The NIS2 Directive (EU 2022/2555) was supposed to be transposed by all 27 EU Member States by October 2024. Several countries missed that deadline — France among them. In July 2026, the European Commission referred France to the Court of Justice of the EU (CJEU) for non-compliance (NIS-2-directive.com), and the French transposition bill is still working its way through parliament.
This delay should not mislead anyone. The directive has been in force across the European Union since January 2023. Its obligations are known, documented, and their substance will not change in national transposition. Several Member States — Germany (BSIG), the Netherlands, and Belgium — have already enacted full implementation laws. National cybersecurity authorities across the EU have opened registration portals for affected entities, and audits are already underway in countries with completed transpositions.
For a CIO or CISO at a mid-market company in a covered sector, the question is no longer “do we need to prepare?” but “where are we against the framework, and what do we do next?”
NIS2 in the EU: Who Is Covered and When?
The 18 NIS2 Sectors: From Energy to Manufacturing
NIS2 covers 18 sectors split across two annexes of the directive:
Annex I — Highly critical sectors: energy (electricity, hydrogen, gas, oil), transport (aviation, rail, maritime, road), banking, financial markets, health, drinking water, wastewater, digital infrastructure (cloud providers, data centres, communication networks), ICT service management, public administration, space.
Annex II — Other critical sectors: postal and courier services, waste management, manufacture of chemicals, food production, manufacturing (medical devices, computers and electronics, machinery, motor vehicles), digital providers (online marketplaces, search engines, social networks).
This list captures thousands of companies that previously had no formal cybersecurity obligations at the European level. The EU-wide estimate puts the number of affected entities at approximately 160,000 across all Member States. In France alone, the national cybersecurity agency ANSSI estimates between 15,000 and 18,000 entities fall within scope (aide.monespacenis2.cyber.gouv.fr).
Essential Entities (EE) vs Important Entities (IE): Two Distinct Regimes
NIS2 creates two categories with different obligation levels:
Essential Entities (EE) — large companies in Annex I sectors:
- 250 employees or more, or
- Annual turnover exceeding €50M AND a balance sheet total above €43M
Certain entities are automatically classified as EE regardless of size: DNS service providers, top-level domain name registries, telecom operators, qualified trust service providers, and critical cloud infrastructure providers.
EEs are subject to proactive supervision by national authorities: regular audits, on-site inspections, and stricter certification requirements.
Important Entities (IE) — medium-sized companies in Annex I and II sectors, or large companies in Annex II:
- 50 employees or more, or
- Annual turnover exceeding €10M
IEs benefit from reactive supervision: national authorities intervene primarily on the basis of reports or incidents.
How to Determine Whether Your Organisation Is in Scope
Most national cybersecurity authorities have published self-assessment tools. In France, ANSSI offers a qualification questionnaire at monespacenis2.cyber.gouv.fr. The pre-registration process takes 5 to 10 minutes and asks for: primary sector of activity, headcount, turnover, and presence in other Member States.
Equivalent tools are available in Germany (BSI), the Netherlands (NCSC-NL), and Belgium (CCB). If your country has already transposed NIS2, registration may already be mandatory — check your national authority’s guidance.
Don’t wait for your government’s official deadline. Large enterprises and public-sector suppliers are accelerating compliance across their supply chains, which will push mid-market suppliers — many of whom believe they are out of scope — to comply ahead of any national deadline.
The 10 NIS2 Cybersecurity Obligations That Directly Affect Your ERP
Article 21 of the directive requires entities to take “appropriate and proportionate technical, operational and organisational measures” to manage risks. These measures span 10 domains, several of which directly involve the ERP.
IT Governance and Risk Management
Senior management must approve cybersecurity measures and oversee their implementation. NIS2 explicitly engages the personal liability of executives: in the event of a serious violation, national authorities can seek a temporary ban on individual managers holding their roles (Article 32 for EEs). This is a clean break from the convention where cybersecurity is delegated exclusively to the CIO or CISO.
In practice: a cybersecurity policy validated by the executive committee, a dedicated cybersecurity budget, and regular security reviews reported to the board.
Digital Supply Chain Security
Article 21(2)(d) requires you to assess and control the security of each critical supplier — and your ERP vendor is, by definition, a critical supplier. If your ERP is compromised through a malicious update or a vulnerability at the vendor, your NIS2 liability is engaged.
Required actions: inventory of critical suppliers, assessment of their security level (ISO 27001, SOC 2 certifications), contractual incident-notification clauses, and audit rights.
