Does NIS2apply to you?
An estimated 160,000 European entities are in scope. Most of them don't know it yet.
This page is the short version: what NIS2 requires, how to find out where you stand, and which requirements Stoïk's 360° approach helps you cover.

Let's get the uncomfortable part out of the way.
Before any product argument, two things need to be clear about what NIS2 is and about what an insurer can and cannot do for you.
What NIS2 is not
It is not a product, a certificate, or something a vendor can hand you. Cyber insurance is not a compliance product, and no single product makes a company NIS2-compliant, ours included.
Anyone selling you compliance in a box is selling you something else.
What Stoïk actually is here for
A 360° risk-management approach: insurance combined with prevention, detection, training and 24/7 response.
That covers a large share of NIS2's operational requirements. The compliance itself stays yours.
What NIS2 actually is.
The EU's revised cybersecurity directive. It replaces NIS1 and widens formal cybersecurity obligations from roughly 1,500 entities to an estimated 160,000.
~1,500 → 160,000
Entities in scope, from NIS1 to an estimated figure under NIS2
18 sectors
Annex I, highly critical (11) and Annex II, other critical (7)
24h / 72h / 1 month
Early warning within 24 hours, incident notification within 72 hours, final report within 1 month
€10M / 2%
Maximum fines for essential entities, or 2% of global turnover, whichever is higher
Two types of entities
Essential Entities
Who: Large companies in Annex I sectors (energy, transport, banking, health…), plus all telecom operators, core internet infrastructure providers, trust service providers and public administrations. "Large" means more than 250 employees or more than €50M revenue.
Security requirements: Full NIS2 security scope.
Supervision: Proactive — can be audited without a prior incident.
Sanctions: Fines up to €10M or 2% of global turnover, whichever is higher, plus personal liability for management, up to suspension from office.
Important Entities
Who: Medium-sized companies in Annex I sectors, plus companies in Annex II sectors (food, manufacturing, chemicals…).
Security requirements: Full NIS2 security scope.
Supervision: Reactive — mainly after an issue is detected.
Sanctions: Fines up to €7M or 1.4% of global turnover, whichever is higher, plus personal liability for management, up to suspension from office.
A directive, not a regulation.
NIS2 was published at EU level on 27 December 2022. Because it is a Directive, each Member State must transpose it into national law, and the only legal source of truth is always the national transposed law.
- ItalyTransposed — October 16, 2024In force
- BelgiumTransposed — October 18, 2024In force
- GermanyTransposed — December 6, 2025In force
- NetherlandsTransposed — August 15, 2026In force
- AustriaAdopted, not yet in force — October 1, 2026Adopted
- FranceBefore ParliamentNot transposed
- SpainDraft billNot transposed
Status as of August 31, 2026. Member States can adapt the content of the directive when transposing it, so scope and detail vary by country. Some deadlines run from the date an entity is identified rather than a single national date.
For almost every company, NIS2 collapses into three questions.
Strip away the legal vocabulary and this is what a management team actually needs to answer.
Does it apply to me?
Sector, size and role in the chain decide it. Essential or important, or neither. Most entities have never checked.
What does it actually expect from me?
Ten cybersecurity areas plus notification duties. Early warning within 24 hours, incident notification within 72 hours, final report within 1 month.
Where do I stand today against that?
The gap between the ten areas and reality. Knowing it is the whole starting point of the work.
Am I in scope for NIS 2?
Answer a few questions to find out whether the NIS 2 directive applies to your organisation, and which compliance areas concern you.
How many people does your company employ?
This self-assessment gives you a quick view of where you stand on NIS 2. It is not a compliance audit, nor evidence your national supervisory authority would accept. Real compliance requires documented evidence and expert advice. This tool is indicative only.
Compliance check: Three questions, one screen.
The Compliance Check module is free for every Stoïk insured, inside Stoïk Protect. It is a self-assessment, not an audit or a legal opinion, and it is not evidence opposable to any national authority. NIS2 is one of several compliance frameworks it covers.
Three fields, already filled in
Sector of activity, number of employees, consolidated turnover, pre-filled from what we already know from the insurance contract, and editable in one click. No questionnaire, no consultant, no spreadsheet.
A verdict, not a maybe
Whether NIS2 applies, and as what: essential entity, important entity, or out of scope. With it, the five things that change, supervision, personal liability, maximum sanction, deadlines, notification clock.
Forty concrete actions.
Ten areas, four tasks each, tagged with its NIS2 article. The ones Stoïk already delivers arrive pre-ticked, so you see exactly what is left and what is genuinely yours.
Five pillars. Each one maps to different NIS2 requirements.
This is why the coverage above is possible. Stoïk is Europe's first cyber MGA, so insurance, cybersecurity and an in-house CERT sit under one roof instead of three vendors to coordinate.
Technical Risk
Continuous external, Active Directory, cloud and credential-leak scanning of your exposure.
50,000+ high and critical vulnerabilities flagged across the portfolio last year
Human Risk
Awareness training and phishing simulations across all employees, with measurable progress.
Managed Defense
Managed detection and response stopping malware and fraud before they spread.
24/7 in-house SOC
Incident Response
A 24/7 in-house CERT, from containment to full reconstruction.
1,000+ incidents managed last year, under 5 days average reconstruction
Insurance Coverage
Cover for business interruption, restoration costs, liability and cyber fraud.
Insurance coverage for companies with revenue up to €2bn
Where do you want to start?
Two ways into the same conversation.
One for brokers, one for the companies they advise.
NIS2 is the best reason your clients have had in years to talk about cyber.
Your clients are already asking whether NIS2 applies to them, and most have nobody to ask. That question opens a conversation about risk instead of premium.
Start with the honest answer to "does this apply to me?"
You do not need a consultancy project to find out. Begin with the question, then work outwards from what you already have in place.