Regulation readiness

NIS2: from an EU directive to always-on security

NIS2 makes systematic, risk-based security a legal requirement for essential and important entities across the EU — with a strict incident-reporting clock and personal accountability for management. Active Focus gives you the continuous testing, visibility and response capability the directive demands, and the evidence to prove it.

Who NIS2 applies to

NIS2 replaced the old “operators of essential services / digital service providers” split with two broader categories, across far more sectors than NIS1. Its transposition deadline (17 October 2024) has passed, so the obligations are already in force — and they now reach deep into your supply chain.

Essential entities

Larger organizations in high-criticality sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, and digital infrastructure — face the strictest supervision.

Important entities

Medium-sized organizations in a wider set of sectors — postal services, waste management, chemicals, food, manufacturing, digital providers and research — carry the same core duties under lighter-touch supervision.

Expanded sectors

NIS2 widens scope well beyond NIS1. Many organizations that were previously out of scope are now caught, often without realising it — the size and sector thresholds decide, not self-classification.

Your supply chain

NIS2 makes you responsible for the security of your suppliers and service providers. Third-party exposure is now your exposure — and it has to be assessed and managed continuously.

The incident-reporting clock

When a significant incident hits, NIS2 puts you on a strict, staged reporting timeline to your national CSIRT. Missing it is a compliance failure in its own right — so detection and response have to be operational, not best-effort.

  1. Within 24 hours

    Early warning

    An initial early warning to your CSIRT or competent authority, flagging that a significant incident has occurred and whether it looks malicious or cross-border.

  2. Within 72 hours

    Incident notification

    A fuller notification with an initial assessment of severity, impact and any indicators of compromise.

  3. Within 1 month

    Final report

    A final report covering root cause, the mitigation applied, and the cross-border impact of the incident.

The obligations that need continuous work

NIS2’s Article 21 measures are not a one-off audit — they describe a security program you have to run and keep proving. Here is how River Security’s services line up with the duties you have to sustain.

Active Focus

Risk management & testing

Article 21 requires risk-based technical and organizational measures. Active Focus combines continuous attack surface management and expert penetration testing, so you are constantly identifying and validating real risk — not relying on an annual snapshot.

Incident Response

Incident handling & reporting

NIS2 puts a 24 / 72‑hour / one‑month clock on significant incidents. Our incident response capability helps you detect, triage and produce the early warning, notification and final report within the directive’s deadlines.

Active Focus

Supply-chain security

NIS2 makes third-party exposure your responsibility. Active Focus continuously discovers and monitors everything you — and your suppliers — expose to the internet, keeping supply-chain risk visible instead of assumed.

CISO as a Service

Governance & accountability

NIS2 holds management personally accountable and expects documented policy, oversight and audit evidence. CISO as a Service provides the security leadership, governance and reporting that keeps your board covered and your program demonstrable.

Active Focus platform showing prioritised vulnerabilities and remediation history

One continuous engine for NIS2 readiness

NIS2 asks you to work systematically with security and demonstrate it. Active Focus does both: attack surface management and expert penetration testing delivered as one always-on service, with the platform holding the history of what was found, when, and how it was fixed. That record is exactly the evidence NIS2 supervision and incident reporting depend on — and it maps directly to the directive control-by-control in our Compliance Hub.

More about Active Focus
Customer case

Cyber Resilience for Aneo and Their Critical Energy Infrastructure

River Security gives us clarity, structure, and sparring that adds real value. The Active Focus platform makes it easier to prioritize and follow up, and we truly appreciate having a skilled security professional in the loop.

Thomas Mørtsell
Thomas MørtsellChief Security Officer, Aneo
View all customer cases →

Preparing for NIS2?

Book a short call and we will walk you through where you stand against NIS2’s risk-management, supply-chain and reporting obligations — and how Active Focus closes the gaps. In Norway, NIS2 is implemented through the Digital Security Act (digitalsikkerhetsloven), which we also map in the Compliance Hub.

Schedule a NIS2 readiness call

Compliance and regulation content from our team