Two European regimes arrive within three months of each other. Member states must have transposed the second network and information security directive into national law by 17 October, which is fifteen weeks from today. The digital operational resilience regulation begins applying to financial entities on 17 January next year. Both entered force in January last year, which means the eighteen-month grace period everyone treated as distant has become a quarter. The interesting question for an organisation outside Europe is not what the rules say. It is who will ask you for what, and when.
You will not be audited against the directive. You will be audited against whichever national law your customer's regulator enforces — and there are going to be twenty-seven of them
That distinction is the single most useful thing to understand before spending money this quarter.
The two instruments do different jobs
The directive sets out who must have security governance: sectors deemed essential or important, above certain size thresholds, with obligations covering risk management measures, incident reporting, supply chain security and accountability at management level. The regulation is narrower and sharper. It applies to financial entities and, crucially, reaches into how they contract with technology providers — contractual content, a register of arrangements, concentration risk, exit planning and resilience testing. Together they push obligations downwards and outwards. A provider three steps removed from any European regulator will feel both, transmitted through commercial contracts rather than through supervision.
The transposition gap is this year's real problem
A regulation applies uniformly. A directive does not. With fifteen weeks remaining, a substantial number of member states have not completed their implementing legislation, and the drafts that exist diverge in ways that matter operationally: where the size and sector thresholds land, how entities register themselves, how much detail the incident reports require, the level of penalties, and how directly liability attaches to named managers. The practical response is not to build a programme against the directive text. It is to build the artefacts every plausible transposition will demand, then track the two or three national laws that actually govern your establishments and your largest customers. Organisations that built to the directive last year are now discovering that the national law adds registration duties and reporting detail the directive never specified.
The incident clock is the part that changes behaviour
The reporting structure is staged: an early warning within twenty-four hours of becoming aware, a fuller notification within seventy-two hours, and a final report within a month. The twenty-four hour early warning is the operationally difficult one, and not because it is short. It is difficult because it must be sent when you still know almost nothing, which means someone has to be authorised to notify a regulator on incomplete information, at any hour, without waiting for a management meeting. Most organisations have no such authority defined, and discover this during the incident. Fix it on paper now: who may send the early warning, what template they use, what the standing wording is for "we do not yet know", and who is told afterwards. It is an hour of work and it is the difference between a filed notification and a late one.
What the financial regulation actually demands from suppliers
Three things, in descending order of how much work they are. The register of information. Financial entities must maintain granular records of every contractual arrangement for technology services, including subcontracting chains and the functions supported. They cannot populate it without data from you, and the requests have already started. Contractual content. Specified provisions on access and audit rights, subcontracting, service levels, incident cooperation, termination and exit assistance. Where the service supports a critical or important function, the requirements are heavier. Resilience testing. Participation in the customer's testing programme, and for some entities threat-led penetration testing that may reach into provider environments.
Management liability moves the decision rights
Both regimes place accountability on management bodies rather than on a security function, including approval of risk measures and, in some transpositions, personal consequences. That changes who signs the risk acceptance, and it tends to change how quickly the unglamorous remediation gets funded. It is the most underrated mechanism in either instrument.
What a non-European supplier should assemble this quarter
A short control attestation you can send without a bespoke project each time. An incident notification commitment whose clock is tighter than your customer's regulatory clock. A current subcontractor list with locations and functions. A written exit plan with data return format and timescales. And evidence that you tested something recently. That pack answers most of what will be asked and costs far less than answering each customer individually for the next two years.
| Review track | Evidence to prepare |
|---|---|
| Direct entity scope | Sector, legal entity, establishment and relevant national implementation. |
| Customer commitments | Agreed incident, access, subcontracting and exit clauses. |
| Dependency records | Named service functions, subcontractors and locations. |
| Decision authority | Named notification authority, rehearsal and reusable evidence pack. |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
Practical Guidance for NIS2 Readiness Assessment
- Identify the national laws that actually apply to you, not just the directive.
- Inventory your European establishments against the sector annexes.
- Name who may file a 24-hour early warning and give them a template.
- Commit to notifying customers faster than their regulator requires.
- Maintain a subcontractor list with locations and supported functions.
- Write the exit plan including data format and timescales.
- Read the audit and inspection clauses before signing amendments.
