More than a year and a half after the NIS2 transposition deadline, the Directive continues to reshape how organisations across Europe approach cybersecurity. For telecom operators, energy companies, banks, transport businesses, and digital infrastructure providers, NIS2 is no longer a distant regulatory milestone. It is an active compliance process that requires organisations to look not only at cybersecurity controls, but also at how well they understand and manage the infrastructure those controls are meant to protect.

A much broader regulatory scope

The original NIS Directive, adopted in 2016, applied to a relatively limited group of operators of essential services and digital service providers, identified under national frameworks.
NIS2 significantly expands that scope. The European Commission has estimated that around 160,000 entities across the EU may now fall within the Directive, covering sectors such as energy, telecommunications, banking, transport, and digital infrastructure — industries in which Suntech has operated for many years.

As a general rule, medium-sized and large organisations operating in sectors covered by NIS2 fall within its scope, although certain categories of entities are covered regardless of size.

The Directive also distinguishes between 'essential' and 'important' entities. Both groups must implement cybersecurity risk-management measures, but essential entities are subject to a more proactive supervisory regime.
This represents a major shift from the original NIS framework. Instead of relying primarily on individual designation of operators by Member States, NIS2 establishes broader criteria that determine which organisations are covered.

Implementation remains uneven across Europe

EU Member States were required to transpose NIS2 into national law by 17 October 2024. In practice, implementation has progressed at different speeds.
The European Commission launched infringement proceedings against a number of Member States that failed to complete transposition on time. On 8 July 2026, it referred France, Spain, Ireland, and the Netherlands to the Court of Justice of the European Union for failing to notify full transposition of the Directive. The Netherlands subsequently brought its national NIS2 legislation into force on 15 August 2026.

This staggered implementation means that organisations operating in several European markets still need to pay close attention to national requirements. NIS2 establishes a common European framework, but registration procedures, supervisory mechanisms, audit requirements, and enforcement practices are implemented through national legislation. Belgium, for example, has introduced a structured, conformity-assessment framework for essential entities, while supervisory models in other member states may operate differently.

For multinational organisations, NIS2 therefore requires not only understanding the Directive itself, but also monitoring how it is implemented in each jurisdiction in which they operate.

The gap between obligation and readiness

Even where legislation is already in force, organisations continue to face significant implementation challenges.
Recent industry research shows that many businesses are still working through requirements related to areas such as vulnerability management, incident response, business continuity, supply-chain security, and governance. The consequences of non-compliance can be substantial.

For essential entities, NIS2 provides for administrative fines of up to at least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher. For important entities, the corresponding thresholds are at least EUR 7 million or 1.4% of total worldwide annual turnover.
The Directive also makes cybersecurity a management-level responsibility. Management bodies are expected to approve cybersecurity risk-management measures and oversee their implementation.

This changes the organisational position of cybersecurity. It can no longer be treated solely as a technical responsibility of IT or security teams. It becomes part of corporate governance, operational resilience, and business risk management.

What does NIS2 require in practice?

At its core, NIS2 requires organisations to take a systematic approach to cybersecurity risk.
This includes incident handling, business continuity, disaster recovery, supply-chain security, vulnerability management, access control, and other measures designed to reduce the likelihood and impact of security incidents.

The Directive also introduces strict incident-reporting obligations and places greater emphasis on an organisation's ability to demonstrate that appropriate cybersecurity measures are actually in place. This makes traceability and reliable documentation increasingly important.
Essential entities are also subject to proactive supervision. Competent authorities must have the power to use measures such as inspections, security audits, and requests for information or evidence of implemented cybersecurity controls.

The practical implication is straightforward: organisations need to understand their environment well enough to demonstrate how critical systems and resources are managed, protected, and monitored.

Why infrastructure visibility matters?

Much of the discussion around NIS2 focuses on deadlines, reporting procedures, penalties, and formal compliance requirements.
However, effective cybersecurity risk management depends on something more fundamental: knowing what infrastructure an organisation actually has, and how its components are connected.

It is difficult to identify critical resources, assess dependencies, or understand the potential impact of an incident if information about network assets is scattered across multiple systems, outdated, or stored in an inconsistent form.
The same applies when responding to an incident. Security teams may need to determine which resources are affected, what services depend on them, and whether a problem in one part of the infrastructure can impact other systems.

Without accurate infrastructure data, these questions become considerably harder to answer.

The Role of Network Inventory

This is where Network Inventory Systems can support NIS2-related processes.
Solutions such as SunVizion provide a structured view of network infrastructure, including resources, locations, connections, configurations, and dependencies between different elements. This information can help organisations understand which assets support critical services, analyse relationships between network components, and assess the potential impact of failures or security incidents. Reliable inventory data can also support change management by providing visibility into how infrastructure evolves and helping teams maintain a consistent view of the current network state.

Network Inventory alone does not make an organisation compliant with NIS2. Compliance requires a much broader set of governance, security, organisational and technical measures. However, accurate and structured infrastructure information can provide an important data foundation for risk management, incident analysis, asset management, and audit-related processes.
For telecom operators, in particular, this can be especially valuable because physical resources, logical resources, services and network dependencies are often highly interconnected.

Compliance as a result of better infrastructure management?

NIS2 can be viewed purely as another regulatory obligation, but it also creates an opportunity to improve practices that are valuable, regardless of compliance. Accurate infrastructure information supports more than cybersecurity.
It helps organisations plan changes, understand dependencies between resources, respond to failures, analyse service impact, and maintain better control over complex network environments.

Organisations that have already invested in reliable Network Inventory and disciplined infrastructure management start from a stronger position. Instead of first determining what resources exist and how they are connected, they can focus on applying cybersecurity controls, improving monitoring, and strengthening risk-management processes.

In that sense, NIS2 reinforces a principle that has long mattered in infrastructure management: protecting a network effectively starts with understanding what it contains, where its critical components are, and how they depend on one another.