NIS-2 requirements, established by Directive (EU) 2022/2555 and enforceable across EU member states from October 2024, define a binding set of cybersecurity obligations for a significantly wider group of organisations than its predecessor. For the IT manager, the directive is not an abstract policy document: it creates operational duties, audit trails and personal liability chains that reach into daily infrastructure decisions, including the choice of collaboration workspace.
What NIS-2 Actually Requires from IT Managers
NIS-2 Article 21 specifies the minimum technical and organisational measures that in-scope entities must implement. These are not aspirational guidelines but enforceable requirements that national supervisory authorities can audit.
The directive covers at least 18 sectors, including digital infrastructure, public administration, healthcare and postal services. ENISA estimates that more than 160,000 entities across the EU now fall within NIS-2 scope, compared to roughly 5,000 under the original NIS-1 Directive.
The mandatory controls under Article 21 include:
- Risk analysis and information system security policies
- Incident handling procedures, including detection, classification and containment
- Business continuity and crisis management
- Supply chain security, covering direct suppliers and service providers
- Encryption and cryptographic controls for data at rest and in transit
- Multi-factor authentication (MFA) and access control
- Human resources security and cybersecurity training
Crucially, Article 20 assigns personal accountability to management bodies: board members and senior executives can be held liable for failing to approve or oversee these measures. As the European Parliament and Council stated in Recital 93 of Directive (EU) 2022/2555: “Management bodies of essential and important entities must approve the cybersecurity risk-management measures taken by that entity, oversee its implementation and can be held liable for infringements.”
Incident Reporting: The 24-Hour Clock
One of the most operationally demanding NIS-2 requirements is the incident reporting timeline defined in Article 23.
| Stage | Deadline | Recipient |
|---|---|---|
| Early warning | 24 hours after awareness | National CSIRT or competent authority |
| Incident notification | 72 hours after awareness | National CSIRT, including initial impact assessment |
| Final report | 1 month after notification | National CSIRT, including root cause and mitigation |
Meeting the 24-hour early warning is only feasible if your infrastructure produces real-time, searchable logs. Platforms that aggregate logs in jurisdictions outside the EU, or that obfuscate event data behind proprietary interfaces, create a structural compliance gap precisely at the moment it matters most.
Which Controls Your Workspace Choice Covers
Not all collaboration platforms map equally to the Article 21 control list. The table below shows how platform characteristics align with specific NIS-2 requirements.
| NIS-2 Article 21 Requirement | Relevant Workspace Capability | Risk if Absent |
|---|---|---|
| Encryption at rest and in transit | End-to-end and post-quantum encryption layers | Data exposure, failed audit |
| Access control and MFA | Role-based permissions, enforced MFA | Unauthorised access, liability |
| Incident handling | Immutable audit logs, real-time alerting | Missed 24-hour deadline |
| Supply chain security | Sovereign or on-premise hosting, no third-country data transfer | GDPR/NIS-2 conflict |
| Business continuity | Backup, failover, data portability | Recovery failure, fine |
Platforms hosted under US jurisdiction, including hyperscaler-based productivity suites, introduce a structural tension: the US CLOUD Act can compel disclosure of data held by US-headquartered providers regardless of where the data physically resides. This conflicts directly with the NIS-2 obligation to maintain control over network and information systems and with GDPR Chapter V on third-country data transfers.
How to Build a NIS-2 Evidence Trail Through Your Workspace
Compliance is not a state but a documented process. NIS-2 supervisory authorities, including national CSIRTs and sector-specific regulators, will expect evidence rather than assertions. ENISA has noted that the security of network and information systems “is of vital importance to the functioning of our societies and economies,” framing documentation as central to the directive’s intent.
For IT managers, this means the workspace must actively produce compliance artefacts: access logs tied to individual identities, encryption key management records, backup completion reports and incident timelines. Nextcloud Enterprise, when deployed with sovereign hosting and a managed configuration, natively generates the majority of these artefacts. Qsentinel, as a managed Nextcloud Enterprise provider with Swiss and on-premise hosting options and post-quantum encryption, structures this evidence layer as part of the service rather than requiring custom integration.
The evidence trail for a NIS-2 audit should cover at minimum: who accessed what data and when, how encryption was applied and managed, how incidents were detected and escalated, and how the vendor supply chain was vetted. Each of these maps to a specific workspace configuration choice, not a policy document written in isolation.
FAQ
Who is personally liable under NIS-2?
NIS-2 Article 20 places direct accountability on management bodies, meaning board members and senior executives can be held personally liable for failing to approve or oversee cybersecurity measures. IT managers are operationally responsible for implementation and must be able to demonstrate it.
What is the NIS-2 incident reporting deadline?
Article 23 of Directive (EU) 2022/2555 requires a 24-hour early warning to the national CSIRT after becoming aware of a significant incident, followed by a full incident notification within 72 hours, and a final report within one month.
Does NIS-2 apply to my organisation if we are not in critical infrastructure?
NIS-2 applies to both “essential” and “important” entities across 18 sectors. Public administration, digital services, postal services and food supply chains are all included. ENISA estimates more than 160,000 EU entities now fall in scope, a dramatic expansion from NIS-1.
Which technical controls does NIS-2 explicitly require?
Article 21 lists mandatory measures including policies on risk analysis, incident handling, business continuity, supply chain security, encryption, access control and multi-factor authentication. All must be documented and demonstrably implemented, not merely described in a policy.
How does workspace choice affect NIS-2 compliance?
Your collaboration platform determines whether encryption, access logs, MFA and data residency controls are natively available and auditable. A platform hosted outside EU jurisdiction can create GDPR and NIS-2 conflicts, particularly around incident reporting timelines and third-country data transfers under GDPR Chapter V.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
