What is NIS2? Formally Directive (EU) 2022/2555, is the EU’s revised cybersecurity directive, setting baseline security and incident reporting requirements for essential and important entities across critical sectors, including energy, water, transport and digital infrastructure, and extending the scope of its 2016 predecessor.

NIS2 compliance now depends less on having a written cybersecurity policy and more on being able to demonstrate, with evidence, that a utility understands its risk and can respond to an incident.

Here is how that shift happened.

For many European utilities, the first phase of NIS2 was largely about interpretation. Are we in scope? Which national law will apply? Who is our competent authority? What will the regulator expect? Those questions still matter, but the conversation has moved on.

NIS2 is increasingly becoming a practical test of whether a utility can understand its risk, protect its essential services, respond to an incident and demonstrate what actually happened. That is a much bigger challenge than publishing a new cybersecurity policy.

Utilities have an unusually difficult environment to protect

A utility is not simply a collection of employees, laptops, applications and cloud services.

Its technology estate may include substations, pumping stations, treatment facilities, smart meters, distributed generation, environmental sensors, telemetry units and thousands, and sometimes millions, of remotely connected devices.

Some of those assets may have been designed to operate for 15 or 20 years. They may use embedded hardware that cannot easily be upgraded. They may sit in locations that are difficult or expensive to visit. Operational technology also behaves differently from conventional IT.

In an office environment, taking a server offline to patch it may be inconvenient. In an electricity, gas or water environment, availability and physical safety may take priority. A security change cannot be allowed to interrupt an essential process or create a new operational risk.

This combination of legacy equipment, remote infrastructure, third party support and increasing connectivity is precisely what makes utility cybersecurity so difficult.

What NIS2 compliance actually requires

The directive requires appropriate and proportionate technical, operational and organisational measures covering areas including risk analysis, incident handling, business continuity, supply chain security, vulnerability management, access control and secure communications.

It also introduces a demanding incident reporting process. A significant incident can require an early warning within 24 hours, followed by a fuller notification within 72 hours and a final report later in the process.

That creates an important operational question:

Could the utility assemble a reliable picture of the incident quickly enough?

It may need to understand when the event began, which systems were affected, what services were disrupted, whether the incident is ongoing and whether it could have an impact across borders.

Policies will not answer those questions. Evidence will.

Visibility across IT is not the same as visibility across the utility

Many organisations have invested heavily in IT security monitoring. The more difficult question is whether the same level of understanding extends into operational technology, field communications and mobile connected infrastructure.

ENISA previously found that 32% of surveyed energy operators did not have a single critical OT process monitored by a security operations centre. It also found that 52% were monitoring IT and OT through a single SOC, despite the specialist requirements of operational environments. This is not simply a tooling problem.

Utilities often depend on several organisations to deliver a complete service: equipment manufacturers, systems integrators, mobile operators, roaming partners, connectivity providers, cloud platforms and application suppliers. When something fails, each participant may only see its own part of the chain.

The device may be connected to a radio network, but is its data reaching the utility’s application? Where is the traffic breaking out? Which route is it taking? Has the device stopped communicating, or has the application stopped responding?

That lack of complete understanding makes ordinary troubleshooting harder. During a cyber incident, it can become a major constraint.

NIS2 Compliance is driving investment, but implementation remains difficult

ENISA’s 2025 study of 1,080 public and private organisations found that compliance was the primary cybersecurity investment driver for 70% of respondents.

However, organisations still identified patching, business continuity and supply chain risk management as major implementation challenges. Almost one in three had not conducted a cybersecurity assessment during the previous 12 months, while 28% took more than three months to patch critical vulnerabilities.

For utilities, those challenges are magnified by equipment lifecycles, availability requirements and complex supplier relationships. The answer cannot simply be to replace everything.

The more immediate requirement is to gain greater control over the environment that already exists.

From cybersecurity policy to operational evidence

The next stage of NIS2 is therefore likely to focus less on whether an organisation has written a policy and more on whether it can show that its controls work.

That test increasingly comes down to seven capabilities: identifying critical communications, restricting how remote devices are reached, separating different types of traffic, determining where data is routed and processed, detecting a change in normal connectivity behaviour, preserving enough information to support incident analysis, and recovering communications without creating an uncontrolled workaround.

None of these capabilities provides NIS2 compliance on its own.

Together, however, they help turn cybersecurity from an aspiration into something that can be operated, tested and evidenced.

For utilities, that may be the most important shift created by NIS2.

The directive is no longer simply asking organisations to take cybersecurity seriously. It is asking them to demonstrate that they understand and can manage the networks on which essential services increasingly depend.

Frequently Asked Questions (FAQs)

NIS2 compliance now means being able to demonstrate, with evidence, that an organisation understands its risk and can respond to an incident, not simply having a written policy. For utilities, that includes visibility across IT, operational technology and connected field assets, not just the traditional IT estate.

ENISA has found that many energy operators do not have a single critical OT process monitored by a security operations centre, and some monitor IT and OT through the same SOC despite their different needs. Without that visibility, a utility cannot assemble the evidence NIS2’s incident reporting timeline requires.

A significant incident can require an early warning within 24 hours, a fuller notification within 72 hours, and a final report later in the process. Meeting that timeline depends on being able to quickly understand what happened, not on a policy describing what should happen.