
NIS2 Online Marketplaces: Is Your E-Commerce Client in Scope?
Marketplaces, search engines and social networks are NIS2 digital providers. How the scope test, Article 26 jurisdiction and user thresholds work.
The latest insights on NIS2 compliance and cybersecurity.

Marketplaces, search engines and social networks are NIS2 digital providers. How the scope test, Article 26 jurisdiction and user thresholds work.

Food producers and wholesalers are important entities under NIS2. The scope test, the size trap, and what the OT floor means for your food clients.

Spain still hasn't transposed NIS2. The Commission took it to the CJEU in July 2026 — here's what governs Spanish entities now.

Joining a cyber information-sharing community is voluntary. Telling the regulator you joined is not. Article 29(4) of NIS2, explained for MSPs.

Question 14 on the procurement form asks for your NIS2 certificate. It does not exist. What Article 24 actually allows, and why EUMSS changes things.

Article 28 binds registries, registrars and resellers directly — no size threshold, no essential-entity test. Here is what it actually demands.

CIR 2024/2690 replaces NIS2 Article 21 judgement calls with hard numbers for cloud, data centre, DNS and MSP entities. Here are the actual thresholds.

Central government is in scope in every EU member state. Regional and local government is a national choice. How to scope a public sector client correctly - and why supplying one puts NIS2 into your contracts.

NIS2 Article 21(2)(j) is not just MFA. It also requires secured voice, video and text channels and an emergency channel that survives a tenant compromise.

NIS2 covers air, rail, water and road transport. Who is in scope, why Part-IS does not switch NIS2 off, and what auditors ask transport clients for.

NIS2 water sector rules explained: scope traps, OT security, Article 21 measures and incident reporting for drinking water and wastewater utilities.

NIS2 Article 26 decides which national authority supervises your client. Main establishment, not headquarters. Here is how to get it right.

NIS2 enforcement now runs on evidence: BSI notices, CCB audit windows, ANSSI orders. What regulators request and how to build the evidence pack in time.

CRA reporting starts 11 September 2026. The 24-hour deadline, the Single Reporting Platform, and what NIS2-regulated organisations and MSPs must do now.

ENISA NIS360 2026 puts rail, water and ICT service management in the risk zone. Here is how supervisors use that map to prioritise NIS2 audits.

NIS2 puts energy clients in Annex I. The EU Network Code on Cybersecurity adds its own scope, control tiers and audit clock. What MSPs must check.

Article 21(2)(a) is two obligations: a security policy with 11 mandatory contents and a risk framework with named owners. What CIR 2024/2690 requires.

NIS2 incident handling under Article 21(2)(b) is what makes the 24- and 72-hour deadlines achievable. What regulators test, and the evidence needed.

The EU's July 2026 Action Plan makes AI-assisted detection an expected NIS2 practice. What MSPs and consultants must change before the next audit.

Article 21(2)(i) bundles access control, asset management and HR security. What CIR 2024/2690 actually requires — and why MSPs must get it right first.

NIS2 Article 21(2)(e) covers secure acquisition, development, maintenance and vulnerability handling — what MSPs must evidence to pass a NIS2 audit.

Article 21(2)(g) is the NIS2 control regulators check first. What cyber hygiene and security awareness training really require — and how MSPs deliver it.

NIS2 registration is a separate obligation from Article 21 — and the easiest thing for a regulator to check. Deadlines, portals and what MSPs must do now.

Sweden's Cybersecurity Act (SFS 2025:1506) has been live since 15 January 2026. What IT consultants, MSPs and suppliers to Swedish clients must do now.

Article 21(2)(h) demands a cryptographic policy, not just encryption. What CIR 2024/2690 and the EU's 2030 quantum deadline mean for MSPs.

Ireland has not yet enacted the National Cyber Security Bill that transposes NIS2, and the Commission has taken it to the Court of Justice. What that means for Irish organisations and their suppliers, and what to do before the law arrives.

Manufacturing is in scope for NIS2 — and the IT/OT boundary is where audits fail. A practical guide to segmentation, OT incident reporting, and the June 2026 deadline.

ENISA's EUVD is live and the September 2026 manufacturer reporting deadline is real. Here's how consultants and MSPs operationalise NIS2 coordinated vulnerability disclosure.

Hospitals are essential entities under NIS2 with the strictest oversight. Here is what MSPs and consultants must deliver for healthcare clients.

Article 21(2)(f) is the NIS2 audit loop that proves your controls actually work. Here's how MSPs and vCISOs operationalise it before an auditor does.

CIR 2024/2690 turns NIS2 business continuity into 20+ evidenced requirements. What auditors check in 2026 — and where clients fall short.

