NIS2 does not mention insurance even once, and it does not directly regulate insurers. Yet by raising the cybersecurity baseline of fifteen to twenty thousand French entities and by making executives personally liable, this directive profoundly reshapes the risk that insurers underwrite.
The directive of 14 December 2022 known as NIS2, formally Directive (EU) 2022/2555, replaces the first directive of 2016 on the security of network and information systems, whose scope had proved too narrow and whose application too heterogeneous in the face of worsening threats1. The change of scale is dramatic. Where the first directive targeted only about five hundred operators of vital importance and essential services in France, NIS2 extends its obligations to eighteen sectors and to a population estimated by ANSSI at between fifteen thousand and twenty thousand entities2. Energy, transport, health, water, digital infrastructure and public administration, but also the manufacturing of critical products, food, waste management and research, now fall within the scope of a binding regulation.
NIS2 distinguishes two categories of regulated parties according to their criticality and their size. Essential entities, generally the large enterprises in the most sensitive sectors, are subject to ex-ante supervision, proactive and ongoing. Important entities, of intermediate size or belonging to less critical sectors, are controlled only ex post, in response to an incident or a suspicion of breach. The two categories nonetheless share the same substantive baseline of obligations, and it is this baseline that primarily interests the insurance analysis, for it defines the new security standard with which any covered organisation will have to comply.
The obligations of NIS2 rest on three structuring articles. Article 21 imposes a set of technical and organisational risk-management measures, ranging from supply chain security to strong authentication, by way of business continuity and encryption3. Article 23 sets a strict timeline for the notification of significant incidents, with an early warning within twenty-four hours, a detailed notification within seventy-two hours and a final report within one month3. Article 20, finally, places cybersecurity at the level of the management body, which must approve and oversee the measures, undergo training, and may see its personal liability engaged4. This last article is the tipping point that turns cybersecurity from a technical issue into a fiduciary responsibility of the board.
A common confusion deserves to be cleared up at the outset. NIS2 does include banking and financial market infrastructure among its sectors, and one might think that insurers are subject to it for their own cybersecurity. This is not the case. Article 4 of NIS2 provides that where a sector-specific act imposes at least equivalent obligations, those obligations apply instead. The financial sector has precisely such an act, the DORA Regulation on digital operational resilience, which expressly declares itself lex specialis for financial entities5. An insurer therefore falls under DORA, not NIS2, for its ICT risk management and its incident notification, as confirmed by national transpositions, such as German law, which explicitly refers to DORA for undertakings governed by the insurance supervision code.
This point of law, far from being a subtlety, entirely shifts the object of the analysis. If NIS2 does not govern the internal cybersecurity of insurers, then its insurance implications lie not on the side of the insurer as a regulated entity, but on the side of its policyholders. NIS2 acts on the insurance market not by imposing rules on the companies, but by transforming the risk profile of the tens of thousands of businesses those companies cover. It is a prevention regulation that, by ricochet, becomes a structuring force for the cyber insurance and directors' liability markets. The insurer is not the subject of NIS2, it is its indirect beneficiary and its interested observer.
By imposing a common baseline of security measures on tens of thousands of businesses, NIS2 redefines what insurers call cyber hygiene, that is, the minimum level of protection below which a risk becomes difficult to underwrite. Before NIS2, cyber insurers had to assess this level case by case, through underwriting questionnaires whose reliability depended on the policyholder's own declarations. The directive now creates an enforceable regulatory benchmark, a legal security standard against which compliance can be verified and, where appropriate, sanctioned by a public authority. For the insurer, this benchmark is a valuable instrument of risk selection, because it outsources part of the verification work to the national supervisor.
The effect manifests itself at two moments in the contract. At underwriting, NIS2 compliance tends to become a criterion of eligibility or a pricing factor, with insurers incorporating questions on essential or important entity status and on compliance with the measures of Article 21. At the claims stage, non-compliance with these measures may justify a reduction in indemnity, or even a forfeiture of cover, where the contract makes coverage conditional on maintaining a reasonable level of security, or where the failure that caused the loss results from a deliberate breach of legal obligations. Regulatory compliance and the insurance guarantee thus become entangled, the former becoming an implicit condition of the latter.
Beyond risk selection, NIS2 offers insurers a trove of data that cyber insurance has sorely lacked. The previous article in this series stressed how difficult cyber risk remains to price for want of a stationary history and homogeneous data. By requiring thousands of entities to document their security measures, to notify their incidents in a common format and to submit to audits, the directive generates a stream of standardised information that, once aggregated, could feed far finer pricing models. The technical frameworks published by ENISA in 2025, which map the measures of Article 21 onto existing standards such as ISO 27001, reinforce this convergence by equipping the market with a common language of security10.
This advantage nonetheless remains theoretical for as long as notification data stay confined to supervisors and subject to confidentiality. The insurance value of NIS2 will therefore depend largely on the extent to which this information, duly anonymised and pooled, can feed market knowledge. The issue is as much one of data governance as of law, and it will determine whether the directive remains a mere prevention instrument or becomes also an instrument for the measurability of cyber risk, the very lock that earlier articles identified as central to the insurability of cyber.
The most consequential innovation for insurance is undoubtedly Article 20, which elevates cybersecurity into an obligation of the management body itself. Members of management must approve risk-management measures, oversee their implementation and undergo dedicated training, failing which their personal liability may be sought. Several national transpositions attach individual sanctions to this principle. Germany provides for personal fines of up to five hundred thousand euros, and the directive authorises, for essential entities, a temporary ban on exercising management functions4. Cybersecurity thus leaves the operational sphere of the information systems officer to become a duty of care of the board.
