NIS2: What the EU Cybersecurity Directive Means for Companies — and How an ERP Helps You Prepare

Table of Contents

NIS2 changes cybersecurity from an IT concern into a business-management responsibility.

It affects how companies manage risk, suppliers, access rights, incidents, continuity, and proof of control.

For many organisations, the first question is: “Does NIS2 apply to us?” The more useful question is: “Could a cyber incident stop us from delivering products, paying suppliers, serving customers, or meeting legal obligations?” If the answer is yes, NIS2 should influence how the company operates—even if it is not directly regulated today.

NIS2 is the EU’s updated cybersecurity directive. Formally called Directive (EU) 2022/2555, it replaced the original NIS Directive and created a common cybersecurity framework across the EU. It covers 18 critical sectors, expands the number of organisations in scope, and introduces stronger supervision, incident-reporting duties, and management accountability. Read the official Directive and the European Commission’s NIS2 overview.

“Cybersecurity is no longer only about protecting systems. It is about protecting the company’s ability to operate.”

NIS2 at a glance

TopicWhat NIS2 requires in practice
ScopeMedium and large entities in designated critical sectors, plus certain smaller organisations with a high societal or economic impact
LeadershipManagement must approve cybersecurity measures, oversee implementation, and receive appropriate training
Risk managementCompanies must use proportionate technical, operational, and organisational security measures
IncidentsSignificant cyber incidents must be reported quickly through national channels
Supply chainVendors, service providers, software, and managed IT partners become part of the cybersecurity risk picture
EnforcementNational authorities can inspect, audit, request evidence, issue binding instructions, and impose fines
Business impactCybersecurity becomes connected to procurement, continuity planning, finance, operations, HR, manufacturing, and customer service

The Directive entered into force in January 2023. EU Member States were required to transpose it into national law by 17 October 2024, and NIS1 was repealed from 18 October 2024. European Commission.

NIS2 in Bulgaria: the current position

Bulgaria adopted amendments to its Cybersecurity Act to implement NIS2. The law was adopted by the National Assembly on 5 February 2026 and published in the State Gazette on 13 February 2026. It establishes the Bulgarian scope, differentiates between essential and important entities, and sets national reporting duties and transition steps. Official State Gazette text.

The Bulgarian law covers public authorities and private or public entities in the sectors listed in its annexes when they meet the size criteria for medium-sized enterprises or larger. It can also apply regardless of company size where a business is the sole provider of an essential service, its disruption could materially affect public safety or health, or it is critical at national or regional level. Bulgarian Cybersecurity Act amendment.

This matters because the answer is not simply “we have fewer than 250 employees, so NIS2 does not apply.” Size is important, but it is not the only test. Sector, service criticality, dependencies, and national designation also matter.

The Bulgarian transition timetable includes the designation of competent authorities, implementation rules, and identification of essential and important entities. Companies should therefore monitor notices from the relevant authority and seek legal advice for a formal scope determination.

Does NIS2 apply to every company?

No—not every company is directly ​regulated by NIS2. However, nearly every company will feel its effect through customers, suppliers, insurers, banks, tenders, and contractual security questionnaires.

A small furniture manufacturer may not fall directly within the Directive. But if it supplies a regulated manufacturer, public body, utility, hospital, or digital-service provider, it may be asked to demonstrate:

  • who can access its systems and ERP data;
  • whether backups are tested;
  • how it handles a ransomware incident;
  • what happens if a supplier, cloud provider, or warehouse system fails;
  • how it reviews third-party software and IT partners;
  • whether its management has approved cybersecurity policies.

That is why NIS2 is best understood as a market-wide resilience standard, not just a legal issue for a narrow group of companies.

Company profileLikely NIS2 positionWhat to do now
Large energy, transport, healthcare, water, digital infrastructure, telecom, or managed IT providerOften directly in scope; may be an essential entityComplete formal legal scope assessment and build an evidence-based compliance program
Medium or large manufacturer in covered categories, food producer, waste-management business, postal/courier provider, online marketplace, research organizationMay be directly in scope as an important entityReview sector classification, company size, national designation, and reporting obligations
Small supplier to a regulated companyOften indirectly affected through contracts and supply-chain requirementsEstablish a security baseline and prepare evidence for customer due diligence
General SME outside listed sectorsUsually not directly in scope, unless specifically designatedUse NIS2 as a practical resilience framework rather than waiting for a customer incident

Which sectors are in scope?

NIS2 distinguishes between sectors of high criticality and other critical sectors. The exact legal classification should always be reviewed against the Directive and the relevant national law.

