NIS2 Due Diligence: The 3 Factors That Set Your Bar — and the 8 a Regulator Weighs Instead
NIS2 says “due diligence” once — not about suppliers. See the 3 factors that set your bar under Article 21(1), and the 8 a regulator weighs instead.
NIS2 compliance guides and resources
NIS2 says “due diligence” once — not about suppliers. See the 3 factors that set your bar under Article 21(1), and the 8 a regulator weighs instead.
The NIS2 Cooperation Group can’t fine you. But Article 23(11) can turn its 26 May 2026 reporting templates into a mandatory format — the 3 tasks to track.
NIS2 has 144 recitals and none are binding. Yet ENISA sends you to three to define “basic cyber hygiene” — the one Article 21 duty with no definition.
NIS2 EU-CyCLONe: no severity level triggers Article 16, and the EU’s agreed scale isn’t due until June 2027. What that means for your incident report.
Search NIS2 for force majeure and you get zero hits. See what a state-sponsored attack changes under Articles 21, 23 and 32 — and what it never does.
NIS2 Article 8 makes every Member State name a single point of contact. In 16 of 27 it is also the competent authority — here is who you actually report to.
Three national bodies can contact you under NIS2. Only the competent authority can audit, order, or fine you — here is exactly what Articles 32 and 33 let it do.
Your NIS2 CSIRT has eight tasks under Article 11(3). Two include services that start only when you ask — how to trigger them, and when it can say no.
The NIS2 size threshold is not “50 employees or €10M turnover”. You stop being small at 50 annual work units, or when turnover and balance sheet both top €10M.
Eight routes out of NIS2 scope — but only four remove your entity from the Directive. What Article 2(1), 2(7), 2(10) and Article 4 each actually switch off.