NIS2 Directive
NIS2 · The European Union directive that imposes cybersecurity obligations on medium and large organisations in critical sectors such as energy, health, digital infrastructure, manufacturing and digital services.
- 01
Why it matters
NIS2 sets concrete rules on risk management measures, incident reporting and management accountability: for a significant incident, an early warning is due within 24 hours and a detailed notification within 72 hours. Companies in Turkey may not be directly in scope, but they are affected indirectly because their EU customers ask about supply chain security.
- 02
Example
An Austrian energy client of a Turkish software company asks its suppliers to document their security measures because of NIS2. The company puts its access management, backup process and incident-reporting commitment in writing and keeps the contract.
- 03
Common mistake
Thinking NIS2 is a problem only for large companies in the EU. Small firms that supply those companies end up answering the same questions in their contracts.
- 04
Let's talk about your project.
Tell us what you need; we will define the scope together.