Blogpost, Video

NIS2: three legal considerations organisations should not overlook

NIS2: three legal considerations organisations should not overlook

Key takeaways

  • NIS2 qualification requires more than checking your sector. The organisation’s size must also be assessed, applying the relevant EU rules on linked and partner enterprises where necessary.
  • The distinction between essential and important entities is particularly relevant at the level of supervision and enforcement. The substantive cybersecurity obligations are broadly similar for both, but the supervisory regime and potential exposure differ.
  • The applicable national NIS2 law should be determined carefully. For certain digital service providers, the applicable law and relevant jurisdiction may follow the organisation’s main establishment rather than simply the country in which services are provided.
  • NIS2 extends into the supply chain.Organisations should review existing supplier contracts, update contractual templates and consider clear cybersecurity contracting guidelines.

NIS2 is not just an IT project

When organisations start preparing for the renewed Network and Information Security Directive, better known as NIS2, the focus often immediately shifts towards IT systems, cybersecurity controls and incident response.

Even though those elements are of course central to compliance, NIS2 also has an important legal and governance dimension.

Before implementing controls, organisations need to answer several fundamental questions: does NIS2 apply to us at all? If so, under which national law? And what does NIS2 mean for our relationships with suppliers?

Three legal considerations deserve particular attention.

1. Determine whether your organisation falls within scope

The first step is establishing whether the organisation qualifies as an entity falling within the scope of NIS2. Two elements are particularly important.

  • First, the sector in which the organisation operates must be considered. NIS2 covers a broad range of sectors regarded as critical or highly critical, including energy, transport, healthcare, digital infrastructure and certain digital services;

Second, organisations must consider their size. This assessment generally involves both the number of employees and relevant financial thresholds.

The size test can, however, be more complex than simply looking at the figures of the individual legal entity. European rules concerning partner and linked enterprises may require organisations to take into account data relating to parent companies, subsidiaries or other connected entities. Depending on the corporate relationship, those figures may need to be included proportionally or in full.

As a result, an entity that appears to fall outside NIS2 when viewed in isolation may nonetheless be caught by NIS2 once the wider corporate structure is considered.

Documenting this assessment is therefore advisable. A clear NIS2 qualification report can record why the organisation is (or is not) considered in scope and whether it qualifies as an essential or important entity. It also creates a useful basis for reassessment if the business, group structure or applicable legislation changes.

The distinction between essential and important entities does not fundamentally change the cybersecurity measures they need to implement. It does, however, affect the supervisory and enforcement regime, making the qualification relevant from a legal risk perspective.

2. Identify which national NIS2 law applies

NIS2 is an EU Directive. This means that its requirements are implemented through the national laws of the EU Member States.

It should in any case not automatically be assumed that, because an organisation is established or active in Belgium, the Belgian NIS2 legislation will necessarily govern all of its activities.

This question is particularly relevant for organisations operating across borders.

For certain providers, including cloud computing service providers and managed service providers, NIS2 provides for a form of one-stop-shop mechanism. In those circumstances, applicable law and relevant jurisdiction may be linked to the Member State in which the provider has its main establishment. In other cases, an internationally active organisation may need to comply with multiple local implementation acts implementing the NIS2 Directive.

For international groups and digital service providers, determining the applicable national regime or national regimes should therefore form part of the initial NIS2 legal assessment.

Getting this question right is important because the competent supervisory authority, registration requirements, enforcement process, practical compliance expectations and applicable deadlines may depend on the applicable jurisdiction.

3. Do not overlook supply-chain responsibility

A third important legal consideration concerns the organisation’s suppliers and service providers.

After all, NIS2 explicitly requires organisations to consider cybersecurity risks arising from their supply chain and their relationships with direct suppliers and service providers. Cybersecurity compliance therefore cannot stop at the organisation’s own perimeter.

From a legal perspective, this creates an immediate need to examine whether existing contractual arrangements provide sufficient protection. Organisations may need to review long-standing supplier agreements to determine whether appropriate cybersecurity obligations, incident notification requirements, audit rights or cooperation mechanisms are included.

The same exercise should be performed prospectively. Standard procurement agreements, IT contracts and supplier templates should be reviewed and, where appropriate, updated to make them NIS2-ready.

For organisations handling a large number of supplier negotiations, it can also be useful to develop or update a contracting playbook. This can define the organisation’s preferred cybersecurity clauses, minimum contractual requirements, acceptable fallback positions and circumstances in which additional legal or security review is required.

Turning NIS2 into a legal compliance framework

Successful NIS2 implementation thus requires more than technical remediation. Organisations should ensure that their cybersecurity programme is supported by a clear legal analysis, that ensures that the right measures are implemented at the right time.

That starts with three questions:

How does NIS2 apply to our organisation? Which national NIS2 regime governs us? And are our supplier contracts aligned with our cybersecurity responsibilities?

Answering those questions early provides organisations with a clearer view of their regulatory exposure and helps translate NIS2 from a purely technical exercise into a structured and defensible compliance framework.

 

Share this:

Written by

Marie Manhaeve

Marie Manhaeve

Bernd Fiten

Bernd Fiten

Hi! How can we help?

In need of internal privacy help or an external DPO? Reach out and we’ll look for the best solution together with you.

  • Solutions
  • Expertise
  • Knowledge
  • Careers
  • About