- Assemble one reusable evidence pack instead of bespoke responses.
The Regional Angle
The first thing regional providers will notice is that this does not arrive as a questionnaire. It arrives as a contract amendment, frequently unilateral in tone, from a European bank or insurer that has been told to bring its arrangements into line before January. The clauses are not negotiable in the customer's mind and they are substantial: rights of access and on-site inspection extending to the customer's regulator, consent requirements before changing subcontractors, cooperation duties during incidents, and exit assistance obligations that can run for months at your cost. Regional providers with modest legal capacity tend to sign these unread because the account matters. Read three things before signing: what the audit and inspection right actually permits and who may exercise it, what the exit assistance obligation would cost you to perform, and whether your own subcontractors will accept the flow-down you have just promised. All three are priceable, and none of them can be renegotiated after signature. The second catches regional groups by surprise more often than the supplier question. Scope is determined by sector and by the size of the European establishment, not by where the group is headquartered. A Gulf-based group with a European logistics arm, a manufacturing subsidiary, a food distribution business or a digital infrastructure operation can find that entity directly in scope as an essential or important entity — with registration duties, incident reporting obligations and management accountability attaching to that company's directors, who are very often group executives sitting on the board from elsewhere in the region. Inventory every European establishment against the sector lists this quarter, and confirm who is formally on those boards, because the liability provisions in several transpositions land on named individuals rather than on the company alone. The third is a genuine conflict rather than an inconvenience. Granting a European financial customer and its supervisor rights of access and on-site inspection over a facility in this region can collide with local obligations — confidentiality undertakings on government and semi-government contracts, banking secrecy provisions where you also serve a local financial institution, and restrictions on exporting certain categories of data for review. A provider serving both a European bank and a regional public-sector client may be unable to honour both sets of commitments in full, and the discovery usually happens when the first inspection is scheduled. Get a written legal position before signing, and consider whether the European workload should sit in a segregated environment with its own access path, its own subcontractors and its own evidence trail. That is an architectural decision with a cost, and it is far cheaper taken now than retrofitted under an audit notice.
The objection worth taking seriously
The strongest objection is that this is a documentation exercise dressed as security policy. Europe has produced two enormous instruments whose principal observable effect will be consultancy spend, template policies, registers populated with data nobody reads, and contract clauses that no party intends to exercise. Meanwhile the intrusions that actually happen will keep happening through the same credentials and the same unpatched systems, entirely undisturbed by a register of information. A fair amount of that prediction will come true, and anyone who lived through the first two years of the general data protection regulation recognises the pattern. Three mechanisms are nonetheless different, and they are worth separating from the paperwork. The twenty-four hour early warning cannot be satisfied by documentation — it requires real detection, a real decision path and a named person with authority out of hours, which most organisations genuinely lack. The register forces financial entities to know their own dependency chains at a level of granularity they have never had, and knowing your dependencies is the precondition for every resilience decision that follows. And management accountability relocates the risk decision from the security function to the board, which is the only intervention that reliably changes what gets funded. An organisation that builds those three things and treats the rest as compliance overhead will end up materially more resilient, whether or not it has a European customer. That is a reasonable way to spend the next fifteen weeks.
Common Questions
Does the directive apply to companies outside Europe?
Not directly, in most cases. It reaches you through your European establishments if you have them, and through your customers' supply chain obligations if you do not.
Will the October deadline slip?
The deadline itself will not, but several member states will miss it, which produces a period of uneven national law rather than a general extension. Plan for divergence, not delay.
Do we need separate programmes for the two regimes?
No. The evidence overlaps heavily. Build one set of artefacts and map them to both, then handle the register and contractual requirements as the financial-specific addition.
What should we expect over the next twelve months?
Expect a wave of contract amendments from European financial customers between now and January, and expect the ones arriving in December to be the least negotiable. Expect national transpositions to keep landing through the autumn and into next year, with real differences in registration and reporting detail. Expect the first enforcement attention to fall on registration and reporting failures rather than on technical controls, because those are the easiest things for a supervisor to observe. And expect your largest customers to start asking for evidence rather than assurances, which is why the reusable pack is worth building before the requests arrive.
NIS2 Readiness Assessment — we map which national laws and customer clauses actually bind you, then build one evidence pack that answers all of them.
