The Directive imposes on “essential” and “important” entities obligations covering risk management measures, supply chain security and strict incident reporting (early warning within 24 hours, notification within 72 hours). The management body is responsible for approving and overseeing the measures; personal liability may arise in the event of a breach.
Overview
NIS2 is the directive that broadens and hardens the EU’s cybersecurity baseline. What sets it apart from its predecessor (NIS1) is a much wider scope, penalties that converge towards those of the GDPR, and responsibility that is expressly tied to the management body.
Scope
In the sectors listed in Annexes I and II (energy, transport, banking, healthcare, drinking water, digital infrastructure, public administration; postal services, waste, chemicals, food, critical branches of manufacturing, digital providers), medium-sized and larger entities are, as a rule, within scope. Entities are classified as “essential” or “important”, and the intensity of oversight varies accordingly.
Core obligations
Companies must implement risk-management measures covering incident handling, business continuity, supply-chain security, access control and encryption; report significant incidents on a staged timeline (24 hours / 72 hours / detailed report); and establish oversight at management level.
Key point for the Turkish side
Turkish companies most often fall within scope through the supply chain: customers in the EU add security requirements, audit rights and incident-notification deadlines to their contracts. IT and legal need to negotiate these terms together.
Roadmap
Scope analysis based on the EU subsidiary and customer portfolio; mapping the existing security framework (ISO 27001, etc.) to NIS2 headings; incident-response and notification arrangements; documenting oversight through board resolutions and training records.
Penalties
For essential entities, administrative fines are provided for with a ceiling of at least EUR 10 million or 2% of global turnover; for important entities, at least EUR 7 million or 1.4%. For members of the management body, personal measures in the event of an oversight breach — up to a temporary ban from holding office — are on the table.
Related content
We address the management-responsibility dimension in our NIS2 analysis and the incident-response framework in our Cybersecurity focus. For data-breach notifications, read it alongside the GDPR and KVKK records.
Official Sources
Directive text · EUR-Lex NIS2Guidance · ENISA enisa.europa.euBSI NIS-2 implementation page bsi.bund.de


