Suspect a breach? Report it immediately — response within 1 hour.Report an incident

NIS2 (EU Directive)

European directive on the security of network and information systems, imposing cybersecurity obligations on essential and important entities within the European Union.

Last updatedAugust 22, 2026

Who's affected

Directly: essential and important entities established in the European Union, by sector and size, as defined by each member state upon transposition. Indirectly: non-EU suppliers and subcontractors — notably Moroccan and African exporters — whose European customers pass down security requirements contractually.

What the framework requires

NIS2 requires covered entities to manage cybersecurity risk, notify significant incidents, and meet supply chain security obligations. These are passed down to non-EU suppliers in the form of security questionnaires, contractual clauses, or requirements to align with recognized frameworks, as requested by the European client.

Compliance steps

01

Identify whether your European clients fall within a sector covered by NIS2

02

Inventory the security questionnaires and contractual requirements already received

03

Perform a gap analysis against commonly requested requirements (risk management, incident management, supply chain security)

04

Structure a standard response to supplier security questionnaires

05

Upgrade internal controls identified as insufficient

Common mistakes

  • Responding to each questionnaire case by case without a structured approach
  • Assuming NIS2 does not concern the company simply because it is established outside the EU
  • Ignoring cascading requirements passed down by a European client until the contract is terminated

Cross-mapping to other frameworks (UCM)

FrameworkCovered
iso-27001
rgpd

Downloadable resource

Get the checklist by email.

Frequently asked questions

Is my Moroccan company directly subject to NIS2?

No, NIS2 regulates entities established in the European Union. A Moroccan or African company is not directly regulated but may receive security requirements passed down by its European clients that are subject to the directive.

Why is my European client sending me a security questionnaire?

Because NIS2 requires regulated entities to manage the security risks of their supply chain, including those linked to suppliers located outside the European Union.

What should I answer in a supplier security questionnaire?

A structured response consistent with your actual controls. A downloadable supplier security questionnaire response template helps prepare a reusable baseline for the requests you receive.

Which sectors are most affected by this cascading requirement?

Exporting sectors closely integrated into European value chains: automotive, aerospace, textile, agri-food, and offshoring.

Does NIS2 replace GDPR?

No. NIS2 addresses the security of network and information systems, while GDPR addresses the protection of personal data. The two frameworks are complementary and can both be passed down to a non-EU supplier.