Article · ESG & Supply Chains

The NIS2 era: board responsibility for cybersecurity

With NIS2, cybersecurity has become a matter for management rather than IT: the oversight obligation, the 24/72-hour notifications, and how supply-chain requirements reach Turkish companies.

26 May 20264 dk okumaBy Sven Köksal · ESG & Supply Chains
Köksal Attorney Partnership — data, artificial intelligence, cybersecurity and legal tech work
Summary · At a glance
  • Under NIS2, approving and overseeing the measures is the duty of the management body.
  • For significant incidents, an early warning is required within 24 hours and a notification within 72 hours.
  • Supply chain security requirements are passed down to Turkish suppliers through contracts.
  • ISO 27001 is a good foundation, but on its own it is not NIS2 compliance.

A paradigm shift

NIS2’s real innovation is not technical but organisational: approving cybersecurity measures, overseeing their implementation, and receiving training in this field are now legal duties of the management body. The “IT will handle it” era is over for companies within scope.

Practical guidance

The new security addenda coming from your EU customer are often NIS2-driven; do not sign them before aligning the notification deadlines with your own incident plan.

Let us manage NIS2-driven requirements together

Our Data & Cybersecurity Desk sets up the scope analysis, contract negotiation, and incident-response framework.

Cybersecurity law

How is scope determined?

As a rule, the Directive covers medium-sized and larger organisations in sectors such as energy, transport, health, digital infrastructure, public administration, and critical branches of manufacturing. Organisations are divided into “essential” and “important” entities, and the intensity of supervision and enforcement follows that classification. The transposition deadline expired on 17 October 2024, and Germany has since implemented NIS2 by rewriting the BSIG, in force from 6 December 2025 (as of July 2026).

Incident notification: the 24/72-hour regime

Significant incidents require staged notification: an early warning within 24 hours, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Deadlines like these can be met only if the incident response plan is rehearsed jointly by the legal, IT and communications teams; a plan that exists only on paper will not hold them.

Impact on Turkish companies: the supply chain

Companies within scope are also answerable for supply-chain security, so security requirements, audit rights and incident notification deadlines flow down to suppliers through contract addenda. For a Turkish supplier the critical point is that the deadline promised to the customer must match its own incident plan and its sub-supplier contracts. Otherwise every incident becomes a breach of contract.

The building blocks of compliance

The building blocks are risk analysis, access and encryption policies, redundancy, supplier security, incident management, and oversight documented in board resolutions. An existing ISO 27001 framework is a strong foundation, and mapping it against the NIS2 headings shows where the gaps are.

The sanctions picture and personal liability

NIS2’s sanctions framework approaches the scale of the GDPR: for essential entities, administrative fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to EUR 7 million or 1.4%, whichever is higher. More importantly, the Directive obliges Member States to regulate the personal liability of the management body: managers who breach the oversight duty face measures extending as far as a temporary ban from management functions — a power available in respect of essential entities only. This means that cybersecurity budget decisions must now be justified in the board minutes — we track the current state of implementation in our NIS2 radar entry.

From the moment of the incident to the contract: a practical scenario

Take a ransomware incident. In a NIS2-driven contract you promised your EU client notification within 24 hours, while your own incident plan runs on 48. That gap becomes a breach of contract on the night of the incident — and it does so while colliding with the KVKK and GDPR notification deadlines and those of your cyber insurance. The solution has three steps: an inventory of the notification commitments in client contracts, aligning the internal incident plan to the shortest commitment, and passing the same deadlines down to sub-suppliers. For details on the data-breach dimension, read this alongside the 72-hour regime in our Data focus area.

The Köksal approach

Our Data & Cybersecurity Desk sets up scope analysis, contract negotiation, and the incident response framework at the same table as the technical teams. Documenting board oversight and tying it to a compliance programme makes the personal-liability risk manageable.

Conclusion

NIS2 compliance should be run as a corporate governance project, not an IT project: an arrangement that begins at the management table, is tested at the contract table, and works on the night of the incident. That is the standard the Directive requires and your clients will expect.

This content is for general information purposes only and does not constitute legal advice. Please get in touch with our team for an assessment relating to your specific situation.
Sven Köksal

Author

Sven Köksal

Legal Engineer

Advisory on legal technology, process design and digital business models.

Related Areas of Work

Explore this publication together with the relevant services, practice areas, focus areas, sectors and desks.

Services

Areas of work directly connected to this publication.

See all

Practice Areas

The legal disciplines the topic sits within.

See all

Focus Areas

Focus areas assessed together according to the client's needs.

See all

Sectors

The sectors this topic touches most often.

See all

Regional Desks

Regional desks that follow the matter with a cross-border or specialist focus.

See all

If you have a subsidiary in the EU, directly; if you have EU customers, you come within scope indirectly through contracts.

The Directive requires Member States to provide for management liability where the oversight obligation is breached; national implementations are taking shape in this direction.

No; this is general information. Contact our team for your specific situation.

Knowledge Centre

Let us manage NIS2-driven requirements together

Our Data & Cybersecurity Desk sets up the scope analysis, contract negotiation, and incident-response framework.