HS05

NIS2, the directive no one has read but that binds you anyway

A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.

LawCyberComplianceAugust 19, 2026

The director rereads the clause, puzzled. NIS2, to them, is a European matter reserved for power grids, banks, large operators, not their logistics or spare-parts firm. They are wrong, and the reason for their error is the most interesting thing in the whole text. Because NIS2 does not reach them through the door they were watching, that of a direct and named obligation, but through two doors they did not expect, that of their largest client now made responsible for their security, and that of their own personal liability as a director. The directive no one has read is quietly rewiring the map of responsibility across the entire European economy, and it does so without fanfare, through contract clauses and duties attached to persons.

Here is the thesis. NIS2 is famous for what it seems to be, a technical cybersecurity directive, and decisive for what it really is, a redistribution of legal responsibility. Its three real innovations are not security measures, they are institutional, it massively widens the perimeter of covered entities, it makes senior managers personally and legally accountable for cyber-risk governance, and it makes every covered entity responsible for the security of its supply chain. The directive therefore reaches far beyond its named targets, it travels along contracts and climbs up to individual people. You do not need to be designated by NIS2 to be its prisoner, it is enough to be the supplier of an entity that is, or to hold a seat on the board.

From the fortress to the whole town

The first lever is the widening of scope. The first directive, NIS1, had fenced off the obvious fortresses, energy, water, banks, large vital operators. NIS2 fences off the whole town around them. It replaces a narrow list with a vast set of sectors labelled essential or important, and captures the medium and large entities within them, pulling into its field thousands of companies that never saw themselves as critical infrastructure. A component maker, a digital-service provider, a logistics or food-industry player can now find itself covered, when it thought itself safe by its modest size or its ordinary sector. The change of scale is abrupt, one moves from a few hundred supervised operators to tens of thousands of bound entities.

The text moreover introduces a subtle gradation between two categories, essential entities and important entities, which are not supervised in the same way. The former are subject to proactive control, the authority being able to check their compliance without waiting for an incident, whereas the latter are only checked after the fact, once the suspicion of a breach has arisen. This distinction draws a pyramid of vigilance, the more an entity is judged critical, the sooner the regulator's eye settles on it. But the border between the two categories sometimes stays blurred, and many companies discover late which side they fall on, with appreciably different obligations and intensity of oversight at stake.

The second lever is the deepest, the personal liability of managers. NIS2 requires management bodies to approve and oversee cyber-risk-management measures, provides that they may be held personally liable, and mandates that they be trained. Cyber ceases to be something delegated to the IT department and forgotten, it becomes a duty attached to the very person of the manager, backed by sanctions. It is this lever that truly changes behaviour, because a fine on the company is merely a cost, whereas a liability that weighs personally on the manager is a threat. One does not govern a risk the same way when it is one's own estate, not the company's, that answers for negligence.

This liability comes with very concrete obligations that make their weight felt day to day. NIS2 requires significant incidents to be notified within tight deadlines, an early warning within a few hours, a full notification in the days that follow, which presupposes having put detection and procedures in place beforehand. The sanctions are not symbolic, they can reach substantial fines calculated on worldwide turnover, and some transpositions provide for the temporary suspension of managers from their functions. The regime then ceases to be a mere exhortation to prudence and becomes a framework with teeth, where a breach is paid in money and sometimes in career. It is this materiality of the sanctions that turns a paper obligation into a real constraint.

NIS2 does not necessarily reach you because it names you. It reaches you because your client is now responsible for your security, and because your director answers personally for it. The directive spreads less through the regulator's sanction than through the contagion of contracts and the weight placed on individual people.

Contagion through contracts

The third lever is the one that explains the letter our director received, the supply-chain cascade. Covered entities must manage the cyber risk of their suppliers, so they push this obligation downward, by contract. Your client, now held responsible for your security as part of its own compliance, contractually forces you to fall into line. The law then spreads not through the regulator's action, but through contagion across commercial relationships, reaching companies the authority never directly targeted. A directive that does not name you ends up binding you, passed from link to link by each party's fear of being held responsible for its neighbour's weaknesses.

The underlying reason for this cascade lies in a lesson learned the hard way, an attacker does not always enter through the front door of its target, it often comes through a smaller, less protected supplier, whose access to the systems of the large principal becomes a Trojan horse. Securing the fortress is useless if the delivery driver who crosses its gates each day leaves their own wide open. NIS2 draws from this a logical consequence, an entity's security is worth that of the weakest link in its chain, so forcing each party to watch its suppliers is not a bureaucratic whim but the legal translation of a technical reality. Responsibility spreads because vulnerability was already spreading, and the law merely follows the path the attacks were already taking.

This mechanism of diffusion is formidably effective, because it turns every large compliant company into an agent transmitting the norm. Where a regulator would have to inspect tens of thousands of entities one by one, an impossible task, the market does it by itself, each principal demanding of its suppliers what the law demands of it. Compliance thus flows down the chain like a current, from the largest to the smallest, all the way to the workshops and providers who have never opened the Official Journal of the Union. It is a form of private normative power, where legal constraint travels through the commercial channel rather than the administrative one.

