Who NIS2 applies to
NIS2 replaced the old “operators of essential services / digital service providers” split with two broader categories, across far more sectors than NIS1. Its transposition deadline (17 October 2024) has passed, so the obligations are already in force — and they now reach deep into your supply chain.
Essential entities
Larger organizations in high-criticality sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, and digital infrastructure — face the strictest supervision.
Important entities
Medium-sized organizations in a wider set of sectors — postal services, waste management, chemicals, food, manufacturing, digital providers and research — carry the same core duties under lighter-touch supervision.
Expanded sectors
NIS2 widens scope well beyond NIS1. Many organizations that were previously out of scope are now caught, often without realising it — the size and sector thresholds decide, not self-classification.
Your supply chain
NIS2 makes you responsible for the security of your suppliers and service providers. Third-party exposure is now your exposure — and it has to be assessed and managed continuously.
The incident-reporting clock
When a significant incident hits, NIS2 puts you on a strict, staged reporting timeline to your national CSIRT. Missing it is a compliance failure in its own right — so detection and response have to be operational, not best-effort.
- Within 24 hours
Early warning
An initial early warning to your CSIRT or competent authority, flagging that a significant incident has occurred and whether it looks malicious or cross-border.
- Within 72 hours
Incident notification
A fuller notification with an initial assessment of severity, impact and any indicators of compromise.
- Within 1 month
Final report
A final report covering root cause, the mitigation applied, and the cross-border impact of the incident.
The obligations that need continuous work
NIS2’s Article 21 measures are not a one-off audit — they describe a security program you have to run and keep proving. Here is how River Security’s services line up with the duties you have to sustain.
Risk management & testing
Article 21 requires risk-based technical and organizational measures. Active Focus combines continuous attack surface management and expert penetration testing, so you are constantly identifying and validating real risk — not relying on an annual snapshot.
Incident handling & reporting
NIS2 puts a 24 / 72‑hour / one‑month clock on significant incidents. Our incident response capability helps you detect, triage and produce the early warning, notification and final report within the directive’s deadlines.
Supply-chain security
NIS2 makes third-party exposure your responsibility. Active Focus continuously discovers and monitors everything you — and your suppliers — expose to the internet, keeping supply-chain risk visible instead of assumed.
Governance & accountability
NIS2 holds management personally accountable and expects documented policy, oversight and audit evidence. CISO as a Service provides the security leadership, governance and reporting that keeps your board covered and your program demonstrable.

One continuous engine for NIS2 readiness
NIS2 asks you to work systematically with security and demonstrate it. Active Focus does both: attack surface management and expert penetration testing delivered as one always-on service, with the platform holding the history of what was found, when, and how it was fixed. That record is exactly the evidence NIS2 supervision and incident reporting depend on — and it maps directly to the directive control-by-control in our Compliance Hub.
Customer case
Cyber Resilience for Aneo and Their Critical Energy Infrastructure
River Security gives us clarity, structure, and sparring that adds real value. The Active Focus platform makes it easier to prioritize and follow up, and we truly appreciate having a skilled security professional in the loop.

Preparing for NIS2?
Book a short call and we will walk you through where you stand against NIS2’s risk-management, supply-chain and reporting obligations — and how Active Focus closes the gaps. In Norway, NIS2 is implemented through the Digital Security Act (digitalsikkerhetsloven), which we also map in the Compliance Hub.
Schedule a NIS2 readiness callCompliance and regulation content from our team

Guide to Navigate the Most Common Frameworks and Regulations for Cyber Security
In this comprehensive guide I will go through the most common frameworks and regulations for Cyber Security, as there might be some confusion in how t…

SSL/TLS Management: Reducing Risks and Gaining Visibility
Transport Layer Security (TLS) and its predecessor SSL remain cornerstones of modern internet security. They protect confidentiality, integrity, and a…

Continuous Security, Real Risk Insights, and Business Value – Why Our Customers Choose Active Focus
A few years back, River Security developed and launched Active Focus, a world-first, disruptive IT security technology and service enabling penetratio…






