NIS2 in 3 sentences
NIS2 is the EU cybersecurity law. It requires essential and important entities to prove control over their ICT supply chain. Managed service providers face personal management bans and fines up to EUR 10 million or 2 percent of turnover.
- NIS2 scope: Essential entities include managed service providers and managed security service providers under Annex I sector 9
- Management liability: Article 20 makes management bodies personally liable for cybersecurity risk management failures
- The fix: Own your infrastructure. Remove external provider dependencies from your critical ICT supply chain
Note: This is a simplified checklist. Refer to the official NIS2 Directive (EU) 2022/2555 for full requirements. Consult legal counsel for compliance advice.
NIS2 cybersecurity checklist
Check each item that applies to your ICT supply chain. NIS2 requires documented control over critical systems and supply chain security.
NIS2 says your CEO and board are personally on the hook for cybersecurity. If you fail, regulators can ban your CEO from running any company. Your name goes on the public notice.
NIS2 says you must control every ICT provider you use. If you rent your systems from a big cloud company, they will not change their contract for you. That is a compliance gap you cannot close.
NIS2 fines go up to EUR 10 million or 2% of your global turnover. Your cloud provider is the weak link. Their failure is your fine.
If you are an MSSP or managed service provider under NIS2 Annex I sector 9, this applies to you today. If you serve regulated clients, DORA Article 28 and Article 30 contractual flow-down catches you too. Check your DORA exposure.
Worried about NIS2, DORA, AI Act or GDPR?
These regulations ask the same question. Who controls the systems you depend on. Our sovereign platform gives you the answer. You.
No sales pressure. A clear look at your numbers, your dependencies, and your options.