Licensed by the Estonian FIU · FIU000117Operating since 2014Punane 6, Tallinn

info@micaconsult.com+372 5089565

LexorCorp Global

NIS2 · Directive (EU) 2022/2555

NIS2 compliance documentation

What the NIS2 Directive requires, who it covers, why it reaches suppliers that are not covered themselves, and what non-compliance costs — with the route to company-specific NIS2 documentation on nis2europe.eu, operated by AIPOS OÜ.

In short

  • NIS2 is the EU cybersecurity directive, Directive (EU) 2022/2555. Each Member State applies it through its own transposition law.
  • It covers medium-sized and large organisations in 18 sectors, and some entities regardless of size.
  • Covered entities must have management-approved risk-management measures, report significant incidents within 24 hours, and control the security of their suppliers.
  • Because of the supply chain duty, suppliers outside the scope are asked by their customers for NIS2 evidence as well.
  • Company-specific NIS2 documentation for 24 EU countries is ordered on nis2europe.eu from AIPOS OÜ. It is usually ready within an hour after payment is received.

Choose your country on nis2europe.eu Current prices on nis2europe.eu

What NIS2 is

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (the NIS2 Directive) replaced the first NIS Directive (EU) 2016/1148. The Member States had to transpose it by 17 October 2024 and apply the national measures from 18 October 2024 (Article 41(1)). A directive does not bind companies directly: the binding text for a company is its own country's transposition act — in Estonia, for example, the Cybersecurity Act (küberturvalisuse seadus), supervised by the Information System Authority (RIA). National acts follow the same structure but differ in details such as the competent authority, registration deadlines and the amount of fines.

Who it covers

Sector test. An entity is in scope if it is of a type listed in Annex I (sectors of high criticality: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration and space) or Annex II (other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of listed products, digital providers and research).

Size-cap rule. Under Article 2(1), NIS2 applies to such entities if they qualify as medium-sized enterprises under Article 2 of the Annex to Commission Recommendation 2003/361/EC, or exceed those ceilings. In practice: 50 or more employees, or an annual turnover and a balance sheet total each above EUR 10 million. Figures of partner and linked enterprises may have to be added, so a small subsidiary of a larger group can be in scope.

Regardless of size. Article 2(2) to (4) brings in, among others, providers of public electronic communications networks or services, trust service providers, top-level domain name registries and DNS service providers, the sole provider of an essential service in a Member State, entities identified as critical under Directive (EU) 2022/2557, domain name registration services, and central government public administration.

Jurisdiction. As a rule, an entity falls under the Member State in which it is established (Article 26(1)); telecom providers fall under each Member State where they provide services, and certain digital providers under the Member State of their main establishment in the Union.

Essential and important entities

Article 3 sorts covered entities into two categories. Essential entities (Article 3(1)) are, in particular, Annex I entities that exceed the ceilings for medium-sized enterprises, qualified trust service providers, top-level domain name registries and DNS service providers regardless of size, medium-sized telecom providers, central government entities, critical entities under Directive (EU) 2022/2557 and entities a Member State designates as essential. Important entities (Article 3(2)) are all other Annex I and II entities in scope. The obligations are the same; the difference lies in supervision (proactive for essential, reactive for important) and in the maximum fines.

The supply chain: why NIS2 reaches companies outside its scope

Article 21(2)(d) requires every essential and important entity to address supply chain security, including security-related aspects of its relationships with its direct suppliers and service providers. Article 21(3) adds that, when choosing these measures, the entity must take into account the vulnerabilities specific to each direct supplier and service provider, the overall quality of their products and cybersecurity practices, including their secure development procedures, and the results of EU coordinated risk assessments of critical supply chains (Article 22(1)).

A covered entity can only meet this duty through its contracts. The result is visible in every procurement: large customers push compliance evidence down to their suppliers — security questionnaires, contractual security and incident notification clauses, audit rights, and requests for documented policies. A supplier that cannot answer risks losing the contract, even though NIS2 does not apply to it directly.

nis2europe.eu offers a Supply Chain Security Attestation for exactly this situation: a supplier that is not itself subject to NIS2, but whose NIS2-regulated customer asks for evidence of supply chain security measures. More in the guide NIS2 supply chain requirements for suppliers.

