Home/ Blog/ NIS2 in practice: what mid-size firms actually need to do
Compliance

NIS2 in practice: what mid-size firms actually need to do

June 15, 2026

A pragmatic checklist for compliance without drowning your IT team.

The NIS2 Directive doesn’t just apply to power grids and hospitals anymore. It has widened the net to cover mid-size firms across manufacturing, digital services, food supply, and dozens of other sectors that never thought of themselves as “critical infrastructure.” A lot of companies are only now realizing they’re in scope — often a few months before their national deadline.

The good news is that most of what NIS2 asks for is good security practice you should already be doing, not a new invention. The bad news is that “good practice” has to be documented, tested, and reportable, and that’s where most teams stall.

In practice, four things matter most: a written risk management process that’s actually followed, incident reporting that can hit the 24-hour early warning and 72-hour full report windows, supply chain security checks on your key vendors, and clear accountability at management level — NIS2 makes leadership personally responsible for oversight, not just IT.

None of this requires a compliance department. It requires a checklist, an owner, and a realistic timeline. Start with the incident reporting process, since it’s the one requirement you can’t improvise under pressure.