Understand NIS2: directly or indirectly covered?
With the NIS2 directive coming into force on July 1, 2025, Danish companies face new requirements for IT security and risk management. Many are aware that the directive includes companies in critical sectors, but fewer know that it can also affect businesses indirectly. Here we give you an overview of what it means to be directly or indirectly affected by NIS2.
What is NIS2?
NIS2 is an update of the EU Network and Information Security Directive. It aims to strengthen IT security across member states by setting requirements for companies in sectors such as energy, health, transportation and finance. The directive also sets out sanctions for non-compliance, including fines and injunctions.
Directly covered: If you are a key player
Companies directly covered by NIS2 typically operate in critical sectors where their operations are important to the functioning of society. Examples include:
- Energy suppliers
- Water utilities
- Financial Institutions
- Healthcare sector
These companies must meet a number of requirements, such as risk assessments, implementing security measures and reporting security incidents.
Indirectly covered: An overlooked risk
Even if your business is not in a critical sector, you may still be indirectly affected. This is especially true if your company provides services or products to a company that is directly affected. Examples include:
- Subcontractors of IT systems
- Consulting companies
- Logistics and transportation companies
- Facility management
If your customers are subject to NIS2, they will often require their suppliers to comply with similar IT security standards. This means that you as a subcontractor may face certification, risk management and reporting requirements.
What does this mean for your business?
Being indirectly covered by NIS2 means that you should consider:
- The level of security in your organization - Are your systems and processes robust enough to meet requirements
- Customer demands - Prepare for major customers to ask questions and make demands on your IT security.
- Compliance - Consider implementing standards like ISO 27001 to strengthen your credibility as a supplier
How to get started 👇
- Map your customers and suppliers: Are you part of a critical value chain?
- Review your IT security: Do you have the necessary measures in place?
- Consider external advice: Many companies choose to get help navigating the requirements of NIS2.
What can you do now?
While your company may not be directly affected by NIS2, indirect impact can have a big impact on your business. By taking responsibility for your IT security now, you can not only ensure compliance, but also strengthen your position as a trusted business partner.
At IT Forum Gruppen, we offer advice to help your business navigate the requirements and opportunities that NIS2 brings.
We can help you with:
- Mapping your business risk profile
- Implementing the right IT security measures
- Certification preparation
- Ongoing advice and support to keep you ahead of the game
Want to know more about how we can help your business become compliant while strengthening your IT security? Contact us today for a no-obligation conversation about your needs.