All systems operational Your IP: 216.73.216.190 info@cloudhosting.lv +371 66 66 29 69 Client area

← All questions

What is NIS2 and does it apply to your company?

NIS2 is the European Union's cybersecurity directive, and it turns "we really should look at security one day" into a legal duty with deadlines, a named responsible person and fines. If your company has 50 or more employees or more than 10 million euro on the books and works in one of the eighteen listed sectors, it almost certainly reaches you. Size on its own is not a trigger. Supplying a company that is in scope is not one either, but it still reaches you, through their contract rather than through the regulator.

The directive, and why its dates matter

The formal name is Directive (EU) 2022/2555. It replaced the 2016 NIS directive, which covered too few organisations and left member states free to interpret nearly everything. NIS2 entered into force in January 2023 and gave member states until 17 October 2024 to write it into national law.

Most missed that date, and the European Commission opened infringement proceedings against the majority of them before the end of 2024. Latvia was actually one of the early ones: the National Cyber Security Law took effect on 1 September 2024, supervision sits with the national cyber security centre under the Ministry of Defence, and the law set staged deadlines through 2025 for registering, appointing a person responsible for cybersecurity and documenting measures. Those dates differ by category, so check the act itself.

That distinction matters. The directive is the frame; what binds you is the national law implementing it, and your register, your supervisory authority, your reporting channel and your penalty scale are all national. Treat the regulation and your national act as the real text and let a lawyer settle the edge cases.

Essential or important, and the size test that pulls you in

NIS2 sorts organisations into two classes. The security obligations are the same for both. What differs is how hard you are supervised and how much you can be fined.

ClassWho lands hereSupervisionFine ceiling
EssentialLarge entities in the sectors of high criticality: from 250 staff, or turnover above 50 million euroProactive: inspections, audits and security scans with no incident at allAt least 10 million euro or 2 percent of worldwide annual turnover, whichever is higher
ImportantMedium sized entities in those sectors, from 50 staff or 10 million euro, plus medium and large entities in the other critical sectorsReactive: the authority acts on evidence, a complaint or an incidentAt least 7 million euro or 1.4 percent of worldwide annual turnover, whichever is higher

Size is not the whole test. Some organisations are in scope however small: DNS providers, domain registries, trust service providers, public electronic communications operators, the sole provider of a service critical to society in its country, much of central public administration. Financial entities follow DORA instead, so a bank does not do NIS2 twice.

The sectors, including the ones nobody expects

Annex I, high criticality: energy, transport, banking, financial market infrastructure, health, drinking water, waste water, digital infrastructure (data centre services, cloud, DNS, domain registries, internet exchanges, content delivery, trust services, public electronic communications), managed service and managed security providers, public administration and space.

Annex II is where boards get a surprise: postal and courier services, waste management, chemicals, the production, processing and distribution of food, manufacturing (medical devices, electronics, electrical equipment, machinery, vehicles), digital providers such as online marketplaces, search engines and social networks, and research organisations.

Read that again if you run a food plant, a courier firm or a waste operator. A 90 person meat processing company is an important entity, with the same ten baseline measures as a large hospital and only lighter supervision.

Out of scope, and dragged in anyway

Article 21 makes covered entities responsible for risk in their supply chain, including the security practices of each direct supplier. The regulator has no route to you if you are not in scope. Your customer does. It arrives as a questionnaire, then a contract annex: security requirements, short notification deadlines, audit rights, a termination clause. Losing the contract is not a fine, but it costs about the same.

The ten baseline measures

Article 21(2) lists what every covered entity must have, proportionate to its size and exposure, covering physical risk as well as digital:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity: backup management, disaster recovery, crisis management
  4. Supply chain security, including the security of direct suppliers
  5. Security in acquiring, developing and maintaining systems, including vulnerability handling
  6. Procedures to assess whether the measures actually work
  7. Basic cyber hygiene and cybersecurity training
  8. Policies on cryptography and, where appropriate, encryption
  9. Human resources security, access control and asset management
  10. Multi factor authentication, secured communications and emergency communication inside the company

Not one of them says "buy product X". They say: have a policy, be able to demonstrate that it works, keep the evidence. Most of the work is decisions and documents, and the technical half is ordinary cybersecurity hygiene that should have been in place anyway.

Reporting: 24 hours, 72 hours, one month

A significant incident is one that causes or could cause serious operational disruption or financial loss to you, or considerable damage to other people. When one happens:

  • Within 24 hours of becoming aware, an early warning to the CSIRT or competent authority, saying whether you suspect a malicious act and whether there could be cross border effect. A flag, not a report.
  • Within 72 hours, the notification: an initial assessment of severity and impact, plus indicators of compromise where you have them.
  • Within one month of that notification, the final report: root cause, mitigation applied, cross border effect. If the incident is still running you file a progress report, and the final one follows a month after you finish handling it.
  • An intermediate update whenever the authority asks for it.

Two traps. The clock starts when you become aware, not when you understand what happened, and 24 hours is very short if nobody knows who may notify at three on a Sunday morning. And if personal data is involved, the GDPR notification is a separate duty, to a different regulator, on its own 72 hour clock. One does not replace the other.

Management liability, the part directors miss

Article 20 is short and unpleasant. The management body must approve the cybersecurity risk management measures, oversee their implementation, and can be held liable for failing to do so. Directors have to take training themselves and see that staff get it too. Signing off a slide you have not read is exactly the behaviour the article exists to punish. For essential entities the authority can go further: where nothing else has worked, it can seek a temporary ban on an individual exercising management functions at chief executive or legal representative level. That is personal, not corporate.

What a hosting provider covers, and what stays with you

What a provider can ownWhat never leaves your company
Physical security of the room, racks and hardware accessRisk analysis and the security policy for your business
Network, filtering and a firewall in front of your systemsDeciding what is critical and how fast it must come back
Infrastructure monitoring, engineers around the clockYour own applications: code, updates, access rights, logging
Backup infrastructure and the ability to restoreProving a restore gives working data, and testing it
Data kept in the EU, in a data centre in Riga, under EU lawTraining, multi factor authentication, joiner and leaver process
A contract with security terms and a data processing agreementReporting to the authority, in your own name, on time

Roughly, a provider carries most of measure three and part of measure nine, and none of measures one, six and seven. Nobody sells compliance in a box.

A sane order to do this in

  1. Decide in writing whether you are in scope and as what. Keep the reasoning even if the answer is no, because someone will ask.
  2. Register with the national authority if the law requires it, taking the deadline from that law.
  3. Do the risk analysis first. Every other measure takes its priorities from it.
  4. Write the incident procedure with real names, real phone numbers and a path that works at night.
  5. Fix the boring things: multi factor authentication, backups you have restored from, patching, closing accounts of people who left.
  6. Put the management approval in the minutes, with a date on it.

Where we fit: we run our own data centre in Riga on our own network with engineers available around the clock, so the infrastructure part of your evidence stays in the EU and can be fixed in a signed agreement, and what that covers is on our NIS2 page. The risk register, the policies and the training stay with you.

Rather have us run it for you?
Single-domain certificate. One hostname, one trusted certificate.
Learn more

Ready to start?

Deploy in minutes or talk to an engineer about what fits your project.