// ARTICLE

    NIS2 for firms: what changes

    Obligations, supply chain, expected evidence.

    NIS2 widened the net. Organisations that were comfortably outside NIS1 are now in scope, and so are many of the firms and providers that serve them. For a consulting firm or an MSP there are two angles: your own obligations, and what your clients will now demand from you.

    This is an overview, not legal advice. NIS2 is a directive, and the detail lives in each member state's transposition.

    Who is in scope now

    NIS2 splits regulated organisations into 'essential' and 'important' entities across a broad set of sectors, with size thresholds bringing in mid-sized companies that NIS1 ignored. Energy, transport, health and digital infrastructure are joined by manufacturing, food, waste, and managed service providers.

    The practical shock for many is the supply chain. Even if you are not directly regulated, a regulated client pulls you in through their own obligations.

    The obligations that touch technical work

    Article 21 sets out risk management measures: patching and vulnerability handling, network security, access control, encryption, incident handling, and testing the effectiveness of all of it. Incident reporting comes with tight clocks, an early warning within 24 hours of awareness.

    None of this is exotic to a security team. What changes is that it becomes a demonstrable duty, with management accountable, rather than a best-effort.

    You are somebody's supplier

    Supply chain security is explicit in the directive, which means your regulated clients will push requirements down to you. Expect questionnaires, expect to be asked for evidence, and expect it to become a condition of the contract.

    The firms that handle this well treat it as a sales advantage: they can produce the evidence on request instead of scrambling for it.

    What the evidence looks like

    No scan or report makes you 'NIS2 compliant', and anyone selling that is overreaching. What you can produce is demonstrable diligence: technical findings mapped to the relevant measures, remediated and re-tested over time.

    That is the honest artefact, a record that the technical measures were assessed and acted on, framed as evidence for an assessor rather than a certificate.