Incident Management and Reporting to National Authorities
This is the most operationally demanding point for IT teams. NIS2 imposes a three-stage notification protocol (Article 23 of the directive):
| Deadline | Obligation |
|---|---|
| 24 hours | Early warning: report any “significant incident” to the national authority, indicating whether malicious acts or cross-border impact are suspected |
| 72 hours | Full notification: initial impact assessment, indicators of compromise, measures taken |
| 30 days | Final report: complete incident description, type of threat, mitigation measures, any cross-border impact |
A “significant incident” under NIS2 is any incident that has caused, or is capable of causing, serious operational disruption or significant financial losses. In practice, a ransomware attack taking your ERP down for more than four hours will qualify.
Business Continuity and Recovery Planning (BCP/DRP)
The ERP must be explicitly referenced in the Business Continuity Plan (BCP). The questions to document: what is the maximum tolerable downtime (RTO)? How much data can be lost (RPO)? Are backups tested regularly under realistic disaster conditions?
An ERP recovery test performed once a year on a synthetic production database is insufficient. NIS2 expects regular, documented tests with corrective action on gaps.
Mandatory Strong Authentication on ERP Access
NIS2 explicitly names MFA (Multi-Factor Authentication) as an obligation, “in particular for remote access and for access to sensitive information or privileged accounts.” For an ERP, this covers:
- Business user access, especially finance and HR profiles
- Administrator accounts (high-privilege ERP accounts)
- Integrator and vendor access during maintenance windows
- API connections between the ERP and third-party systems
For a deeper look at implementing MFA and PAM on your ERP, read our guide Zero Trust ERP: IAM, PAM and MFA — A CISO Guide 2026.
Encryption of Data and Communications
All sensitive data processed by the ERP must be encrypted in transit (TLS 1.2 minimum) and at rest. This includes off-site backups and exports to analytics tools. Reviewing the encryption configuration of your ERP — particularly for on-premise or hybrid deployments — is often an uncomfortable discovery during audits.
NIS2 and ERP Vendors: Are Your Suppliers Themselves Compliant?
SAP, Microsoft, Oracle, Sage: Their Current Commitments
NIS2 requires entities to ensure that critical suppliers apply adequate security measures. Here is what the major ERP vendors communicate publicly:
SAP: ISO 27001 certified. Registered as a critical infrastructure operator (KRITIS) in Germany, SAP is itself subject to NIS2-equivalent obligations and maintains a documented vulnerability management policy (SAP Trust Center).
Sage: ISO 27001 certified for secure development and the operation of its SaaS cloud services. Sage publishes its certifications on its Trust Center.
Microsoft Dynamics 365 and Oracle Cloud ERP: both vendors hold ISO 27001 and SOC 2 Type II certifications for their cloud environments. Microsoft publishes detailed compliance reports on the Microsoft Trust Center.
ISO 27001 covers 60–80% of NIS2 requirements but is not sufficient on its own: the incident-notification timelines and governance obligations specific to NIS2 go beyond the scope of the ISO standard.
The Contractual Clauses to Require in Your ERP Cloud Contract
Your ERP contract must include — or be renegotiated to include — the following:
- Incident notification SLA: the vendor must notify you within 24 hours of any incident affecting your instance
- Audit right or third-party audit report: access to up-to-date SOC 2 or ISO 27001 reports, or the ability to commission an independent audit
- Data location: data hosted within the EU (GDPR and NIS2 are aligned here)
- Vendor continuity plan: documentation of the vendor’s BCP covering your instance
- End-of-contract procedures: guaranteed data recovery in a usable format
For a complete review of ERP vendors’ obligations under the Cyber Resilience Act (CRA), which complements NIS2, see our article EU Cyber Resilience Act: How the New Regulation Changes ERP Compliance in 2026.
NIS2 Compliance Plan for Your ERP — 6 Steps
Step 1 — Self-Assessment and NIS2 Scoping
Use the self-assessment tool published by your national cybersecurity authority to determine whether you fall within scope and, if so, at which level (essential or important entity). In France, the questionnaire at monespacenis2.cyber.gouv.fr takes about 10 minutes. In Germany, BSI’s KRITIS self-identification process covers similar ground.
Three possible outcomes: out of scope, important entity, or essential entity. This diagnostic replaces lengthy internal legal analysis.
Complement the self-assessment with a review of the security measure frameworks published by your national authority. In France, ANSSI released the Référentiel Cyber France (ReCyF) in March 2026, listing recommended measures proportionate to each entity category. ENISA also publishes EU-wide implementation guidelines at enisa.europa.eu.
Step 2 — Map Critical Systems Including the ERP
Build an inventory of the information systems that are “essential to the provision of your services” within the meaning of NIS2. The ERP is on the front line — but so is: the HRIS (HR data), the CRM (customer data), EDI platforms (supplier exchanges), BI tools connected to the ERP, and interfaces with production systems.
