Who Must Comply
NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity rulebook for essential and important entities. If your agency builds or maintains digital infrastructure for clients — hosting, e-commerce, SaaS, networks — you are likely in scope either directly or through your clients' supply-chain obligations under Article 21(2)(d). Member states had to transpose the directive by October 17, 2024, and enforcement is active across the EU in 2026.
🏢 Essential Entities
Energy, transport, banking, health, digital infrastructure, public administration. Stricter supervision, fines up to €10M or 2% of global turnover.
📦 Important Entities
Postal services, waste management, chemicals, food, manufacturing, digital providers. Fines up to €7M or 1.4% of turnover.
🔗 Supply Chain
Even if your agency is too small to be in scope itself, essential-entity clients must verify YOUR security under Article 21(2)(d). A completed checklist is your proof.