NIS2 Directive Explained: Cyber Security Compliance for Finance Teams

NIS2 broadens EU cyber security law well beyond financial services. Here's what finance and compliance professionals need to know about scope, obligations and penalties.

Learnsignal Education Team
7 min read
Updated

The EU's NIS2 Directive is the biggest overhaul of European cyber security law in a decade, and it's landing at an awkward time for finance professionals: just as many are getting to grips with DORA, a second, broader directive is working its way onto the compliance agenda. If your organisation sits outside financial services, or if you advise clients who do, NIS2 is the one to watch next.

What is NIS2?

NIS2 (the second Network and Information Security Directive) is EU legislation designed to raise the baseline level of cyber security across critical and important sectors. It replaces the original 2016 NIS Directive, which regulators judged too narrow and too inconsistently applied across member states. NIS2 widens the net considerably, covering energy, transport, water, health, digital infrastructure, public administration, manufacturing, postal and courier services, waste management, food, and managed service providers, among others.

Each in-scope organisation is classified as either an "essential entity" (larger organisations in the highest-risk sectors) or an "important entity" (smaller organisations, or those in moderately critical sectors). Both categories face binding obligations around risk management, incident reporting, supply chain security, and board-level accountability — but essential entities face more intensive supervision.

How NIS2 relates to DORA

If you've already read up on the Digital Operational Resilience Act, you might reasonably ask why finance teams need to care about NIS2 too. The short answer: DORA is "lex specialis" for the financial sector, meaning banks, insurers, investment firms and other DORA-regulated entities generally follow DORA's ICT risk rules rather than NIS2's. But NIS2 still matters to finance professionals in several situations:

  • Your organisation is a non-financial entity in an NIS2-covered sector (energy, manufacturing, digital infrastructure, healthcare, and so on) and you sit in the finance function — NIS2 compliance costs, incident reporting and governance obligations will land on your desk.
  • You work in practice and advise clients outside financial services who fall in scope of NIS2 — understanding the directive is now part of a well-rounded advisory or audit conversation.
  • Your finance function relies on third-party ICT suppliers or managed service providers who are themselves NIS2-regulated, and their compliance posture affects your own supply chain risk assessments.

Key obligations under NIS2

Entities in scope must implement a set of minimum cyber security risk-management measures, broadly covering:

  • Risk analysis and information system security policies
  • Incident handling, including mandatory notification to the relevant national authority within tight timeframes (an early warning within 24 hours of becoming aware of a significant incident, followed by a fuller notification within 72 hours)
  • Business continuity and crisis management, including backup management and disaster recovery
  • Supply chain security, extending accountability to suppliers and service providers
  • Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
  • Policies and procedures to assess the effectiveness of cyber security risk-management measures
  • Basic cyber hygiene practices and staff training
  • Use of cryptography and encryption where appropriate
  • Human resources security, access control policies and asset management
  • Multi-factor authentication, secured voice/video/text communications and secured emergency communication systems, where appropriate

Crucially, NIS2 makes management bodies personally accountable. Directors and senior managers of in-scope entities must approve the cyber security risk-management measures, oversee their implementation, and can face liability for non-compliance — a deliberate move by EU legislators to push cyber risk out of the IT department and into the boardroom, alongside financial and legal risk.

Penalties for non-compliance

Under Article 34 of the directive, essential entities face maximum administrative fines of at least €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face a lower ceiling of at least €7 million or 1.4% of total worldwide annual turnover, whichever is higher. National authorities can also impose additional measures, including temporary bans on individuals carrying out managerial responsibilities at the entity in the most serious cases.

Where transposition stands

NIS2's original transposition deadline for EU member states was 17 October 2024, but implementation has been uneven. As of mid-2026, the large majority of member states have enacted national implementing legislation, while a smaller group — including Ireland — is still finalising its own NIS2 law. In Ireland, the General Scheme for the Network and Information Security Bill was published in 2024, with the National Cyber Security Centre (NCSC) and the Central Bank of Ireland (for financial-sector-adjacent entities) expected to act as competent authorities once the legislation is enacted. Until national law is in force, the original NIS Directive continues to apply to previously designated operators of essential services.

The practical implication for finance teams: don't wait for the exact transposition date in your jurisdiction before starting readiness work. The underlying obligations are settled at EU level, and boards are increasingly expected to demonstrate progress regardless of where national legislation currently stands.

What finance and compliance teams should do now

  • Confirm whether your organisation, or a major client, falls within an NIS2-covered sector, and if so, whether it's classified as essential or important.
  • Map ICT and cyber risk governance against the NIS2 minimum measures listed above, and identify gaps.
  • Review third-party and supply chain risk assessments to capture NIS2-regulated suppliers.
  • Build incident reporting timelines (24-hour early warning, 72-hour full notification) into existing risk and business continuity procedures.
  • Ensure board-level training and sign-off processes exist for cyber risk oversight, mirroring what many finance teams have already built for DORA.

FAQ

Does NIS2 apply to financial services firms?
Generally no — DORA takes precedence for banks, insurers, investment firms and other financial entities already regulated under DORA. NIS2 is more relevant to finance professionals working in, or advising, other in-scope sectors.

Is NIS2 already in force?
The directive's obligations are settled at EU level, but national transposition has been uneven. Some member states have national law in force; others, including Ireland, are still finalising theirs as of 2026.

Who is accountable for NIS2 compliance?
Management bodies — boards and senior leadership — are directly accountable and can face liability, not just IT or security teams.

Cyber security and operational resilience regulation is moving fast, and NIS2 is one more example of it becoming a board and finance-function issue rather than a purely technical one. Learnsignal's CPD courses cover the regulatory landscape finance professionals need to stay current on, including operational resilience and governance topics like those covered in our guide to cyber resilience fundamentals.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience helping students advance their professional careers.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Learning Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans