NIS2
The EU cybersecurity directive
NIS2 is a European Union directive that extended cybersecurity duties to far more sectors than the regime before it. Every member state transposed it through its own act — Slovakia by amendment no. 366/2024 Coll., the Czech Republic by a standalone act, no. 264/2025 Coll. A company becomes a regulated entity through its sector and size, not through a decision by the regulator.
Who NIS2 binds
Classification follows from the combination of sector and company size. The directive lists sectors such as energy, transport, healthcare, water, waste, digital infrastructure, IT services, food, manufacturing and public administration. In most cases the duty applies to companies with at least 50 employees or turnover above 10 million euro.
Crucially, nobody gets in touch. If a company falls under the definition, registering with the supervisory authority is its own duty. Failing that one step is separately punishable, before the state of its actual security is even examined.
What a regulated entity has to put in place
Most of the requirements are not about technology but about order in how the company runs. The national implementing decrees set out the detail, and they differ between member states even though the directive behind them is the same.
The significant change against the earlier regime is direct management accountability. The statutory body has to complete cybersecurity training and answers for risk management — the work can be delegated, the responsibility cannot.
- A written risk analysis with named owners and regular review.
- A procedure for handling and reporting security incidents.
- Business continuity — backups and tested recovery.
- Security requirements written into supplier contracts.
- Cyber hygiene, including multi-factor authentication.
- Regular staff training and training for management.
Frequently asked questions
When did NIS2 start to apply?
The directive itself had to be transposed by October 2024, but the dates that bind a company are the national ones. Slovakia's amendment took effect on 1 January 2025 with a transition period to 31 December 2026; the Czech act took effect on 1 November 2025.
What are the fines?
The directive sets the ceiling at 10 million euro or 2 % of worldwide annual turnover, whichever is higher. National law sets the exact bands, including separate penalties for failing to register at all.
Does NIS2 reach the suppliers of regulated entities?
Indirectly, yes. Supply-chain security is a duty in its own right, so a regulated entity has to push the requirements into its supplier contracts. Smaller companies therefore meet NIS2 through supplier questionnaires and customer audits.