This mapping is the foundation of any risk analysis and remediation plan. Without it, you are working blind.
Step 3 — Risk Analysis: ISO 27005 or EBIOS RM
ENISA recommends aligning with ISO 27005 for risk management. In France, ANSSI additionally promotes the EBIOS Risk Manager (EBIOS RM) method, which is compatible with ISO 27005 and enables you to prioritise measures against realistic risk scenarios (ransomware on the ERP, administrator account compromise, supplier data leak, etc.).
For a mid-market company, this analysis can be completed in 2 to 4 days with a qualified security audit provider. In France, look for ANSSI-accredited PAMS providers; in other Member States, check your national authority’s register of approved security service providers.
Step 4 — Technical Measures: MFA, Encryption, SOC/SIEM
Prioritise the measures with the highest NIS2 return:
- MFA on all ERP access: deployment in 1 to 3 weeks depending on your vendor
- Encryption of backups and data flows: configuration audit, 1 to 4 weeks
- SIEM or centralised log aggregation: essential for detecting an incident within the 24-hour window required for NIS2 early warning; 4 to 12 weeks depending on maturity
- PAM (Privileged Access Management) for ERP administrator accounts: 4 to 8 weeks
- Network segmentation: isolate the ERP from non-critical user workstations
Step 5 — BCP/DRP Planning and Continuity Testing with the ERP
Formalise a Business Continuity Plan and a Disaster Recovery Plan that explicitly document the ERP:
- RTO (Recovery Time Objective) and RPO (Recovery Point Objective) defined and board-approved
- Failover procedures to the backup environment tested
- Full restoration test at minimum annually, ideally every six months
- Crisis exercises simulating a NIS2 incident: who notifies the national authority, who manages external communications, who makes degraded-operation decisions?
Step 6 — Incident Notification Procedures
Draft your notification procedures before an incident occurs:
- Criteria for qualifying a significant incident: define internal thresholds (duration of downtime, data compromised, customer impact)
- Decision chain for the 24-hour alert: who qualifies, who notifies, via which channel (national authority portal)
- 72-hour and 30-day report templates: prepare templates with the fields required by the directive
- Coordination with your ERP vendor: incident communication protocol between your teams and vendor support
NIS2 Sanctions: Up to €10M or 2% of Global Turnover
Article 34 of the directive (official text: EUR-Lex 32022L2555) sets the penalty ceilings:
- Essential Entities: up to €10 million or 2% of global annual consolidated turnover (whichever is higher)
- Important Entities: up to €7 million or 1.4% of global annual consolidated turnover
These ceilings are consistent with GDPR (4% of turnover for personal data breaches). They do not cancel each other out: a ransomware incident involving personal data can result in cumulative NIS2 and GDPR penalties.
Beyond fines, NIS2 provides powerful non-monetary measures: temporary suspension of certifications (critical for healthcare operators or public-sector suppliers), publication of the decision (major reputational impact), and for essential entities, a temporary ban on senior managers holding their roles. This last measure — unprecedented in European cyber law — is why NIS2 is now a board-level conversation, not just a CIO or CISO concern.
NIS2 × ERP Compliance Checklist
| NIS2 Obligation | Concrete Action | Owner | Urgency |
|---|---|---|---|
| EE/IE entity classification | Complete self-assessment via national authority portal | CIO + CEO | Now |
| Board-approved security policy | Draft and validate the IT security policy | CISO + Board | 1 month |
| Critical IT systems mapping | Inventory ERP, HRIS, CRM, EDI, BI | CIO | 1 month |
| Risk analysis | ISO 27005 or EBIOS RM with qualified provider | CISO | 2–3 months |
| MFA on ERP access | Enable MFA for all profiles, PAM for admin accounts | CIO | 1–4 weeks |
| Backup encryption | Config audit + AES-256 encryption in transit and at rest | CIO | 1–4 weeks |
| SIEM/log aggregation | Deploy or subscribe to managed SIEM | CIO | 4–12 weeks |
| BCP/DRP with testing | Draft, test ERP restoration, run crisis exercise | CIO + Business | 3–6 months |
| 24h notification procedure | Alert template + decision chain | CISO | 1 month |
| ERP vendor contract clauses | Renegotiate SLA + security audit rights | Legal + CIO | 3–6 months |
For a comprehensive overview of the directive and its implications for mid-market companies, see our reference article NIS2 Directive and ERP: Compliance Requirements for Mid-Market Companies by 2026.
Download our ERP evaluation grid — 30 criteria on a 100-point scale to benchmark 3 vendors side by side, including a dedicated section on security certifications and NIS2/CRA compliance.