Regulatory

NIS2 Directive Practical Guide: Cybersecurity Obligations for Essential and Important Entities

✎ Kieran Upadrasta 📅 2025-08-20 🎓 CISSP, CISM, CRISC, CCSP

The Network and Information Security Directive 2 significantly expands the scope of EU cybersecurity regulation, bringing an estimated one hundred and sixty thousand additional organisations under mandatory cybersecurity requirements. This practical guide provides a structured approach to NIS2 compliance for both essential and important entities, addressing the key challenge many organisations face: translating directive requirements into concrete technical and organisational measures.

The guide begins with a comprehensive scope assessment methodology, helping organisations determine whether they fall within NIS2's expanded scope — which now covers sectors including energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. The distinction between essential and important entities is clarified, along with the implications for supervision and enforcement.

Core cybersecurity risk management measures required under Article 21 are mapped to practical controls, including policies on risk analysis and information system security, incident handling procedures, business continuity and crisis management, supply chain security, security in network and information systems acquisition and development, policies for assessing effectiveness of measures, cybersecurity hygiene and training, cryptographic controls, human resources security, and multi-factor authentication requirements.

The paper provides particular depth on supply chain security requirements, reflecting the directive's recognition that supply chain attacks represent one of the most significant and growing threats to organisational cybersecurity. Practical approaches to vendor risk assessment, contractual security requirements, and ongoing supplier monitoring are detailed, drawing on experience managing third-party risk across complex financial services supply chains.

  1. 01NIS2 Directive: Scope & Key Changes
  2. 02Essential vs Important Entity Classification
  3. 03Article 21: Risk Management Measures
  4. 04Incident Notification Requirements
  5. 05Supply Chain Security Obligations
  6. 06Governance & Accountability Framework
  7. 07Technical Controls Implementation
  8. 08Cross-Border Compliance Considerations
  9. 09Continuous Compliance & Audit Preparation
K

Kieran Upadrasta

CISO & Strategic Cyber Consultant · CISSP, CISM, CRISC, CCSP

27 years securing financial services · Big 4 pedigree (Deloitte, PwC, EY, KPMG) · Zero breaches managing £500B+ in assets

https://www.kie.ie · LinkedIn