NIS2 Article 21 names MFA, but ENISA now sets the bar at phishing-resistant. What MSPs and consultants must deploy and document.

Austria's NISG 2026 takes effect 1 October 2026, raising in-scope firms from 100 to 4,000. Registration closes 31 December. What consultants must do now.

The EU has referred France and Spain to the Court of Justice over NIS2. Here's what the referral means for suppliers and MSPs — and what to do this week.

On 30 June 2026, essential entities must have completed their first NIS2 compliance audit. Here is exactly what consultants and MSPs need to evidence before the deadline.

The European Commission proposed targeted NIS2 amendments in January 2026. Here's what IT consultants and MSPs need to know about ransomware reporting, scope changes, and certification pathways.

On May 26, 2026, the EU's NIS2 Cooperation Group adopted common incident reporting templates. Here's what that means for IT consultants and MSPs managing compliance for European organisations.

France's NIS2 transposition law is expected July 2026, and ANSSI's 152-measure ReCyF framework is already live. Here's what IT consultants and MSPs serving French clients need to act on now.

Italy's NIS2 authority ACN ran its first categorization window from May 1 to June 30, 2026. What entities filed shapes their security obligations, and the basic security measures are due in October 2026.
Belgium became the first EU member state to enforce a hard NIS2 conformity assessment deadline. Here is what the CyFun framework means for MSPs and IT consultants serving Belgian clients.

The Cyberbeveiligingswet (Cbw), the Dutch NIS2 law, has applied since 15 August 2026. Who is in scope, how to register via MijnNCSC, what the duty of care and reporting duty require, and who supervises you.
These 10 questions from our NIS2 compliance assessment reveal the gaps that catch even well-prepared organisations off guard. Test yourself — if you hesitate on more than three, you have work to do.
Poland enacted its NIS2 law in March 2026. Registration deadline: 3 October 2026. Here's what it means for EU suppliers and supply chains.
NIS2 Article 21(2)(d) requires cybersecurity clauses in supplier contracts. Learn what must be included and how it affects SMEs in the supply chain.
Portugal's NIS2 law took effect on 3 April 2026. Decreto-Lei 125/2025 is live. Here's what EU suppliers to Portuguese entities need to know now.
Germany's BSI registration deadline passed on 6 March 2026. By 30 June, 17,729 companies had registered, against the roughly 29,500 the BSI expects in scope. Here's what it means for your business.
Learn how to run a NIS2 gap analysis against Article 21. Identify compliance gaps, prioritise actions, and prepare before enforcement begins.
NIS2 fines reach €10M or 2% of global turnover. Learn what board members risk, which measures are mandatory, and how to prepare before enforcement starts.
NIS2 fines get the headlines. But management bans, public naming, and suspended operations can hurt your business far more. Here are the 7 penalties you need to know.
If your organisation operates in the financial sector, you may face two overlapping EU regulations: NIS2 and DORA. They share common ground but serve different purposes. Here is how they compare — and what you need to do.
Managed service providers fall under NIS2 directly — AND face new requirements from their customers. This creates a unique challenge, but also a massive business opportunity. Here is how to turn NIS2 from a compliance burden into a revenue stream.
When a significant cybersecurity incident hits, NIS2 gives you just 24 hours to file your first report. Miss the deadline and you face additional penalties. Here is exactly what you need to report, when, and to whom.
NIS2 doesn't just regulate the organisations in scope — it reshapes the entire supply chain. If you're a supplier, MSP, or software vendor to a NIS2 entity, expect new cybersecurity requirements. Here is what you need to know.
Article 21 of the NIS2 Directive lists ten cybersecurity measures every covered organisation must implement. This guide explains each one in plain language — with practical examples of what "good" looks like.
Most member states now have a NIS2 law in force. France, Spain and Ireland are still legislating, and the Commission has taken four states to the Court of Justice. The status per country, the EU enforcement timeline, and what it means if you work across borders.
If your organisation already has ISO 27001 certification, you have a solid foundation for NIS2 compliance. But ISO 27001 alone is not enough. Here is exactly where the gaps are — and how to close them.
Under NIS2, board members are personally liable for cybersecurity failures. This is not a theoretical risk — it is written into EU law. Here is what that means for you as a director.
One of the most common questions about NIS2 is: does it actually apply to me? The answer depends on two factors — your organisation's size and the sector you operate in. Here is how to find out.
NIS2 is the EU's cybersecurity law for 18 sectors. Who it applies to, what the 10 measures and reporting deadlines demand, what non-compliance costs, and which countries still have no national law.