A paradigm shift
NIS2’s real innovation is not technical but organisational: approving cybersecurity measures, overseeing their implementation, and receiving training in this field are now legal duties of the management body. The “IT will handle it” era is over for companies within scope.
Practical guidance
The new security addenda coming from your EU customer are often NIS2-driven; do not sign them before aligning the notification deadlines with your own incident plan.
Let us manage NIS2-driven requirements together
Our Data & Cybersecurity Desk sets up the scope analysis, contract negotiation, and incident-response framework.
How is scope determined?
As a rule, the Directive covers medium-sized and larger organisations in sectors such as energy, transport, health, digital infrastructure, public administration, and critical branches of manufacturing. Organisations are divided into “essential” and “important” entities, and the intensity of supervision and enforcement follows that classification. The transposition deadline expired on 17 October 2024, and Germany has since implemented NIS2 by rewriting the BSIG, in force from 6 December 2025 (as of July 2026).
Incident notification: the 24/72-hour regime
Significant incidents require staged notification: an early warning within 24 hours, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Deadlines like these can be met only if the incident response plan is rehearsed jointly by the legal, IT and communications teams; a plan that exists only on paper will not hold them.
Impact on Turkish companies: the supply chain
Companies within scope are also answerable for supply-chain security, so security requirements, audit rights and incident notification deadlines flow down to suppliers through contract addenda. For a Turkish supplier the critical point is that the deadline promised to the customer must match its own incident plan and its sub-supplier contracts. Otherwise every incident becomes a breach of contract.
The building blocks of compliance
The building blocks are risk analysis, access and encryption policies, redundancy, supplier security, incident management, and oversight documented in board resolutions. An existing ISO 27001 framework is a strong foundation, and mapping it against the NIS2 headings shows where the gaps are.
The sanctions picture and personal liability
NIS2’s sanctions framework approaches the scale of the GDPR: for essential entities, administrative fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher; for important entities, up to EUR 7 million or 1.4%, whichever is higher. More importantly, the Directive obliges Member States to regulate the personal liability of the management body: managers who breach the oversight duty face measures extending as far as a temporary ban from management functions — a power available in respect of essential entities only. This means that cybersecurity budget decisions must now be justified in the board minutes — we track the current state of implementation in our NIS2 radar entry.
From the moment of the incident to the contract: a practical scenario
Take a ransomware incident. In a NIS2-driven contract you promised your EU client notification within 24 hours, while your own incident plan runs on 48. That gap becomes a breach of contract on the night of the incident — and it does so while colliding with the KVKK and GDPR notification deadlines and those of your cyber insurance. The solution has three steps: an inventory of the notification commitments in client contracts, aligning the internal incident plan to the shortest commitment, and passing the same deadlines down to sub-suppliers. For details on the data-breach dimension, read this alongside the 72-hour regime in our Data focus area.
The Köksal approach
Our Data & Cybersecurity Desk sets up scope analysis, contract negotiation, and the incident response framework at the same table as the technical teams. Documenting board oversight and tying it to a compliance programme makes the personal-liability risk manageable.
Conclusion
NIS2 compliance should be run as a corporate governance project, not an IT project: an arrangement that begins at the management table, is tested at the contract table, and works on the night of the incident. That is the standard the Directive requires and your clients will expect.


