NIS2: EU cyber-security requirements that reach Ukrainian suppliers
The NIS2 directive obliges EU essential and important entities to control the security of their suppliers. If you build software or provide cloud or managed services to European customers, NIS2 requirements will reach you through contracts and questionnaires — we prepare you in advance.
Who NIS2 applies to
The directive covers 18 sectors: energy, transport, banking, health, digital infrastructure, cloud and managed services, data centres, digital providers and more. A Ukrainian company is usually not directly in scope, but Article 21(2)(d) requires NIS2 entities to manage supply-chain risk — so your European customers must assess you and put requirements into the contract.
Ukraine is also aligning its legislation with NIS2 as part of EU integration, so the requirements are gradually becoming national.
The 10 measures of Article 21
- Risk analysis and information-system security policies
- Incident handling
- Business continuity, backups, disaster recovery, crisis management
- Supply-chain security
- Security in acquisition, development and maintenance, vulnerability handling
- Assessing the effectiveness of measures
- Cyber hygiene and training
- Cryptography and encryption
- HR security, access control, asset management
- Multi-factor authentication and secured communications
All ten map directly to ISO 27001:2022 controls and the SOC 2 criteria. If you already hold one of them, the NIS2 dossier comes together quickly.
Incident reporting
NIS2 introduces three-stage reporting: an early warning within 24 hours, an incident notification within 72 hours, a final report within one month. Your NIS2-entity customers will pass these deadlines on to you as a supplier. We build a procedure that can meet them and test it with exercises.
What you get
- NIS2 applicability and supply-chain role assessment
- Gap analysis against the 10 Art. 21 measures
- Mapping to ISO 27001 / SOC 2 (no duplication)
- 24/72-hour incident-notification procedures
- Supply-chain security and vendor-assessment programme
- Leadership training on NIS2 accountability
- Compliance dossier for customer questionnaires