The EU's NIS2 Directive is changing how organizations think about cybersecurity. Unlike GDPR, which focuses on protecting personal data, NIS2 is designed to strengthen the resilience of critical and important organizations against cyber threats. It raises the baseline for cybersecurity across Europe by requiring organizations to implement stronger security measures, improve governance, and report significant incidents.

For many organizations, cloud services are central to daily operations. Whether you're storing sensitive files, collaborating with external partners, or managing business-critical information, the cloud provider you choose can play an important role in supporting your NIS2 compliance efforts.

Our latest webinar discussed the different aspects of NIS2 and what steps companies should take to prepare for compliance. You can now watch the webinar On-Demand below.

 

What is NIS2? Key objectives and considerations

NIS2, officially known as Directive (EU) 2022/2555, is the EU's updated cybersecurity framework designed to improve the security and resilience of organisations that provide essential and important services.

It replaces the original NIS Directive and introduces stricter requirements, broader sector coverage, stronger oversight, and increased accountability for leadership teams. The goal is to create a more consistent level of cybersecurity across EU Member States and improve how organisations prepare for, respond to, and recover from cyber incidents.

Who does NIS2 apply to?

NIS2 significantly broadens the scope of organisations covered compared to its predecessor. The Directive generally applies to medium-sized and large organisations operating in sectors that are considered important to society, public services, or the economy.

Essential entities

Examples include organisations operating in:

  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Healthcare
  • Drinking water and wastewater
  • Public administration
  • Digital infrastructure
  • Space services

Important entities

Examples include organisations operating in:

  • Postal and courier services
  • Waste management
  • Food production and processing
  • Chemicals
  • Manufacturing
  • Digital providers (online marketplaces, online search engines, and social networking service platforms)

The exact scope depends on factors including organisational size, sector, and the services provided.

How do cloud services fit into NIS2?

Cloud services play two different roles under NIS2. First, cloud service providers themselves may fall directly within the scope of the directive, depending on the services they provide.

Second — and for many organizations more importantly — cloud services are part of the organization's own digital supply chain. Choosing a secure cloud provider helps reduce operational and cybersecurity risks that NIS2 requires organizations to manage.

Using a cloud platform does not transfer responsibility for compliance to the provider. Organizations remain responsible for understanding their risks, implementing appropriate security measures, and ensuring that third-party vendors meet their security expectations.

Think of cloud security as a shared responsibility. Your provider secures the infrastructure and offers security capabilities, while your organization remains responsible for how the service is configured, how users access data, and how sensitive information is handled.

Security and risk management requirements under NIS2

NIS2 adopts a risk-based approach to cybersecurity. Rather than prescribing specific technologies, it requires organisations to implement measures that are appropriate for their risk profile and operations.

Risk management

Organisations must identify, assess, and manage cybersecurity risks that could affect their systems, services, and data. This includes understanding where sensitive information resides, who has access to it, and how it is shared both internally and externally.

Supply-chain security

One of the most significant additions under NIS2 is its focus on supplier and third-party risk. Organisations are expected to evaluate the security practices of software vendors, cloud providers, contractors, and other service providers that support critical business operations. Using a cloud provider does not eliminate responsibility for protecting sensitive information.

Incident response and business continuity

Organisations must be prepared to detect, respond to, and recover from cyber incidents. This includes having documented incident response plans, clear escalation procedures, defined responsibilities, and tested recovery processes. Business continuity planning is equally important to ensure critical services remain available during a disruption.

Access control and asset management

Knowing what assets need protection is fundamental to cybersecurity. Organisations should maintain visibility of their systems and ensure employees, partners, and contractors can access only the information necessary for their role. Granular access controls become particularly important when sensitive information is shared through cloud platforms.

Encryption techniques to safeguard data 

To comply with NIS2, organizations must ensure their workplace encryption methods offer a robust defense against cyber threats and breaches.

Reporting and governance obligations under NIS2

NIS2 is not only about implementing technical security controls. It also introduces significant governance responsibilities.

