Back to blog
Compliance·Jun 15, 2026·7 min read

NIS2 compliance: what it means for your software and AI stack

NIS2 is usually handed to the security team and forgotten by everyone else. That is a mistake. Its reach runs straight through your software supply chain, and the AI tools layered on top of it are squarely in scope.

If you run software in a sector the EU considers essential or important, NIS2 is already your problem, and it is broader than the firewall-and-patching exercise people expect. It pulls your vendors, your SaaS, and increasingly the AI tools your teams adopt into one accountability chain, with named liability at the top.

This guide explains what NIS2 actually requires, who it applies to, and the part most teams miss: how your software and AI stack sits inside its supply-chain and risk-management obligations. For the wider regulatory picture, see the EU AI Act explained.

What NIS2 is

NIS2, formally Directive (EU) 2022/2555, is the EU's updated cybersecurity law. It replaced the original 2016 NIS Directive, widened the sectors in scope, raised the baseline security requirements, and added real accountability for senior management. Member states had to transpose it into national law by 17 October 2024, so for most organisations it is already in force through national implementing legislation.

Where the first directive was light-touch and unevenly applied, NIS2 is prescriptive. It sets common risk-management measures, hard incident-reporting deadlines, and supervisory powers that include fines and management liability.

Who NIS2 applies to

NIS2 sorts organisations into two tiers, essential entities and important entities, across around eighteen sectors. Essential covers the highest-criticality sectors such as energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, and public administration. Important covers sectors such as postal services, waste management, chemicals, food, manufacturing, digital providers, and research.

Size matters too. As a rule of thumb, medium-sized and larger organisations (broadly, 50 or more staff or over 10 million euros turnover) in those sectors are in scope, with some smaller entities pulled in where they are critical. The practical test is simple: if your service going down would disrupt an essential function, assume you are in scope and confirm against your national transposition.

Two things catch organisations out. The supply-chain reach means you can be affected even if you are not directly regulated, because your regulated customers must now hold their suppliers to NIS2-grade security. And digital infrastructure and ICT service management are explicitly in scope, which sweeps in many software and cloud businesses that did not think of themselves as critical.

What NIS2 actually requires

The obligations cluster into four areas.

Risk-management measures. Article 21 sets a baseline every in-scope entity must implement: policies for risk analysis and information security, incident handling, business continuity and backups, supply-chain security, security in acquiring and maintaining systems, vulnerability handling, cryptography, access control, and multi-factor authentication. It is an all-hazards approach, not a checklist of point products.

Incident reporting. The deadlines are tight: an early warning to your national authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. Significant means an incident that causes serious operational disruption or affects other parties.

Supply-chain security. Entities must assess and manage the security risks of their suppliers and service providers, including those vendors' own security practices. This is the clause that drags your software and AI stack directly into scope.

Governance and accountability. Management bodies must approve the risk-management measures, oversee their implementation, and undergo training, and they can be held personally liable for failures. NIS2 deliberately moves cybersecurity from a back-office IT concern to a board-level duty.

Where your software and AI stack comes in

Here is the part that turns NIS2 from a security-team task into a governance problem. The supply-chain obligation does not stop at your infrastructure vendors. Every piece of software your organisation depends on, and every service that processes your data, is part of the supply chain you are now required to assess and manage.

AI tools are software, and usually third-party software handling sensitive data. A generative AI assistant that ingests internal documents, a vendor model that scores customers, an AI feature embedded in a SaaS product you already pay for: each is a supplier relationship NIS2 expects you to have assessed for security. Most organisations have not, because they do not even hold a complete list of the AI tools in use.

Assessing those third-party AI vendors — their subprocessors, hosting and certifications — is what Grasp's automated vendor assessments do, so the supply-chain obligation is covered by evidence rather than guesswork.

That is the link to shadow AI. The unsanctioned AI tools your teams adopt without review are, in NIS2 terms, unmanaged third-party software inside your supply chain, and exactly the gap a supervisor or an incident will expose. You cannot secure or report on a tool you cannot see, which is why an inventory comes first. Our guides to detecting shadow AI and building an AI inventory cover how to surface them.

How NIS2 overlaps with your other obligations

NIS2 does not sit in isolation, and the overlap is good news because it lets you build once. Its risk-management baseline maps closely onto ISO 27001, so an existing information-security management system gives you a head start; the ISO 42001 versus ISO 27001 guide covers where the AI-specific controls extend it. It overlaps with GDPR on incident handling and data protection, and it runs alongside the EU AI Act, which governs the AI systems NIS2 treats as part of your supply chain. Treat them as one programme, not four.

Penalties

NIS2 has teeth. Essential entities face fines up to 10 million euros or 2% of global annual turnover, whichever is higher. Important entities face up to 7 million euros or 1.4%. Beyond fines, supervisory authorities can issue binding instructions, order the suspension of services, and hold named managers liable, including temporarily barring individuals from management roles in the most serious cases. The accountability is personal, not just corporate.

What to do about it

The work sequences cleanly. Build a complete inventory of the software and AI systems in use, including the embedded and unsanctioned ones, because supply-chain security starts with knowing your supply chain. Assess each supplier and tool against your risk-management baseline, and prioritise the ones touching critical functions or sensitive data. Put the incident-reporting process in place so the 24 and 72 hour clocks can be met. And get the risk-management measures formally approved at board level, because under NIS2 that approval is itself an obligation.

Frequently asked questions

What is NIS2 in simple terms?

NIS2 is the EU's updated cybersecurity law. It requires organisations in essential and important sectors to put baseline security measures in place, report significant incidents within tight deadlines, secure their supply chains, and hold senior management accountable for cyber risk.

When did NIS2 come into force?

Member states had to transpose NIS2 into national law by 17 October 2024, so for most organisations it applies now through national implementing legislation. Exact timing and detail vary by country, so confirm against your national transposition.

Does NIS2 apply to my company?

If you operate in one of the roughly eighteen essential or important sectors and you are medium-sized or larger, assume you are in scope. You can also be affected indirectly, because regulated customers must now hold their suppliers to NIS2-grade security, so software and service providers feel it through the supply chain.

How does NIS2 relate to AI tools?

AI tools are third-party software that often processes sensitive data, so they fall under NIS2's supply-chain security and risk-management obligations. Unsanctioned AI tools in particular are unmanaged supply-chain risk that NIS2 expects you to identify and control.

What are the penalties for NIS2 non-compliance?

Up to 10 million euros or 2% of global annual turnover for essential entities, and up to 7 million euros or 1.4% for important entities. Authorities can also issue binding orders and hold named managers personally liable.

How is NIS2 different from the EU AI Act?

NIS2 governs cybersecurity and resilience across critical sectors; the EU AI Act governs how AI systems are built and used, by risk tier. They overlap where AI sits inside a regulated entity's supply chain, and the cleanest approach is to manage both as one governance programme.

Grasp gives security and compliance teams a live inventory of every software and AI tool in use, the risk picture across the supply chain, and the audit-ready evidence that obligations like NIS2 demand. See how Grasp keeps you compliance-ready →