You own or run a company of a hundred-and-something people — logistics, manufacturing, energy services, food distribution. Somewhere in the last two years, "NIS2" started appearing in board packs and customer emails. This post is for you, not for your IT manager: what the law actually asks of you personally, and the five questions that tell you whether your company is in decent shape — in business language, with the jargon unpacked as we go.
What the law asks of the company, in one paragraph
NIS2 is the EU's cybersecurity law for sectors the economy depends on — energy, transport, manufacturing, food, digital services, and more. Each EU country has written it into national law on its own schedule. Stripped of the legal language, it asks a company to do three things: manage its security risks — explicitly including the risk that comes in through suppliers and service providers; report serious incidents to the authorities quickly; and be able to prove both of those, on paper, when asked. Not "be unhackable." Manage, report, prove.
What it asks of you personally
This is the part that tends to surprise owners. The directive's governance clause puts three duties on management directly: management approves the cybersecurity risk-management measures, management oversees their implementation, and management can be held liable when the company fails to comply. There is also a training duty — management is expected to understand the risks well enough to actually judge what it is approving. Some national laws sharpen this further: Germany's version, for instance, spells out personal liability for management bodies in its own section of the act.
The practical meaning is simple: "IT handles that" stops being an acceptable answer, because signing off is now your job, and the signature has your name on it. The good news is that approving and overseeing something is entirely doable — if the something exists and produces records you can read.
On fines, once and calmly: depending on how your company is classified, the maximum administrative fine is up to €10 million or 2% of global annual turnover, whichever is higher — or up to €7 million or 1.4% for the lighter category. Fines are high. Planning and an organised process are cheaper. That is the entire role fear should play in this decision.
The five questions
You don't need to read the directive. You need honest answers to five questions. Ask them of whoever owns security in your company — your IT manager, your head of operations, your external IT partner.
1. Are we on the list — and in which category?
As a general rule, the law reaches companies in the covered sectors from around 50 employees or €10 million turnover, with a heavier category starting around 250 employees or €50 million. A few kinds of company are covered regardless of size, and the exact thresholds sit in each country's national law — so this first question deserves a real answer, in writing, from someone who has checked your sector and your country, not a guess. Everything else depends on it.
2. Which ten suppliers could take us down?
The supply-chain clause is the part of NIS2 most mid-market companies are least prepared for, and the reason is structural: the evidence lives outside your company. Start with the blunt version of the question — which suppliers, if they went down or got breached tomorrow, would stop production, payroll, or deliveries? If the answer is a confident list with an owner and a last-updated date, you are ahead of most. If it's "we'd have to pull that together," that's the first gap.
3. If one of them is breached tonight, how fast can we say what they touch?
When a supplier reports a breach, the clock that matters is yours: once your company becomes aware of a significant incident affecting it, the first notice to the authorities is due within 24 hours, a fuller report within 72. Those deadlines are survivable if someone can open one record and see what the supplier does for you, what systems they reach, and who assessed them last. They are miserable if the answer lives across a spreadsheet, an inbox, and the memory of someone who left last year. Ask for a live demonstration, with a real supplier, and time it.
4. Who approved each critical supplier — and where is that written down?
At some point, someone decided each of your critical suppliers was acceptable. The question is whether that decision exists as a record — who approved, on what evidence, when — or only as institutional memory. The test is unforgiving: if the person who made the call resigned tomorrow, could you still show why the supplier was approved? Regulators and auditors ask exactly this, usually years after the decision. So do lawyers, after an incident.
5. What would we show an inspector next month?
Not hypothetically — literally. If a supervisory letter arrived Monday, what pile of documents would your team assemble, and how long would it take? The companies that handle inspections calmly aren't the ones with the biggest security budgets; they're the ones whose evidence was organised before the letter came. If the honest answer is "it would take us weeks and we'd find gaps," better to learn that from this question than from the letter.
What to do with the answers
If the five answers came back solid — genuinely, not politely — your job is oversight: put the questions on a quarterly rhythm and keep the records current. If two or more came back soft, resist the instinct to buy something first. Sequence it: confirm your classification, build the one supplier list with an owner, then work through assessment and record-keeping from there.
Two ways we can help, sized differently. The NIS2 readiness check is self-serve, takes about five minutes, and scores the same ground these questions cover. If you'd rather have the answers produced for you, the NIS2 Supplier Exposure Assessment is a fixed-scope, fixed-price engagement: we inventory your supplier exposure, classify it, and hand over an audit-ready report with the gaps named and prioritised — something you can put in front of a board, or an inspector, with your name on it and evidence behind it.