EU cybersecurity directive

NIS2, your cloud provider and the supply chain

NIS2 widened the EU’s cybersecurity rules from a handful of operators to whole sectors of the economy, and it made your suppliers your problem. If you fall in scope, the security of the cloud provider you depend on is now something your management is accountable for, in writing. This page covers who NIS2 binds, the obligations that touch cloud specifically, and the supply-chain clause that makes provider choice a compliance decision.

This is general information about NIS2, not legal advice. Scope and obligations vary by national transposition; confirm yours with a qualified lawyer.

Who NIS2 binds, and in which tier

NIS2 (Directive (EU) 2022/2555) replaced the original 2016 NIS directive and had to be transposed into national law by member states in October 2024. It sorts organisations into "essential" and "important" entities across sectors including energy, transport, banking, health, digital infrastructure and public administration, generally catching medium and large organisations in those fields.

Two things about scope surprise people. First, cloud computing service providers are themselves named in scope as digital infrastructure, so your provider carries its own NIS2 duties. Second, being an "important" rather than "essential" entity does not exempt you; it mainly changes whether supervision is proactive or triggered after an incident. Fines are set as a percentage of global turnover, which is what moved this from an IT topic to a board topic.

The obligations that reach your cloud

NIS2 requires appropriate and proportionate technical and organisational risk-management measures (Article 21). The list is concrete: risk analysis, incident handling, business continuity and backups, access control, encryption, and, critically, supply-chain security. These are not optional annexes; they are the baseline the directive names.

Incident reporting is tight. For a significant incident, an early warning is due within 24 hours, a fuller notification within 72 hours, and a final report within one month. If your cloud provider suffers the incident that disrupts your essential service, you are the one on that clock, which means you need contractual visibility into their incidents, not just your own.

Supply-chain security makes provider choice a duty

Article 21 explicitly extends risk management to the security of the supply chain, including the relationship between an entity and its direct suppliers. In a cloud-hosted business, your most consequential supplier is your cloud provider. NIS2 turns evaluating that provider’s security, resilience and practices from good hygiene into a documented obligation.

This is where jurisdiction quietly re-enters. Supply-chain risk assessment includes the provider’s ability to withstand disruption and honour its commitments. A provider whose control plane, support and legal exposure sit outside the EU is a different risk profile from one that does not, and NIS2 expects you to have reasoned about it.

Management liability changes the stakes

NIS2 makes management bodies approve the risk-management measures and oversee their implementation, and it makes them liable for breaches (Article 20). In serious cases, this can reach personal accountability for senior managers. Compliance is no longer something the security team owns alone.

The practical consequence is that "we use a major cloud provider, so we are fine" is not a defence. The directive asks whether you assessed and managed the dependency. A migration onto infrastructure you can reason about, in a jurisdiction you understand, is one defensible answer to that question.

Where NIS2 is still moving

NIS2 is a directive, not a regulation, so the detail lives in national transposition, and member states did not all land on the same day or the same thresholds. Precisely which entities are caught, and some of the exact obligations, can differ between, say, France and Germany. Anyone telling you NIS2 means exactly one fixed checklist across the EU is overstating a directive’s uniformity.

The Commission has issued implementing acts sharpening the requirements for digital infrastructure and cloud providers, and guidance continues to arrive. The direction is settled; the fine print is still hardening. Treat the obligations here as the stable core and confirm national specifics for your member state.

Common questions about NIS2 and cloud

Is my cloud provider covered by NIS2, or am I?
Often both. Large cloud providers are in scope as digital infrastructure and carry their own NIS2 duties. If you are an essential or important entity, you are separately in scope and must manage the provider as part of your supply-chain security. The two obligations sit side by side; the provider’s compliance does not discharge yours.
Does using a compliant provider make me compliant?
No. NIS2 obligations attach to your organisation directly, including risk management, incident reporting and management oversight. A provider’s own compliance is an input to your supply-chain assessment, not a substitute for your own measures. You still have to show you assessed and managed the dependency.
What counts as a reportable incident under NIS2?
A significant incident, broadly one causing serious operational disruption or financial loss, or affecting others. The clock is a 24-hour early warning, a 72-hour notification and a one-month final report. If a cloud outage disrupts your essential service, it can trigger your reporting duty, so you need incident visibility from the provider written into the contract.