Sprita iT

Directive (EU) 2022/2555

NIS2 and software security

NIS2 requires essential and important entities to manage cybersecurity risk with appropriate technical and organisational measures. Two of those measure areas land directly on software teams: supply chain security, and security in the acquisition, development and maintenance of systems — including vulnerability handling and disclosure.

  1. 16 January 2023

    Directive entered into force

  2. 17 October 2024

    Member State transposition deadline

  3. 18 October 2024

    National laws apply — obligations now live

Primary source: Directive (EU) 2022/2555 on EUR-Lex · Last reviewed 14 August 2026

Who is in scope

  • Essential and important entities in the sectors listed by the directive, above the applicable size thresholds
  • ICT service management providers, which brings many technology companies into direct scope
  • Suppliers to in-scope entities — indirectly, through their customers' supply chain security obligations

Scope depends on your entity, sector and — for directives — national transposition. This page is informational, not legal advice.

What we produce

  • Scope and method statement covering the analysed estate
  • Dependency inventory and supplier component risk view
  • Vulnerability handling procedure with operating evidence
  • Control narrative mapping engineering practice to the measure areas

We produce technical evidence and control narratives. We do not certify your compliance — that remains with you and your auditors.

What it requires from software teams

01

Supply chain security

Risk management must extend to relationships with direct suppliers and service providers — which for software means knowing your dependencies, assessing the components you consume, and being able to answer for them.

02

Secure acquisition, development and maintenance

Security has to be embedded across the lifecycle of network and information systems, not applied as a final gate before release.

03

Vulnerability handling and disclosure

You need a defined process for receiving, triaging, remediating and — where relevant — disclosing vulnerabilities, with evidence that it operates.

04

Management accountability

Management bodies are expected to approve and oversee risk-management measures, which is why these programmes now require reporting that an executive committee can read.

How Sprita iT Europe helps

  1. 1

    Map your software estate against the measure areas that apply to your entity

  2. 2

    Establish dependency inventory and supply chain governance with continuous SBOM

  3. 3

    Integrate secure development controls into the lifecycle rather than beside it

  4. 4

    Build the vulnerability handling workflow with owners, SLAs and an auditable trail

Frequently asked questions

Is NIS2 the same in every EU country?

No. NIS2 is a directive, so it takes legal effect through each Member State's national transposition. The core measure areas converge, but thresholds, registration duties, supervisory regimes and penalties are defined nationally. Scope must be assessed against the law of the Member States where you operate.

We are a software vendor, not a regulated entity. Does NIS2 reach us?

Often, in two ways. ICT service management is itself a listed sector, so you may be in direct scope. And independently of that, your regulated customers must manage supply chain risk — so their obligations reach you contractually, through security requirements and due-diligence questionnaires.

What does NIS2 actually expect us to produce?

The directive sets measure areas, not a document template. In practice supervisors look for demonstrable process: what you assessed, how you prioritized, who owned remediation, and evidence that it happened. That is the artifact set we build.

Primary sources

We link legal texts and standards directly. This page is informational and is not legal advice; obligations depend on your entity, sector and national transposition.

Where do you stand against NIS2?

A scoped assessment maps your estate to the obligations that actually apply to your entity — and produces the evidence trail.