Why NIS2 affects your clients and your projects
NIS2 does not apply only to operators themselves — it extends to their supply chain. An essential entity (hospital, energy network, transport operator, public authority) must evaluate and document the security of every provider that touches its digital infrastructure. This includes the website host, the application platform and integrated SaaS tools. An agency delivering a project to a NIS2-subject client is therefore indirectly in scope: if it cannot provide documented guarantees about the chosen hosting, its client cannot satisfy its supply chain monitoring obligation.
What NIS2 concretely requires
- Ten minimum cybersecurity measures — including incident management, supply chain security, access control policies and encryption.
- Early warning within 24 h — any significant cyberattack must be notified to the competent authority within 24 hours of discovery.
- Full report within 72 h — detailed incident report to the national authority within three days.
- Documented supply chain audit — each critical supplier must be assessed and security commitments formalized contractually.
- Regular resilience testing — penetration tests, vulnerability assessments and continuity exercises at defined intervals.
- Governance at board level — executives can be held personally liable for failure to meet NIS2 obligations.
Who is affected: essential and important entities
NIS2 distinguishes two categories. 'Essential entities' (EE) operate in the highest-criticality sectors: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure. 'Important entities' (IE) cover adjacent sectors: postal services, waste management, manufacturing, chemicals, food, digital providers. The general threshold: any medium-sized entity (50 employees or EUR 10 M turnover) in these sectors is in scope. Smaller organizations may be included if they play a critical role in their sector. The first registration deadline for essential entities was set at 30 June 2026 in several Member States.
Preparing for NIS2 compliance
Identify whether you or your clients are in scope
Check the sector and applicable thresholds (headcount, turnover) for each client. National transposition texts specify the exact perimeters.
Inventory digital assets and suppliers
List systems, applications and third-party services that process critical data. For each supplier, document available security commitments: data location, certifications, incident procedures.
Set up incident management
Define a detection, escalation and notification circuit: who triggers the 24 h early warning, who drafts the 72 h report, which channel to use to notify the competent national authority.
Choose providers with documented commitments in the EU
Prefer hosting providers whose servers are located in the European Union, who can produce security documentation (ISO 27001 or equivalent) and whose contracts clearly define responsibilities in the event of an incident.
Test and verify regularly
Schedule penetration tests and security reviews at regular intervals. Retain the reports: they constitute the documentary evidence required during a NIS2 audit.
Your hosting provider is part of the NIS2 supply chain
For a NIS2-subject client, the hosting provider is not just any supplier. Server location in the EU, contractual security commitments and documented incident notification procedures count directly in its compliance audit. Choosing a provider able to produce these elements simplifies your client's process and strengthens your agency's position as a trusted partner.
NIS2: a constraint that builds client trust
NIS2 compliance is not purely a regulatory exercise. For agencies delivering projects to essential or important entities, it represents a concrete commercial argument: being able to demonstrate that the chosen hosting meets the standards required by the directive — data location, security, incident management — distinguishes a serious offer from a generic one. Entities subject to NIS2 need providers who understand their constraints. Penalties for non-compliance: up to EUR 10 M or 2% of global annual turnover for essential entities.