European directive on the security of network and information systems, imposing cybersecurity obligations on essential and important entities within the European Union.
Last updated — August 22, 2026
Directly: essential and important entities established in the European Union, by sector and size, as defined by each member state upon transposition. Indirectly: non-EU suppliers and subcontractors — notably Moroccan and African exporters — whose European customers pass down security requirements contractually.
NIS2 requires covered entities to manage cybersecurity risk, notify significant incidents, and meet supply chain security obligations. These are passed down to non-EU suppliers in the form of security questionnaires, contractual clauses, or requirements to align with recognized frameworks, as requested by the European client.
Deadlines
The directive is transposed into national law by each member state, with implementation and enforcement timelines specific to each country. There is no single deadline applicable across the entire European Union; the relevant timeline is that of the regulated entity's country sending you its requirements.
Sanctions
Sanctions applicable to directly regulated entities fall under the national transposition legislation of each member state. For a non-EU supplier, the risk is not a direct regulatory sanction but a commercial one: contract termination or non-renewal if the security requirements passed down by the European client are not met.
Identify whether your European clients fall within a sector covered by NIS2
Inventory the security questionnaires and contractual requirements already received
Perform a gap analysis against commonly requested requirements (risk management, incident management, supply chain security)
Structure a standard response to supplier security questionnaires
Upgrade internal controls identified as insufficient
| Framework | Covered |
|---|---|
| iso-27001 | ✓ |
| rgpd | ✓ |
Get the checklist by email.
No, NIS2 regulates entities established in the European Union. A Moroccan or African company is not directly regulated but may receive security requirements passed down by its European clients that are subject to the directive.
Because NIS2 requires regulated entities to manage the security risks of their supply chain, including those linked to suppliers located outside the European Union.
A structured response consistent with your actual controls. A downloadable supplier security questionnaire response template helps prepare a reusable baseline for the requests you receive.
Exporting sectors closely integrated into European value chains: automotive, aerospace, textile, agri-food, and offshoring.
No. NIS2 addresses the security of network and information systems, while GDPR addresses the protection of personal data. The two frameworks are complementary and can both be passed down to a non-EU supplier.