Cybersecurity is now a leadership responsibility

One of the biggest changes introduced by NIS2 is increased management accountability. Senior leadership and boards are expected to actively oversee cybersecurity risk management rather than treating cybersecurity as solely an IT responsibility. This includes:

  • Approving cybersecurity measures
  • Overseeing implementation
  • Ensuring sufficient resources are allocated to resilience initiatives
  • Understanding how cyber risks could affect business operations

Incident reporting requirements

When a significant cybersecurity incident occurs, organisations must notify the appropriate national authorities within required timeframes. Although implementation details vary slightly between Member States, reporting typically includes:

  • An initial early warning after a significant incident is detected
  • A more detailed notification as investigations progress
  • A final report outlining the incident's cause, impact, response actions, and lessons learned 

Effective reporting requires organisations to have visibility into incidents, clear internal escalation processes, and documented response procedures.

Demonstrating compliance

NIS2 is not simply about having security measures in place. Organisations should also be able to demonstrate that those measures are functioning effectively. This may include maintaining:

  • Security policies
  • Risk assessments
  • Incident response documentation
  • Training records
  • Supplier security reviews
  • Audit logs and activity records

What should organisations look for in cloud services under NIS2?

Choosing a cloud provider should involve more than evaluating storage capacity or productivity features. Organisations should consider whether providers support their security, governance, and compliance obligations.

End-to-end encryption

Encryption plays a key role in protecting sensitive information under NIS2. However, not all encryption approaches provide the same level of protection. Many cloud services encrypt data while it is stored and transmitted, but some providers may still retain the technical ability to access the content. End-to-end encryption adds an additional layer of protection by ensuring that only authorised users can decrypt and access files. This becomes especially important when sharing confidential documents with customers, suppliers, regulators, auditors, or external partners.

Granular access controls

Administrators should be able to define who can access information, from which devices, and under which conditions.

Audit trails and activity monitoring

Comprehensive activity logs should be available to help organisations investigate incidents, demonstrate accountability, and support compliance requirements.

Centralised security policy management

Consistent enforcement of security policies helps reduce risk across teams and locations. Features such as multi-factor authentication requirements, sharing restrictions, and device controls can help strengthen organisational resilience.

Secure external collaboration

Many cyber risks emerge when information leaves organisational boundaries. Cloud platforms should enable employees to securely share information with customers, suppliers, auditors, and partners without resorting to unsecured file-sharing tools or email attachments.

Resilience and recovery capabilities

Organisations should understand how providers approach backup, redundancy, incident response, and disaster recovery to support continuity requirements.

How NIS2 relates to DORA and the Critical Entities Resilience Directive

NIS2 forms part of a broader EU resilience framework. The Critical Entities Resilience (CER) Directive focuses on protecting organisations from a wide range of operational and physical threats. Meanwhile, the Digital Operational Resilience Act (DORA) establishes specific resilience requirements for financial institutions and their ICT providers.

Together, these frameworks encourage organisations to strengthen risk management, improve incident preparedness, and build resilience against disruption.

NIS2 compliance is about resilience

NIS2 represents a shift from reactive cybersecurity toward organizational resilience.

Rather than focusing solely on preventing attacks, the directive encourages organizations to understand their risks, strengthen governance, secure their supply chains, and prepare for incidents before they occur.

Cloud services are only one piece of that puzzle, but they are an important one. Choosing a provider with strong security controls, transparent operational practices, and features that support secure collaboration can help organizations build a stronger cybersecurity foundation while simplifying day-to-day security management.

Ultimately, NIS2 compliance is not about finding a cloud provider that promises compliance. It's about selecting technology that enables your organization to manage cyber risks effectively, demonstrate accountability, and remain resilient in an increasingly complex threat landscape.

Would you like to learn more about NIS2?

In our latest webinar, Koen Verbeke, CTO of Cranium and Turul Balogh, our Group Information Security and Data Protection Officer delved into the key elements of NIS2 and explore its far-reaching impact on organizations. They provided a comprehensive overview of the Directive and highlight the steps organizations need to take to achieve compliance.

What you will learn:

  • Understanding of the core objectives and requirements of NIS2, and which sectors and types of organizations are affected
  • What steps to take to assess and enhance your organization's cybersecurity posture, together with best practices for implementing NIS2 compliance measures
  • How to prepare for audits and reporting obligations under NIS2 and what role your management and staff will play in maintaining compliance

You can watch the webinar On-Demand below.