NIS2 has generated more vendor marketing than almost any other piece of EU legislation, and most of it is wrong in the same two ways: it implies you can buy compliance, and it never says what the Directive actually requires.
This is the version with the article numbers in it. Every requirement below is quoted from Directive (EU) 2022/2555 itself, so you can check it rather than take anyone's word for it — including ours.
Two things to establish before the detail. First, this is not legal advice; NIS2 is a directive, which means it takes effect through national law, and the details differ by member state. Second, no supplier can make you compliant. What a supplier can do is be a manageable part of your supply chain rather than an unmanageable one, and that distinction is written into the Directive.
The dates
- Member states had to transpose NIS2 into national law by 17 October 2024, and apply it from 18 October 2024.
- The previous NIS Directive (EU) 2016/1148 was repealed on 18 October 2024.
- Transposition has been uneven. A minority of member states met the deadline, the European Commission opened infringement proceedings against those that did not, and national implementation continues to land at different times with different specifics.
The practical consequence: "is NIS2 in force?" is the wrong question. The right one is "what has my member state enacted, and when does it bite for my sector?"
Who is in scope
Two tests, applied together: sector and size.
Sector
Annex I lists sectors of high criticality. Section 8, Digital infrastructure, covers:
- Internet Exchange Point providers
- DNS service providers, excluding operators of root name servers
- TLD name registries
- Cloud computing service providers
- Data centre service providers
- Content delivery network providers
- Trust service providers
- Providers of public electronic communications networks
- Providers of publicly available electronic communications services
Section 9, ICT service management (business-to-business), adds managed service providers and managed security service providers.
Read that list again if you run infrastructure. Cloud computing service providers and data centre service providers are named explicitly. So are managed service providers. If you host, operate or manage infrastructure for others in the EU, the sector test is not a grey area.
Size
Article 3 applies a size-cap rule tied to Commission Recommendation 2003/361/EC. In broad terms, entities in a listed sector are in scope once they reach medium-sized enterprise status — 50 or more employees, or annual turnover / balance sheet above €10 million — with entities exceeding the medium-sized ceilings (250+ staff, or turnover above €50 million) classed as essential and most of the rest as important.
Some entity types are in scope regardless of size: qualified trust service providers, TLD name registries and DNS service providers are essential entities whatever their headcount.
The essential/important split does not change what you must do. It changes supervision intensity and maximum penalties.
What you actually have to do: Article 21
Article 21(2) requires an all-hazards approach and lists ten minimum measures. This is the list auditors will work from:
| # | Measure |
|---|---|
| (a) | Policies on risk analysis and information system security |
| (b) | Incident handling |
| (c) | Business continuity — backup management, disaster recovery, crisis management |
| (d) | Supply chain security, including relationships with direct suppliers and service providers |
| (e) | Security in acquisition, development and maintenance, including vulnerability handling and disclosure |
| (f) | Policies and procedures to assess the effectiveness of the risk-management measures |
| (g) | Basic cyber hygiene practices and cybersecurity training |
| (h) | Policies on the use of cryptography and, where appropriate, encryption |
| (i) | Human resources security, access control policies and asset management |
| (j) | Multi-factor or continuous authentication, secured voice/video/text communications, secured emergency communications, where appropriate |
Point (d) is the one that connects this to your hosting provider, and Article 21(3) sharpens it: entities must take into account "the vulnerabilities specific to each direct supplier and service provider and the overall quality of products and cybersecurity practices of their suppliers".
Your hosting provider is a direct supplier. Their practices are, by the Directive's own text, part of your risk assessment.
Reporting: Article 23's clock
For a significant incident, three deadlines:
| Stage | Deadline |
|---|---|
| Early warning | Without undue delay, and in any event within 24 hours of becoming aware |
| Incident notification | Without undue delay, and in any event within 72 hours |
| Final report | Not later than one month after the incident notification |
Twenty-four hours is the number that changes operational design. You cannot meet it with a process that starts with "someone notices something odd and messages the team channel". You need monitoring that detects, an on-call rotation that responds, and a pre-agreed decision path for who declares an incident notifiable and who files.
If an incident is ongoing at the final report deadline, a progress report is submitted instead, with the final report following once the incident is handled.
Penalties: Article 34
For infringements of Article 21 or Article 23, member states must provide for administrative fines of a maximum of at least:
- Essential entities — €10,000,000 or 2% of total worldwide annual turnover in the preceding financial year, whichever is higher.
- Important entities — €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher.
Note "at least": these are floors on what national law must allow, not caps. NIS2 also provides for management-level accountability, which is why this stops being purely an IT budget conversation.
What to actually ask a hosting provider
The NIS2 hosting question is not "is my provider certified" — no such certificate exists. It is "can I evidence this supplier's practices inside my own risk assessment", which is a documentation problem with a specific answer.
Concrete questions that map to Article 21 rather than to a marketing page:
- Are you yourself in scope, and as what? A provider that has worked out whether it is an essential or important entity has done the analysis. One that answers "we are NIS2 compliant" has not.
- What is your incident notification commitment to me, in hours? Your 24-hour clock starts when you become aware. If your provider takes three days to tell you, your clock is already broken. Get the number in the contract.
- What are your backup and disaster recovery arrangements — Article 21(2)(c) — and how are restores tested?
- How is administrative access to my infrastructure controlled? Article 21(2)(i) and (j): access control, asset management, multi-factor authentication.
- What is your vulnerability handling and disclosure process? Article 21(2)(e).
- Which entity, in which jurisdiction, am I actually contracting with? Sub-processors and group structure matter to a supply chain assessment.
- What do you log, for how long, and can I get it during an incident? A 72-hour notification needs evidence.
Ask these before you need them. Every one of them is answerable in writing by a provider that has done the work.
The part nobody sells you
Most of Article 21 is about your own organisation: risk policies, training, access control, cryptography, continuity testing, and the governance to keep them current. No hosting contract delivers those. Choosing infrastructure carefully removes one category of risk from your assessment; it does not remove the assessment.
Treat provider selection as one line item in the supply chain security control — point (d) of ten — and spend the rest of the effort where the Directive actually puts it.
Where NexonHost fits
For teams that need the operational side covered rather than staffed, infrastructure management covers monitoring, OS-level updates and network optimisation on managed infrastructure — the day-to-day work behind points (b), (c) and (e) rather than a compliance certificate.
On the infrastructure itself: NexonHost is a Romanian company operating in twelve cities across eleven countries, so dedicated servers, virtual servers and colocation can be placed in a named EU member state where a residency commitment requires it.
Related reading: practical Linux hardening for a VPS, essential security guidelines for initial server configuration, and choosing the best firewall for a Linux server.
Sources
All Directive citations are from the consolidated text of Directive (EU) 2022/2555 on EUR-Lex: Annex I (sectors), Article 3 (essential and important entities), Article 21 (risk-management measures), Article 23 (reporting), Article 34 (administrative fines). Size definitions are from Commission Recommendation 2003/361/EC. Transposition status: European Commission, NIS2 Directive.