Choose your country on nis2europe.eu

What a covered entity must do

Governance — Article 20
The management body must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements. Its members must follow training, and entities are encouraged to train employees regularly.
Risk-management measures — Article 21
Appropriate and proportionate technical, operational and organisational measures based on an all-hazards approach, covering at least the ten items of Article 21(2): (a) risk analysis and information system security policies; (b) incident handling; (c) business continuity, backup management, disaster recovery and crisis management; (d) supply chain security; (e) security in acquisition, development and maintenance, including vulnerability handling and disclosure; (f) assessment of the effectiveness of the measures; (g) basic cyber hygiene and training; (h) cryptography and encryption; (i) human resources security, access control and asset management; (j) multi-factor or continuous authentication and secured communications.
Incident reporting — Article 23
Significant incidents are notified to the CSIRT or the competent authority in stages: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, intermediate reports on request, and a final report no later than one month after the incident notification.
Registration — Articles 3(4) and 27
Entities provide the competent authority with their name, address and contact details, IP ranges, sector and the Member States where they provide services, and report changes within two weeks (Article 3(4)). Digital infrastructure and digital providers listed in Article 27 register with additional information.

Supervision, fines and management liability

Essential entities are subject to proactive supervision — on-site inspections, audits, security scans and information requests (Article 32). Important entities are supervised when there is evidence or an indication of non-compliance (Article 33). Under Article 34, Member States must provide for administrative fines with a maximum of at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher, for essential entities, and at least EUR 7 million or 1.4% for important entities. For essential entities, a person discharging managerial responsibilities at chief executive officer or legal representative level can be temporarily prohibited from exercising managerial functions (Article 32(5)(b)). More in What happens without NIS2 compliance.

The documentation on nis2europe.eu

nis2europe.eu is operated by AIPOS OÜ (registry code 16966532, Estonia). Its catalogue covers 24 EU countries; each country page is in the local language and built on that country's NIS2 transposition law. The documentation is generated from the company's own data and profile, usually within an hour after payment is received. AIPOS OÜ's terms of purchase describe the one hour as the usual course and set the binding deadline for fulfilling the order at no later than 10 working days after receipt of payment.

According to nis2europe.eu, the NIS2 Document Package contains a cybersecurity risk management policy, an incident handling plan, a business continuity plan, a supply chain security policy, and a management responsibility statement with a training framework. Under AIPOS OÜ's terms, the service does not include legal advice, review of the documents by a lawyer, or implementing the described measures within the company.

Net prices published by AIPOS OÜ on nis2europe.eu/pricing (read on 30 September 2026; the same in all 24 countries). The current price is always the one on nis2europe.eu.
Service on nis2europe.euNet price
Company-Specific NIS2 Cybersecurity Risk Management Policy129 EUR
NIS2 Document Package299 EUR
NIS2 Document Package + technical scan590 EUR
NIS2 technical security check — external assessment99 EUR
Supply Chain Security Attestation299 EUR

Prices are net; VAT is applied as stated on nis2europe.eu. The order, the payment and the invoice are handled on nis2europe.eu by AIPOS OÜ.

Choose your country

Each link opens the country page on nis2europe.eu, in the local language and based on that country's transposition law:

Frequently asked questions

Does LexorCorp Global sell the NIS2 documentation?

No. The documentation is sold and provided by AIPOS OÜ (registry code 16966532) on nis2europe.eu. You order and pay there, the contract is with AIPOS OÜ and the invoice is issued by AIPOS OÜ. This page only explains NIS2 and links to that website.

Is my company subject to NIS2?

Usually yes if it operates in a sector listed in Annex I or II of Directive (EU) 2022/2555 and has at least 50 employees, or an annual turnover and a balance sheet total each above EUR 10 million. Some entities are covered regardless of size (Article 2(2)). The national transposition law of your country decides the details.

My company is too small for NIS2. Can it still be affected?

Yes, as a supplier. Companies in scope must manage the security of their direct suppliers and service providers (Article 21(2)(d) and (3)), so they pass security requirements, questionnaires and contract clauses on to their suppliers.

How quickly is the documentation ready?

According to nis2europe.eu, the documentation is usually ready within one hour after payment has been received. AIPOS OÜ's terms of purchase set the binding deadline: the order is fulfilled no later than 10 working days after receipt of payment.

Does the documentation make my company compliant?

No document by itself does. The documents describe the measures; the company must implement them, and its management body remains responsible for approving and overseeing them (Article 20). Nothing here is legal advice or a guarantee of compliance.

Ready to prepare your NIS2 documentation?

Choose your country on nis2europe.eu. The order is placed with, and invoiced by, AIPOS OÜ — see the notice at the top of this page.