NIS2 in brief

The NIS2 Directive expands digital security obligations to a much broader set of entities than its predecessor. From October 2026, key requirements will be enforced across the European Union, and non-compliance penalties may reach millions of euros.

Who is affected?

The rules divide covered entities into two groups: essential and important. In practice, they cover most medium and large companies operating in sectors such as energy, transport, finance, health, digital infrastructure, food, postal services, chemicals and digital service providers.

Key changes

  • Cyber risk management — formal risk assessment, policies and procedures.
  • Incident reporting obligation within 24–72 hours of detection.
  • Supply chain security — required assessment of suppliers and subcontractors.
  • Management accountability — leadership must oversee cybersecurity.
  • Administrative sanctions — up to EUR 10 million or 2% of annual turnover.

What to do now?

The most effective first step is an NIS2 readiness audit. It quickly verifies gaps in governance, documentation and technical controls and helps plan remediation actions within the required deadlines.

Need support?

Contact the CHORS team to discuss a tailored solution for your business.

Get in touch