determination, governance evidence, control gap assessments, incident-readiness planning and board briefings — independent counsel aligned to DORA and the EU AI Act where obligations overlap.