NIS2
NIS2: who is affected, which obligations apply and how tooling helps
NIS2 tightens cybersecurity obligations for thousands of companies across the EU — including personal liability for senior management. This overview sets out who is affected, what needs to be done and where an RMM covers the evidence obligations technically.
What NIS2 is — and why it matters now
NIS2 is the second EU directive on network and information security (Directive 2022/2555). It vastly widens the circle of companies under obligation, raises the required level of security and makes cybersecurity a documented leadership responsibility.
The practical effect: many companies that were not regulated under the first NIS Directive now fall within scope — often without knowing it. This overview sets out the obligations. It is professional guidance and does not replace legal advice.
Who is affected?
NIS2 distinguishes two categories, each tied to sector, company size and criticality:
- Essential entities — for example energy, transport, health, water, digital infrastructure, the financial sector.
- Important entities — for example postal and courier services, waste management, food, manufacturing, digital service providers.
As a rule, the decisive factor is the size threshold from medium-sized enterprises upwards. Self-assessment should take place early, because the obligations apply regardless of registration with an authority.
The four fields of obligation
NIS2 can be grouped into four blocks:
- Risk management. Technical and organisational measures in line with the state of the art: asset management, patch and vulnerability management, access control, encryption, backup and business continuity.
- Reporting obligations. Significant security incidents must be reported within tight deadlines — an early initial notification followed by more detailed reports. This presupposes working detection and documentation.
- Supply chain security. The security of suppliers and service providers also becomes a mandatory component. Anyone using service providers — such as an MSP — must assess their level of security.
- Governance and liability. Management bodies must approve and oversee the measures and undergo training. NIS2 provides for personal accountability of management.
How tooling and RMM carry the implementation
A substantial part of the NIS2 obligations is technical in nature — and that is precisely where an RMM comes in. It delivers the operational and the evidentiary layer at once:
- Asset inventory. A complete, up-to-date overview of all endpoints, servers and software — the prerequisite for any risk management.
- Patch and vulnerability management. Automated distribution and auditable evidence that critical updates have been applied.
- Incident detection and documentation. Telemetry across the estate that backs reports with data and makes deadlines achievable.
- Hardening and control. Enforceable configuration and access policies across all devices.
An RMM does not replace a security concept, but it is the tool with which a large share of the measures is implemented and evidenced.
Sovereignty as an additional NIS2 dimension
Precisely because an RMM reaches deep into the IT estate, its own operation is security-relevant. If this control layer sits with a provider under foreign jurisdiction, a supply chain and sovereignty risk arises — exactly the point NIS2 addresses.
OneLog is built for exactly this: remote monitoring and management (RMM) software from Germany (PioneerDesk GmbH, Zangberg, Upper Bavaria) that takes NIS2 requirements into account from the outset. It runs on German servers (STACKIT Sovereign Cloud), with no possibility of access by US providers (no US cloud exposure), is certified to ISO 27001:2022 and publicly discloses the safeguards for your data (technical and organisational measures, TOMs under Art. 32 GDPR). AI agents resolve defined incidents autonomously — shortening the response time that counts under the NIS2 reporting obligations. OneLog is validated under real operating conditions.
Next steps
Start with the scope assessment, then the gap analysis against the four fields of obligation. The NIS2 checklist offers a compact starting point; the spoke pages go deeper into implementation for MSPs and for patch management.
Frequently asked questions
- What is NIS2?
- NIS2 is EU Directive 2022/2555 on network and information security. It replaces the first NIS Directive, significantly widens the range of sectors covered and tightens the obligations on risk management, incident reporting and supply chain security.
- Who is affected by NIS2?
- NIS2 applies to “essential” and “important” entities in defined sectors above a certain size (as a rule, medium-sized enterprises and upwards). Classification depends on sector, size and criticality — a binding assessment requires a case-by-case review.
- What are the core obligations under NIS2?
- In essence: technical and organisational risk management measures, reporting obligations for significant security incidents, supply chain security requirements, and governance and liability obligations for management bodies.
- Is senior management personally liable?
- NIS2 requires management bodies to approve and oversee risk management measures and provides for personal accountability. Cybersecurity is thereby explicitly a board-level matter, not solely a task for IT.
- How does an RMM help with NIS2 implementation?
- An RMM provides the technical foundation for several NIS2 obligations: a complete asset inventory, verifiable patch management, hardening and incident detection across the entire IT estate — including auditable evidence.
See OneLog in your environment
Monitors and maintains your IT remotely and fixes many incidents automatically — hosted in the EU, with no dependency on US cloud providers. NIS2 requirements are built in from the start.