High-criticality sectorsOther critical sectors
EnergyPostal and courier services
TransportWaste management
BankingChemicals
Financial market infrastructureFood production, processing, and distribution
HealthManufacturing of certain critical products
Drinking water and wastewaterDigital providers such as online marketplaces, search engines, and social platforms
Digital infrastructureResearch organizations
ICT service management, including managed service and managed security service providers
Public administration
Space

For manufacturing, the scope is particularly relevant for businesses involved in areas such as medical devices, electronics, electrical equipment, machinery, motor vehicles, and other transport equipment. European Commission sector overview.

Essential versus important entities

NIS2 separates regulated organizations into two groups. Both must manage cybersecurity risk and report significant incidents. The main difference is how supervision is carried out and how strict the enforcement approach may be.

CategoryTypical profileSupervision approach
Essential entityLarger entities in high-criticality sectors, certain digital infrastructure providers, public bodies, or specifically designated critical organizationsMore proactive supervision, including regular and targeted audits
Important entityOther covered medium and large entities, including many businesses in Annex II sectorsUsually supervised after evidence of non-compliance or an incident, though national authorities retain strong powers

This distinction should not create false comfort. An “important” entity still needs a serious cybersecurity program. Its systems may be inspected, evidence can be requested, and failure to meet duties can trigger sanctions.

The European Commission explains that authorities may carry out audits, on-site and off-site checks, request documents and evidence, and issue binding instructions. NIS2 FAQ.

The core idea: risk management, not a checkbox exercise

NIS2 does not tell every company to buy one named product or use one exact technology. Instead, it requires appropriate and proportionate cybersecurity risk-management measures.

That wording is important. A small supplier and a national energy operator do not face the same risks. But both must understand their important systems, likely threats, critical suppliers, recovery needs, and decision-making responsibilities.

Article 21 of NIS2 sets out the core areas companies need to address.

NIS2 risk areaThe practical business question
Risk analysis and security policiesDo we know our key systems, risks, owners, and security rules?
Incident handlingWho detects, contains, investigates, communicates, and documents an incident?
Business continuityCan we continue operating if systems are unavailable? Are backups, recovery, and crisis procedures tested?
Supply-chain securityDo we assess the security of software providers, hosting partners, IT service companies, and critical vendors?
Secure development and vulnerability managementAre systems patched, configured securely, and reviewed for weaknesses?
Security effectivenessDo we test whether controls actually work—not merely whether policies exist?
Cyber hygiene and trainingDo employees know how to identify phishing, protect credentials, and report suspicious activity?
Cryptography and encryptionIs sensitive information protected appropriately in storage and transit?
Access control and asset managementDoes each user have only the access they need? Do we know what systems, devices, and data we own?
Multi-factor authentication and secure communicationsAre high-risk accounts and remote access protected by stronger authentication?

The strongest NIS2 program are not built around a policy folder. They are built around operational proof.

A policy saying “we back up our systems” is weak if no one can show when restoration was last tested. A supplier policy is weak if critical IT providers have never been assessed. An access-control rule is weak if former employees still have active accounts.

The board and management are accountable

One of NIS2’s biggest changes is that it brings cybersecurity firmly into the boardroom.

Management bodies must approve cybersecurity risk-management measures, oversee their implementation, and can be held accountable for failures to comply. The Directive also requires management members to undertake training so they can identify risks and understand cybersecurity practices. European Commission NIS2 overview.

This does not mean every CEO must become a security engineer. It means leadership must be able to ask—and receive clear answers to—the right questions:

  • What would stop production, deliveries, invoicing, payroll, or customer support?
  • Which systems are business-critical?
  • Which suppliers have privileged access to our data or infrastructure?
  • When were backups and disaster recovery last tested?
  • How quickly can we recognize and report a significant incident?
  • Who has the authority to stop a process, isolate systems, or communicate with customers?
  • What evidence could we show an auditor tomorrow?
Management responsibilityGood evidence
Approve risk-management approachSigned policy, board minutes, clear ownership
Monitor cyber riskRegular dashboard with key risks, incidents, vulnerabilities, backup tests, and supplier status
Fund critical remediationBudget decisions linked to documented risks
Ensure trainingTraining records for management and relevant employees
Review business continuityTested recovery plans, lessons learned, updated procedures
Oversee suppliersSecurity requirements, contracts, reviews, and escalation paths

Incident reporting: the clock starts early

NIS2 introduces strict reporting expectations for significant incidents. Under the Bulgarian law, essential and important entities report to CERT Bulgaria (СЕРИКС) through a staged process. Official Bulgarian requirements.

Time from becoming aware of a significant incidentExpected action
Within 24 hoursSubmit an early warning. State, where relevant, whether the incident may involve unlawful or malicious activity and whether it could have cross-border effects.
Within 72 hoursSubmit an incident notification with an initial assessment of severity, impact, and available technical details.
When requestedProvide progress or intermediate reports.
Within one monthProvide a final report describing the incident, likely cause, impact, mitigation actions, and any cross-border effects. If unresolved, provide an interim report and submit the final report within one month of resolution.

