Summary: NIS-2 imposes binding cybersecurity and incident reporting obligations on a broad range of organisations across the EU. Choosing a workspace that natively supports encryption, access control and audit logging significantly reduces the compliance burden for IT managers and DPOs.

NIS-2 requirements, established by Directive (EU) 2022/2555 and enforceable across EU member states from October 2024, define a binding set of cybersecurity obligations for a significantly wider group of organisations than its predecessor. For the IT manager, the directive is not an abstract policy document: it creates operational duties, audit trails and personal liability chains that reach into daily infrastructure decisions, including the choice of collaboration workspace.

What NIS-2 Actually Requires from IT Managers

NIS-2 Article 21 specifies the minimum technical and organisational measures that in-scope entities must implement. These are not aspirational guidelines but enforceable requirements that national supervisory authorities can audit.

The directive covers at least 18 sectors, including digital infrastructure, public administration, healthcare and postal services. ENISA estimates that more than 160,000 entities across the EU now fall within NIS-2 scope, compared to roughly 5,000 under the original NIS-1 Directive.

The mandatory controls under Article 21 include:

  • Risk analysis and information system security policies
  • Incident handling procedures, including detection, classification and containment
  • Business continuity and crisis management
  • Supply chain security, covering direct suppliers and service providers
  • Encryption and cryptographic controls for data at rest and in transit
  • Multi-factor authentication (MFA) and access control
  • Human resources security and cybersecurity training

Crucially, Article 20 assigns personal accountability to management bodies: board members and senior executives can be held liable for failing to approve or oversee these measures. As the European Parliament and Council stated in Recital 93 of Directive (EU) 2022/2555: “Management bodies of essential and important entities must approve the cybersecurity risk-management measures taken by that entity, oversee its implementation and can be held liable for infringements.”

Incident Reporting: The 24-Hour Clock

One of the most operationally demanding NIS-2 requirements is the incident reporting timeline defined in Article 23.

Stage Deadline Recipient
Early warning 24 hours after awareness National CSIRT or competent authority
Incident notification 72 hours after awareness National CSIRT, including initial impact assessment
Final report 1 month after notification National CSIRT, including root cause and mitigation

Meeting the 24-hour early warning is only feasible if your infrastructure produces real-time, searchable logs. Platforms that aggregate logs in jurisdictions outside the EU, or that obfuscate event data behind proprietary interfaces, create a structural compliance gap precisely at the moment it matters most.

Let op: NIS-2 incident reporting obligations apply even when the incident originates with a third-party service provider. Your organisation remains responsible for notification. This makes supply chain security, including workspace vendor selection, a direct compliance variable.
See how Qsentinel solves this in practice.Start a 10-user pilot →

Which Controls Your Workspace Choice Covers

Not all collaboration platforms map equally to the Article 21 control list. The table below shows how platform characteristics align with specific NIS-2 requirements.

NIS-2 Article 21 Requirement Relevant Workspace Capability Risk if Absent
Encryption at rest and in transit End-to-end and post-quantum encryption layers Data exposure, failed audit
Access control and MFA Role-based permissions, enforced MFA Unauthorised access, liability
Incident handling Immutable audit logs, real-time alerting Missed 24-hour deadline
Supply chain security Sovereign or on-premise hosting, no third-country data transfer GDPR/NIS-2 conflict
Business continuity Backup, failover, data portability Recovery failure, fine

Platforms hosted under US jurisdiction, including hyperscaler-based productivity suites, introduce a structural tension: the US CLOUD Act can compel disclosure of data held by US-headquartered providers regardless of where the data physically resides. This conflicts directly with the NIS-2 obligation to maintain control over network and information systems and with GDPR Chapter V on third-country data transfers.

Let op: Choosing a workspace vendor is a supply chain security decision under NIS-2 Article 21(d). Document your vendor selection criteria and due diligence. Supervisory authorities are increasingly examining this during audits.

How to Build a NIS-2 Evidence Trail Through Your Workspace

Compliance is not a state but a documented process. NIS-2 supervisory authorities, including national CSIRTs and sector-specific regulators, will expect evidence rather than assertions. ENISA has noted that the security of network and information systems “is of vital importance to the functioning of our societies and economies,” framing documentation as central to the directive’s intent.

For IT managers, this means the workspace must actively produce compliance artefacts: access logs tied to individual identities, encryption key management records, backup completion reports and incident timelines. Nextcloud Enterprise, when deployed with sovereign hosting and a managed configuration, natively generates the majority of these artefacts. Qsentinel, as a managed Nextcloud Enterprise provider with Swiss and on-premise hosting options and post-quantum encryption, structures this evidence layer as part of the service rather than requiring custom integration.

The evidence trail for a NIS-2 audit should cover at minimum: who accessed what data and when, how encryption was applied and managed, how incidents were detected and escalated, and how the vendor supply chain was vetted. Each of these maps to a specific workspace configuration choice, not a policy document written in isolation.

FAQ

Who is personally liable under NIS-2?

NIS-2 Article 20 places direct accountability on management bodies, meaning board members and senior executives can be held personally liable for failing to approve or oversee cybersecurity measures. IT managers are operationally responsible for implementation and must be able to demonstrate it.

What is the NIS-2 incident reporting deadline?

Article 23 of Directive (EU) 2022/2555 requires a 24-hour early warning to the national CSIRT after becoming aware of a significant incident, followed by a full incident notification within 72 hours, and a final report within one month.

Does NIS-2 apply to my organisation if we are not in critical infrastructure?

NIS-2 applies to both “essential” and “important” entities across 18 sectors. Public administration, digital services, postal services and food supply chains are all included. ENISA estimates more than 160,000 EU entities now fall in scope, a dramatic expansion from NIS-1.

Which technical controls does NIS-2 explicitly require?

Article 21 lists mandatory measures including policies on risk analysis, incident handling, business continuity, supply chain security, encryption, access control and multi-factor authentication. All must be documented and demonstrably implemented, not merely described in a policy.

How does workspace choice affect NIS-2 compliance?

Your collaboration platform determines whether encryption, access logs, MFA and data residency controls are natively available and auditable. A platform hosted outside EU jurisdiction can create GDPR and NIS-2 conflicts, particularly around incident reporting timelines and third-country data transfers under GDPR Chapter V.

Hoe Qsentinel dit oplost

Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.

Start a 10-user pilot

Frequently asked questions

Who is personally liable under NIS-2?
NIS-2 Article 20 places direct accountability on management bodies, meaning board members and senior executives can be held personally liable for failing to approve or oversee cybersecurity measures. IT managers are operationally responsible for implementation.
What is the NIS-2 incident reporting deadline?
Article 23 of Directive (EU) 2022/2555 requires a 24-hour early warning to the national CSIRT after becoming aware of a significant incident, followed by a full incident notification within 72 hours, and a final report within one month.
Does NIS-2 apply to my organisation if we are not in critical infrastructure?
NIS-2 applies to both 'essential' and 'important' entities across 18 sectors. Public administration, digital services, postal services and food supply chains are all included. ENISA estimates more than 160,000 EU entities now fall in scope.
Which technical controls does NIS-2 explicitly require?
Article 21 of NIS-2 lists mandatory measures including policies on risk analysis, incident handling, business continuity, supply chain security, encryption, access control and multi-factor authentication. These must be documented and demonstrably implemented.
How does workspace choice affect NIS-2 compliance?
Your collaboration platform determines whether encryption, access logs, MFA and data residency controls are natively available and auditable. A platform hosted outside EU jurisdiction can create GDPR and NIS-2 conflicts, particularly around incident reporting and data localisation.