This shift creates a direct exposure for directors' and officers' liability insurance, known as D&O. Until now, a cyber incident primarily engaged the liability of the company and fell under the cyber policy. With NIS2, a breach of governance obligations may now engage the personal liability of executives, the territory of the D&O policy. The two markets, long distinct, find themselves linked by a single event, a cyberattack revealing a supervisory shortcoming capable of triggering both the company's cyber cover and the D&O cover of its corporate officers. This dual exposure calls for a new contractual coordination between policies designed separately.
This convergence raises unprecedented questions of contractual interaction. Since a single loss may fall under both the company's cyber policy and the D&O policy of its executives, the allocation of the burden between insurers, the coordination of deductibles and the order in which covers respond become genuine matters of negotiation. The market has begun to respond through specific arrangements, with some D&O policies incorporating endorsements covering defence costs linked to cybersecurity investigations, and others, conversely, explicitly excluding regulatory breaches to avoid any overlap of cover. The maturity of the market will be measured by its ability to offer coherent coverage rather than a stack of policies with blurred boundaries, whose gaps the policyholder would discover only at the time of the loss.
NIS2 equips national supervisors with an arsenal of sanctions unprecedented in the history of European cybersecurity. Essential entities face a fine of up to ten million euros or 2 % of worldwide annual turnover, whichever is higher, and important entities seven million euros or 1.4 %6. Beyond fines, authorities may issue binding injunctions, order the cessation of non-compliant conduct or suspend certifications. The deterrent credibility of the apparatus rests on the effective, proportionate and dissuasive character of these sanctions, in line with the requirement laid down by the directive.
It is here that a structural limit of risk transfer is revealed. In French law as in several European jurisdictions, fines and sanctions of a punitive nature are in principle uninsurable, by virtue of a public-policy principle whereby insuring a sanction would neutralise its deterrent function7. A company cannot therefore, as a general rule, transfer to an insurer the cost of a NIS2 fine, any more than an executive can insure against a management ban. What remains insurable lies at the periphery of the sanction, namely defence costs, regulatory investigation costs and the civil liability that may flow from the incident, within limits and depending on the jurisdiction. Pure regulatory risk, for its part, remains the burden of the entity and its directors, which makes it a powerful spur to compliance.
This uninsurability produces a notable behavioural effect on management bodies. Unable to transfer this share of the risk, executives are induced to invest upstream in compliance itself, that is, in prevention, rather than in its mere financial coverage after the fact. NIS2 thereby achieves, through the route of uninsurability, what insurance pricing sometimes struggles to obtain, an alignment of management's interests with the effective reduction of risk rather than with its mere transfer.
This frontier has considerable practical significance. It means that insurance cannot serve as an escape from the discipline imposed by NIS2, and that the directive retains its incentive effectiveness whatever the insurance arrangements taken out. It also implies that policies must be drafted with great precision to distinguish the transferable share from the uninsurable share of the risk, on pain of disputes at the indemnification stage. The contractual sophistication of the cyber and D&O markets will necessarily be reinforced as a result.
The implementation of NIS2 suffers from a delay and a heterogeneity that complicate the task of insurers operating on a European scale. The transposition deadline set for 17 October 2024 was largely missed, leading the European Commission to open infringement procedures against most member states and to refer several of them to the Court of Justice in the spring of 20268. France, in particular, fell notably behind, transposing the directive through the bill on the resilience of critical infrastructure and the strengthening of cybersecurity, known as the Loi Résilience, presented to the Council of Ministers in October 2024, adopted by the Senate in March 2025, then extensively examined by the National Assembly, with promulgation expected in the summer of 20269. ANSSI has planned a gradual ramp-up, made of awareness-raising until 2026, targeted audits from 2026 and effective sanctions from 2027.
This fragmentation creates a difficulty specific to insurance. A group present in several member states finds itself confronted with a patchwork of obligations, thresholds, notification channels and competent authorities, each national transposition adding its particularities to the common baseline. For the insurer that covers such a group, assessing compliance risk becomes a multi-jurisdictional exercise, and uncertainty over the timetable for entry into force delays the adjustment of underwriting conditions. The directive, meant to harmonise, transitionally produces increased complexity.
The supply chain security obligation set out in Article 21 deserves particular attention in light of the themes already addressed in this series. By requiring each entity to master the cyber risk of its suppliers, NIS2 organises a contractual cascade of requirements that propagates along value chains. This logic is virtuous from a prevention standpoint, but it does not eliminate, and may even accentuate, the shared dependence on a small number of critical providers, the source of the systemic accumulation risk analysed in relation to the CrowdStrike incident. A single failure at a shared provider can simultaneously trigger breaches and losses across thousands of regulated entities, turning a distributed security requirement into a concentrated risk correlation.
At the close of this analysis, NIS2 appears as a regulation whose insurance effects are as profound as they are indirect. Without ever addressing insurers, who fall under DORA, it reconfigures the risk they underwrite, raises its hygiene floor, exposes its bad segments, extends the exposure toward the personal liability of executives and draws a clear boundary between what can be transferred and what must remain the burden of the regulated party. The directive does not create a market, but it silently redraws its contours. The real question of the coming years will be whether insurers will manage to turn this regulatory constraint into a knowledge advantage, by exploiting the new transparency it imposes to price more finely a cyber risk that, elsewhere in this series, has proved so resistant to measurement.
Insurance rests on an implicit probabilistic bet: that the past informs the future. Yet climate change invalidates precisely that assumption.
How an endpoint update becomes a global single point of failure and rewrites reinsurers' cyber PML models
Cognitive labor substitution, organizational hyper-flattening and the emergence of new operational risks
A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.