ENISA likewise describes the 24-hour early-warning and 72-hour incident-notification stages as central NIS2 reporting duties. ENISA incident-reporting overview.

This is why incident response cannot begin when a lawyer or executive is finally available. A company must know in advance what counts as a significant incident, who makes the initial classification, and how evidence will be collected.

A realistic ransomware scenario

Imagine a manufacturer discovers at 08:00 on Monday that users cannot access the ERP, warehouse terminals, or production planning system.

The first priority is not writing a report. It is to protect people, contain the incident, preserve evidence, and keep critical operations moving safely. But the reporting clock has already started.

PeriodOperational response
0–4 hoursIsolate affected systems, activate the incident team, preserve logs, identify affected services, and assess whether operations can continue manually
4–24 hoursDetermine whether the incident is significant, prepare the early warning, inform essential internal stakeholders, and begin customer/supplier impact assessment
24–72 hoursDeepen technical investigation, confirm business impact, identify likely attack path, report initial severity and mitigation measures
Days 4–30Recover systems, validate data, document decisions, improve controls, complete the final report

A reporting deadline is not a recovery plan. The company needs both.

Penalties: serious enough to change behavior

NIS2 requires Member States to provide for meaningful administrative fines. At EU level, the Directive sets minimum maximum fine levels:

Entity typeMinimum maximum administrative fine required by NIS2
Essential entityAt least €10 million or 2% of total worldwide annual turnover, whichever is higher
Important entityAt least €7 million or 1.4% of total worldwide annual turnover, whichever is higher

National laws determine the detailed enforcement rules and actual application. Authorities must consider the circumstances of each case, including severity, duration, damage, and whether the infringement was intentional or negligent. European Commission FAQ.

The more immediate business risk is often not the fine. It is the operational cost of an attack: halted production, unavailable warehouse processes, missed deliveries, recovery work, reputational damage, lost data, delayed invoices, and difficult customer conversations.

NIS2, GDPR, DORA, and the Cyber Resilience Act: do not mix them up

Companies often hear several EU digital laws at once. They overlap, but they do not mean the same thing.

FrameworkMain focusTypical question it answers
NIS2Cybersecurity resilience of critical and important entitiesCan this organization prevent, manage, recover from, and report cyber incidents?
GDPRProtection of personal dataAre we processing personal data lawfully and protecting it appropriately?
DORADigital operational resilience in financial servicesCan financial entities withstand ICT disruption and manage ICT third-party risk?
Cyber Resilience ActCybersecurity requirements for products with digital elementsIs this connected product or software secure throughout its lifecycle?
ISO 27001Voluntary information-security management standardDo we have a structured, auditable information-security management system?

A company can comply with GDPR and still fail NIS2. For example, it may handle personal data correctly but have weak recovery planning, poor supplier oversight, or unmanaged operational systems.

Likewise, ISO 27001 certification can provide a strong foundation, but it does not automatically prove NIS2 compliance. NIS2 requires sector-specific, legal, operational, and reporting readiness.

Why ERP is central to NIS2 readiness

ERP is often the operational heart of the business. It holds or connects customer records, suppliers, purchasing, inventory, production planning, finance, invoices, warehouse movements, quality data, service operations, and employee workflows.

If ERP access is lost, incorrect, manipulated, or unavailable, the company may not be able to answer basic questions:

  • What stock do we have?
  • Which purchase orders are open?
  • Which deliveries are due today?
  • Which production orders can still run?
  • Which suppliers must be contacted?
  • Which customer commitments are at risk?
  • Which invoices, payments, or payroll activities are affected?
  • What changed before the incident?

This is why NIS2 is not only a firewall, endpoint-security, or IT-infrastructure topic. It is also a process-control and business-continuity topic.

How SIX ERP can support NIS2-related controls

SIX ERP cannot make a company “NIS2 compliant” on its own. NIS2 requires broader controls across people, devices, networks, cloud services, suppliers, policies, training, and incident response.

However, an integrated ERP can be an important part of the evidence and control environment.

NIS2 needHow SIX ERP can support the process
Controlled accessRole-based access and clear user permissions help reduce unnecessary access to commercial and operational data
AccountabilityAudit trails and change history can support investigation of who changed key records, approvals, or transactions
Asset and process visibilityCentralized information across purchasing, inventory, manufacturing, finance, CRM, and warehousing reduces dependence on disconnected spreadsheets
Supplier risk managementSupplier records, purchasing history, contracts, approvals, and performance data can support structured vendor oversight
Business continuityClear operational data and process documentation make it easier to identify critical workflows and plan manual or recovery procedures
Incident investigationCentral records can help identify affected orders, customers, inventory movements, invoices, or production plans
Segregation of dutiesApproval workflows and role separation can reduce the risk of unauthorized purchasing, payment, or master-data changes
Evidence for auditsReporting and structured data help the company demonstrate processes, controls, ownership, and historical activity

The real value is not simply storing information in one place. It is being able to understand the operational impact of a disruption quickly.

