Compliance & Regulation7 min read

NIS2: what the directive requires from your hosted clients

The European NIS2 directive (EU 2022/2555) has been applicable in national law across most EU Member States since October 2024, with a compliance ramp-up period through summer 2026. It covers 18 sectors and approximately 160,000 entities across Europe. For agencies and service providers delivering websites or applications to clients in these sectors, the choice of hosting provider now falls within the scope of the supply chain audit.

Why NIS2 affects your clients and your projects

NIS2 does not apply only to operators themselves — it extends to their supply chain. An essential entity (hospital, energy network, transport operator, public authority) must evaluate and document the security of every provider that touches its digital infrastructure. This includes the website host, the application platform and integrated SaaS tools. An agency delivering a project to a NIS2-subject client is therefore indirectly in scope: if it cannot provide documented guarantees about the chosen hosting, its client cannot satisfy its supply chain monitoring obligation.

What NIS2 concretely requires

  • Ten minimum cybersecurity measures — including incident management, supply chain security, access control policies and encryption.
  • Early warning within 24 h — any significant cyberattack must be notified to the competent authority within 24 hours of discovery.
  • Full report within 72 h — detailed incident report to the national authority within three days.
  • Documented supply chain audit — each critical supplier must be assessed and security commitments formalized contractually.
  • Regular resilience testing — penetration tests, vulnerability assessments and continuity exercises at defined intervals.
  • Governance at board level — executives can be held personally liable for failure to meet NIS2 obligations.

Who is affected: essential and important entities

NIS2 distinguishes two categories. 'Essential entities' (EE) operate in the highest-criticality sectors: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure. 'Important entities' (IE) cover adjacent sectors: postal services, waste management, manufacturing, chemicals, food, digital providers. The general threshold: any medium-sized entity (50 employees or EUR 10 M turnover) in these sectors is in scope. Smaller organizations may be included if they play a critical role in their sector. The first registration deadline for essential entities was set at 30 June 2026 in several Member States.

Preparing for NIS2 compliance

01

Identify whether you or your clients are in scope

Check the sector and applicable thresholds (headcount, turnover) for each client. National transposition texts specify the exact perimeters.

02

Inventory digital assets and suppliers

List systems, applications and third-party services that process critical data. For each supplier, document available security commitments: data location, certifications, incident procedures.

03

Set up incident management

Define a detection, escalation and notification circuit: who triggers the 24 h early warning, who drafts the 72 h report, which channel to use to notify the competent national authority.

04

Choose providers with documented commitments in the EU

Prefer hosting providers whose servers are located in the European Union, who can produce security documentation (ISO 27001 or equivalent) and whose contracts clearly define responsibilities in the event of an incident.

05

Test and verify regularly

Schedule penetration tests and security reviews at regular intervals. Retain the reports: they constitute the documentary evidence required during a NIS2 audit.

Your hosting provider is part of the NIS2 supply chain

For a NIS2-subject client, the hosting provider is not just any supplier. Server location in the EU, contractual security commitments and documented incident notification procedures count directly in its compliance audit. Choosing a provider able to produce these elements simplifies your client's process and strengthens your agency's position as a trusted partner.

NIS2: a constraint that builds client trust

NIS2 compliance is not purely a regulatory exercise. For agencies delivering projects to essential or important entities, it represents a concrete commercial argument: being able to demonstrate that the chosen hosting meets the standards required by the directive — data location, security, incident management — distinguishes a serious offer from a generic one. Entities subject to NIS2 need providers who understand their constraints. Penalties for non-compliance: up to EUR 10 M or 2% of global annual turnover for essential entities.

Your infrastructure meets NIS2 standards

Servers in the European Union, documented security commitments, contractually defined incident procedures: the elements your NIS2-subject clients need to verify in their supply chain audit.

Need help?

Browse our help center and FAQ, or write to our team — support in French, English and Arabic.