This diffusion finds an unexpected relay, insurance. As NIS2 compliance becomes a market expectation, cyber insurers seize on it as an underwriting criterion, questioning the company about its governance, its measures, the training of its managers. Falling into line then becomes not only a demand of one's client, but a condition for obtaining or keeping cyber cover at a reasonable price. The directive that insures nothing ends up shaping the insurance market, because the insurer rewards the compliant and penalises the negligent. Law and insurance reinforce each other, each making the other more binding, and the company finds itself held by two threads at once, that of the law and that of its policy.

Genius or overreach

The debate is open, and both readings hold. The first sees an elegant and overdue response. Cyber is a systemic, networked risk, it spreads through networks and dependencies, so a law that distributes responsibility across the network and places it on decision-makers matches the very shape of the problem. The contractual cascade achieves, through private agreements, what the regulator could never impose entity by entity, and personal liability finally forces managers to treat cyber as a governance issue, not a technical budget line.

The opposite reading is harsher. NIS2 imposes heavy and costly obligations on small and medium enterprises that lack the resources of the banks the model was designed around, at the risk of breeding a compliance-paperwork industry that produces documents rather than real security. The threat of personal liability can deter competent people from accepting a board seat, or freeze decision-making through excess caution. To this is added fragmentation, a directive is transposed differently in each member state, so a pan-European company faces twenty-seven slightly divergent versions of the same law, several states having in fact transposed late. And a subtler effect, by pushing liability onto managers and suppliers, the law could improve security on paper while concentrating real cyber capability in the few large players who can afford it, smothering the small ones it claims to protect.

A final word on the reality of implementation, because it tempers the picture. NIS2 was to be transposed into the law of each member state by the autumn of 2024, but several countries fell behind, so the real landscape stayed uneven for a long time, some companies fully bound, others still waiting for their national law. This multi-speed implementation creates a paradoxical legal insecurity, the obligation exists at the European level but its concrete enforceability varies from one country to the next, and a single cross-border company can find itself already bound here and still reprieved there. The gap between the ambition of the text and the slowness of its national translation is itself a lesson, a directive only becomes truly real the day twenty-seven parliaments have made it their own, and that day never arrives everywhere at once.

Who will answer on the day of the breach

NIS2 is the moment cybersecurity stopped being a line in the IT budget and became a question of legal responsibility, that of who will answer the day the network goes down. The directive no one has read is quietly redrawing the map of responsibility in the European economy, not through spectacular enforcement, but through clauses in contracts and duties on managers. It moves cyber from the technical basement to the boardroom, and from the company's balance sheet to the estate of individuals.

The question it leaves open is therefore not whether you are compliant, it is who will be held responsible, personally, the day the breach occurs. And that question now travels toward people who have never read a single line of the law that names them, carried not by the regulator but by the letter from their largest client. The obscure directive has quietly become one of the most decisive texts for any European leader, precisely because it acts on the one who ignores it.

This shift moreover goes beyond cyber alone, it heralds a deeper trend, the one moving countless risks from the company's balance sheet toward the personal liability of those who run it. After cyber will come climate, artificial intelligence, social compliance, each with its duty of vigilance and its threat of individual exposure. NIS2 is thus only an early case of a wider movement, the personalisation of responsibility, where one stops sanctioning abstract structures to hold named individuals. It is a powerful way to change behaviour, because nothing concentrates a leader's attention like the idea that their own name sits at the foot of the act, and this logic will only spread in the years to come.

Further reading, the text of the NIS2 directive itself, ENISA's guidance on its implementation, and the national transposition trackers published by authorities and specialist firms make it possible to measure the true reach of the regime.

In echo, AlgoPolis foundational article 08, NIS2 and the new architecture of cyber responsibility, details the scope, sanctions and obligations of the text.

Related articles
08

The NIS2 Directive and Its Insurance Implications

NIS2 does not mention insurance even once, and it does not directly regulate insurers. Yet by raising the cybersecurity baseline of fifteen to twenty thousand French entities and by making executives personally liable, this directive profoundly reshapes the risk that insurers underwrite.

NIS2Cyber Insurance
Read →
05

Ransomware as a Financial Asset

Underground economy, ransom markets and insurer pricing: how ransomware became a structured industry whose growth is partly financed by cyber insurance payouts.

CyberRansomware
Read →
07

Solvency II Tested by Cyber Risk

Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.

Solvency IICyber Risk
Read →
Editorials you might enjoy
HS04

The day Solvency II met a ransom

The regulator asks a simple question, how much money must you hold to survive your worst year in two centuries. For a book of hurricanes, the actuary answers without flinching. For a book of ransomware, the room falls silent.

Solvency IICyber Risk
Read →