NIS2 Compliance Software
NIS2 (Directive (EU) 2022/2555) requires essential and important entities across the EU to strengthen cybersecurity risk management and incident reporting. STREAM helps in-scope organisations evidence compliance — scoped honestly for UK firms with no EU nexus.
NIS2 — the EU's Network and Information Security 2 Directive (Directive (EU) 2022/2555) — requires essential and important entities across the EU to strengthen cybersecurity risk management and incident reporting. STREAM helps in-scope organisations evidence NIS2 compliance: risk management, incident classification and reporting, and supply-chain oversight, in one auditable platform. UK-only firms with no EU operations are not directly bound — see below.
NIS2 frequently asked questions
What is NIS2?
NIS2 (Directive (EU) 2022/2555) is the EU's revised Network and Information Security directive. Unlike a directly-applicable EU regulation such as DORA, NIS2 is a directive: each EU member state transposes it into its own national law, so exact requirements and deadlines vary by country. The original transposition deadline was 17 October 2024. Most member states missed it, and implementation is still landing across the EU through 2026.
Does NIS2 apply to a UK-only firm?
Not directly. The UK is not an EU member state, so it does not transpose NIS2 — it has its own separate reform instead, the UK Cyber Security and Resilience Bill. A UK firm can still be drawn into NIS2's reach two ways: through an EU-based subsidiary or establishment that itself falls in scope under an EU member state's transposed law, or as a supplier whose EU essential or important-entity customers must apply supply-chain security requirements to their vendors. If your organisation is UK-only with no EU establishment or EU customer base, NIS2 itself does not bind you directly.
Is my organisation an essential or important entity under NIS2?
NIS2 splits in-scope organisations into two tiers. Essential entities are broadly larger organisations in higher-criticality sectors — energy, transport, health, digital infrastructure and public administration among them — and face proactive supervision. Important entities cover a wider set of sectors and smaller organisations within them, supervised reactively. Banking and financial market infrastructure sit outside NIS2 specifically because DORA covers them instead. The exact sector list and size thresholds sit in the Directive's Annexes — STREAM's entity classification workflow helps you work through this against your own footprint.
What are the penalties for NIS2 non-compliance?
Under Article 34, essential entities face fines of up to EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to EUR 7 million or 1.4% of turnover, whichever is higher. Management bodies can also be held personally liable, and national authorities can order temporary bans on individuals holding management roles. Because NIS2 is transposed nationally, the exact enforcement mechanism — and how actively it's being applied — varies by member state.
How does STREAM support NIS2 compliance?
STREAM gives you a structured risk register and control library mapped to NIS2's risk-management measures, a classification workflow to help establish whether you sit in the essential or important tier, and incident-management workflows built around NIS2's reporting timeline. The Vendor Management Hub extends the same risk view to your supply chain, so third-party obligations sit in the same evidence base as your own controls — alongside DORA, ISO 27001 and GDPR work, rather than as a separate exercise.
How STREAM supports NIS2 compliance
Risk management
A structured risk register and control library mapped to NIS2's risk-management measures, with the evidence trail an auditor or regulator can review directly.
Incident classification and reporting
Workflows built around NIS2's reporting timeline, so a significant incident moves through classification and notification without a manual scramble.
Supply-chain oversight
The Vendor Management Hub extends the same risk view to suppliers, so third-party obligations sit in one evidence base rather than a separate spreadsheet.
Work out where NIS2 actually reaches your organisation
Talk to us about entity classification, risk management and incident reporting under NIS2 — scoped honestly to what applies to you.
Request a demoSolve Your Challenges with STREAM®
Discover how STREAM®, our Cyber GRC platform, can help you address these challenges and streamline your compliance and risk management processes.