Who Must Comply
NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity rulebook for essential and important entities. If your agency builds or maintains digital infrastructure for clients — hosting, e-commerce, SaaS, networks — you are likely in scope either directly or through your clients' supply-chain obligations under Article 21(2)(d). Member states had to transpose the directive by October 17, 2024, and enforcement is active across the EU in 2026.
Essential Entities
Energy, transport, banking, health, digital infrastructure, public administration. Stricter supervision, fines up to €10M or 2% of global turnover.
Important Entities
Postal services, waste management, chemicals, food, manufacturing, digital providers. Fines up to €7M or 1.4% of turnover.
Supply Chain
Even if your agency is too small to be in scope itself, essential-entity clients must verify YOUR security under Article 21(2)(d). A completed checklist is your proof.