01Introduction
NIS2 extends EU cybersecurity law to thousands of mid-sized and large companies in sectors from energy and health to digital providers and manufacturing. Many are subject to it for the first time.
02What is NIS2?
The NIS2 Directive (EU 2022/2555) replaces the original NIS Directive. Member states had to transpose it into national law by 17 October 2024. It covers essential and important entities across 18 sectors and requires risk-management measures, incident reporting and supply chain security.
Article 21 lists minimum measures, including policies to assess the effectiveness of security controls, vulnerability handling and secure development. Article 23 sets reporting deadlines: an early warning within 24 hours, a notification within 72 hours and a final report within a month. Fines reach at least €10 million or 2% of global turnover for essential entities, and management can be held personally liable.
03How NIS2 works
Obligations depend on national transposition, but the structure is shared.
- 1.
Determine scope
Check sector and size thresholds, and register with the national authority.
- 2.
Risk measures
Implement Article 21 measures, approved and overseen by management, who must be trained.
- 3.
Test effectiveness
Assess controls through vulnerability management and penetration testing.
- 4.
Report incidents
Meet the 24-hour, 72-hour and one-month reporting timeline through incident response.
04Threats and risks
NIS2 is aimed at weaknesses exposed by recent attacks on European infrastructure.
Supply chain attacks
Compromise through suppliers and service providers.
Ransomware
Disruption to essential services such as hospitals and utilities.
Unmanaged vulnerabilities
Known flaws left open on internet-facing systems.
Personal liability
Management bodies accountable for failures to implement measures.
05How Parameter helps
Parameter helps demonstrate that security measures are effective, not just in place.
Effectiveness testing
The pentesting agents test applications continuously and prove what is exploitable.
Vulnerability handling
EASM and scanning keep the external surface under watch.
Supply chain security
Supply Chain tracks third-party code risk, an explicit NIS2 measure.

