The word "directive" usually triggers a yawn, but NIS2 deserves attention for a practical reason: the fines are serious, and the circle of obligated entities is far wider than most people think. In Croatia, the directive is implemented through the Cybersecurity Act, and the categorisation of obligated entities is already under way. The same process is happening across the EU.
Who is covered?
It's no longer just banks and power plants. Obligations extend to energy, transport, healthcare, water supply, digital infrastructure, manufacturing, food, waste management, postal services and a list of other sectors: generally medium and large entities in those sectors, and in some cases smaller ones too.
But here's the catch many overlook: the supply chain. If you're a small company providing services to an obligated entity. IT support, software, maintenance, logistics. Your client will ask you for proof that your security is in order. Not because the law binds you directly, but because it binds them to vet their suppliers. In practice: supplier security questionnaires are already landing in inboxes.
What is actually required?
The law doesn't prescribe equipment brands; it prescribes risk-management measures. Translated into everyday language:
You need to know what you have (an inventory of systems and data) and what could happen to it (a risk assessment). You need baseline technical protection: access control, MFA, encryption, backups, updates. You need an incident plan. Who does what when something happens, and an obligation to report significant incidents to the authority within tight deadlines (the first notification within 24 hours). And you need to train people, including management, because the law explicitly places responsibility on leadership as well.
Why this is actually good news
Honestly? Nothing on that list is bureaucratic whim. It's a list of things every serious company should have anyway, the law merely added a deadline and a penalty for those who wait. Companies that get organised gain twice: genuinely lower exposure to attacks, and a competitive edge with clients who demand security evidence from their suppliers.
The sensible first step is neither panic nor buying expensive equipment, but a gap assessment: where you stand against the requirements, what's critical, and what can wait. With a clear picture, compliance becomes a project with a plan: instead of a fire fought the night before an audit.