WS
The NIS2 directive significantly widens the circle of entities subject to cybersecurity obligations. The question is no longer "is anyone subject" but "are we subject" — and many SaaS companies answer it wrong.

The NIS2 directive significantly widens the circle of entities subject to cybersecurity obligations. The question is no longer "is anyone subject" but "are we subject" — and many SaaS companies answer it wrong.
NIS2 replaced the original NIS directive and broadened the range of entities and sectors. In practice this means obligations that previously applied mainly to large critical-infrastructure operators can now cover a mid-sized technology company providing digital services.
That’s the first and most important question. The scope depends on the sector you operate in and the size of the company. Some entities are covered as "essential", some as "important" — with different levels of obligations and oversight.
Alert regulacyjny — NIS2 · EU · transposition in progress
The transposition deadlines into national law and the size thresholds must be verified for the specific company — interpretations are still being refined. As of May 2026.
The key word is "adequate". NIS2 doesn’t require a mid-sized company to build a bank’s apparatus. It requires measures proportionate to the risk — and that proportionality is exactly where it’s easiest to overshoot in either direction.





