Anders m. Damgren
Head of Safety & Documentation
The requirements of the NIS2 directive apply on an ongoing basis through the national implementing acts, in Denmark since 1 July 2025 and in Germany since 6 December 2025. The requirements fill many articles, but in practice they gather into three areas of accountability: Management must own the risk management, the measures must follow from a risk assessment, and incidents must be handled and reported within fixed deadlines. Here we walk through the three areas and the documentation duty that ties them together.
Table of contents
Management accountability: the task cannot be delegated away
The first and most overlooked requirement is not technical. NIS2 places the responsibility for cybersecurity risk management with the entity’s management body. Management must approve the risk management measures, oversee their implementation and undergo training in information security, so that it can judge the risks it signs off on.
The practical work can of course be done by others, internally or externally. The responsibility cannot. Management can be held personally liable for gross negligence, and the fine levels for the entity are substantial: national maximums of at least €10 million or 2 % of global annual turnover for essential entities, and at least €7 million or 1.4 % for important entities, as set out in the directive.
For boards and executive teams the practical consequence is that cybersecurity needs to be on the agenda as a standing item with decisions that can be documented. An email from the IT manager saying the matter is under control does not meet the requirement.
What the authorities will ask to see
- Risk assessments
- Security policies
- Continuity plans
- Training logs
- Supplier assessments
- Management minutes
Risk management: measures must follow from the risk assessment
The core of the directive is the requirement for appropriate and proportionate measures to manage cybersecurity risks. The order matters: first the risk assessment, then the measures. The authorities will look for the connection, meaning that what you have implemented corresponds to the risks you have identified.
The directive lists the areas the measures must cover as a minimum. The most important in practice:
- policies on risk analysis and information security
- incident handling
- business continuity, backup and crisis management
- supply chain security, including the security of supplier relationships
- security in the acquisition, development and maintenance of network and information systems
- procedures to assess whether the measures are effective
- basic cyber hygiene and staff training
- cryptography, access control and asset management
The supply chain item deserves attention, because it reaches beyond your own organisation. You must assess the security of your suppliers, and that is the mechanism that passes NIS2 requirements on to companies that are not themselves covered. National authorities publish guidance that translates the list into concrete activities; in Denmark that role sits with the Agency for Civil Protection and Preparedness, in Germany with the BSI.
If you build machinery, there is also an overlap with the Machinery Regulation (EU) 2023/1230, which from January 2027 requires control systems to withstand attempted manipulation. We have covered that in our article on CE marking of machinery.
Incidents: 24 hours, 72 hours and one month
Significant incidents must be reported to the authorities within fixed deadlines set by Article 23 of the directive:
- 4. An early warning within 24 hours of becoming aware of the incident.
- 5. An incident notification within 72 hours, with an assessment of the incident, its severity and its impact.
- 6. A final report no later than one month after the notification.
Note that the first two deadlines run in parallel from the moment you become aware of the incident. The 72-hour clock does not start when the 24-hour clock runs out.
The deadlines are short, and they can only be met if the process exists before the incident does. That means deciding in advance what counts as a significant incident in your operation, who assesses it, who notifies the authority, and how you collect the documentation along the way. An incident process that has to be invented at two in the morning, while production is down, does not meet a 24-hour deadline.
Documentation ties it all together
The common denominator across the three areas is documentation. The authorities do not assess your actual security level by testing your systems. They assess what you can produce: risk assessments, policies, continuity plans, training logs, supplier assessments and minutes showing management’s treatment of the subject.
Many technical organisations face the reverse of the expected problem. Security in practice is often better than the paperwork. Our experience from documentation work in regulated industries is that this part can be caught up, if it is approached systematically: area by area, with a clear owner on every gap.
If you want to know where you stand before the authorities or a customer asks, a NIS2 gap analysis is the natural place to start. If you are unsure whether the rules apply to you at all, we have covered the criteria in our article on who is covered by NIS2.
Contact us
Want a concrete picture of where your organisation stands against the requirements? Book a free NIS2 gap workshop, where a specialist walks through 21 control areas with your team, or contact us to talk it through.
FAQ
Management must approve the cybersecurity risk management, oversee the implementation of the measures and undergo information security training. The responsibility sits with management and cannot be delegated away, and management can be held personally liable for gross negligence.
The directive requires appropriate measures across a set list of areas, including risk management policies, incident handling, backup and continuity, supply chain security, access control, cryptography and staff training. The measures must be proportionate to your risk assessment.
An early warning within 24 hours, an incident notification within 72 hours and a final report no later than one month after. The first two deadlines run in parallel from the moment you become aware of the incident.
Member states must provide for maximum fines of at least €10 million or 2 % of global annual turnover for essential entities, whichever is higher, and at least €7 million or 1.4 % for important entities.
Supervision is national and typically sector-based. In Denmark it sits with the sector authorities coordinated by the Agency for Civil Protection and Preparedness, in Germany with the BSI.
Yes. Basic cyber hygiene and staff training are among the measures the directive lists, and management must additionally undergo training itself.
Yes. The requirements for risk management, measures and documentation apply on an ongoing basis. Incident reporting is only the part that activates when something goes wrong.