For example, if a cyber incident affects warehouse operations, management should be able to identify priority customer orders, stock availability, delayed deliveries, alternative fulfilment options, and affected suppliers. With disconnected systems, that work becomes slower exactly when the business can least afford delay.

A practical NIS2 readiness roadmap

The goal is not to create a giant cybersecurity project that never finishes. Start with the operational risks that could materially affect your company.

First 30 days: establish ownership and scope

Appoint an executive owner and form a small cross-functional group covering management, IT, finance, operations, HR, procurement, and legal/compliance. Determine whether the organization is directly in scope and document the reasoning.

At the same time, identify the systems that matter most: ERP, email, identity systems, finance, warehouse tools, production systems, cloud storage, backups, remote access, and critical supplier portals.

If you cannot map your critical systems and dependencies, you cannot manage their risk.

Days 31–60: assess risk and close obvious gaps

Review access rights, former-user accounts, backup coverage, patching, endpoint protection, remote access, supplier contracts, incident contacts, and recovery procedures.

This is also the time to identify “single points of failure.” Perhaps only one person understands a critical ERP integration. Perhaps the warehouse relies on one internet line, or invoices arrive in a shared mailbox with no ownership. These are operational risks, not just technical risks.

Days 61–90: test the plan

Run a short tabletop exercise. Do not make it theoretical.

Ask: “It is Monday morning. ERP and email are unavailable after a suspected ransomware attack. What do we do in the first hour? Who decides? How do we take orders? How do we communicate with customers? What needs to be reported?”

Then test whether backups can actually be restored, whether contact lists are current, and whether key decisions can be made without access to the systems involved in the incident.

After 90 days: build a repeatable program

Cyber resilience is not a one-time project. Review it regularly through management reporting, supplier reviews, training, recovery tests, access reviews, and lessons learned from incidents or near misses.

FrequencyUseful control
MonthlyReview security incidents, critical vulnerabilities, privileged access, failed backups, and supplier issues
QuarterlyReview cyber risks with management; test selected incident-response scenarios
Every 6–12 monthsTest backup restoration and business-continuity procedures
Before onboarding critical vendorsAssess security, data access, support model, incident obligations, and exit arrangements
After significant business changeReassess risk when adding new sites, cloud services, integrations, production equipment, or acquisitions

The supply-chain issue companies often miss

NIS2 explicitly makes supply-chain security a priority. This includes not only raw-material suppliers, but also the companies that support your digital operations:

  • ERP and hosting providers;
  • managed IT and cybersecurity providers;
  • cloud platforms;
  • payroll and accounting systems;
  • warehouse, transport, and production-system vendors;
  • software integration partners;
  • remote-support providers;
  • payment and e-invoicing providers.

A good supplier review should ask more than “Do you have a security certificate?” It should ask what access the supplier has, how incidents are reported, where data is hosted, how backups work, how updates are managed, whether subcontractors are involved, and what happens if the relationship ends.

A secure company can still fail through an insecure dependency.

The business case: NIS2 is resilience, not paperwork

Cybersecurity investment can feel abstract until operations stop. NIS2 forces companies to translate technical risk into business impact.

A strong program can improve:

  • production and warehouse continuity;
  • supplier reliability;
  • customer trust;
  • access control;
  • audit readiness;
  • recovery speed;
  • internal accountability;
  • ability to win enterprise contracts and public tenders;
  • confidence in digital transformation projects.

The companies that benefit most will not treat NIS2 as a compliance checklist. They will use it to build a more resilient operating model.

Final thoughts: turn NIS2 into operational strength

NIS2 is a direct challenge to the old idea that cybersecurity belongs only to IT. It requires leaders to understand the systems, people, suppliers, and processes that keep the business running—and to prove that reasonable controls are in place.

For companies using SIX ERP, the opportunity is practical. Use your central operational data to map critical processes, define access roles, document suppliers, maintain audit evidence, identify business dependencies, and support faster recovery decisions.

The target is not perfect security. The target is a company that can anticipate, withstand, respond to, and recover from cyber disruption without losing control of its business.

SIX ERP can help you bring purchasing, production, warehousing, finance, CRM, approvals, and operational reporting into one connected environment—an important foundation for stronger visibility and business continuity. For a NIS2 readiness discussion, start by mapping the workflows your company cannot afford to lose.

Read the full IDC solution brief

Get the full story in The Business Value of SIX Build for SIX Cloud ERP Customers.

Dr. Andreas Maier

Thinker, Problem Solver, Mentor, Dancer, and in my spare time Entrepreneur and Blogger.

Explore related content