NIS2 Directive Compliance: The EU's New Cybersecurity Standard and Its Impact on Turkey

With the NIS2 Directive (2022/2555) published at the end of 2022, the European Union launched the most far-reaching transformation in cybersecurity legislation of the past decade. Closing the gaps left by the old NIS1 Directive (2016/1148), this new text entered into force on 17 January 2023, the deadline for member states to transpose it into national law was 17 October 2024, and it has been applied from that same date.

NIS2 is not "only a problem for EU-based companies." Turkish companies that serve the EU market, sell products to EU-based customers, or form part of an EU supply chain are directly affected as well. What is more, the directive's provisions on personal board accountability, 24-hour / 72-hour incident reporting and supply chain security also serve as an important reference point for Turkey's framework, including Law No. 5651, Law No. 6698 (KVKK, the Turkish Personal Data Protection Law) and the national Cybersecurity Law currently being drafted.

In this guide we examine what NIS2 is, whom it covers, which technical and administrative obligations it introduces, and how Turkish companies can prepare with a 12-month roadmap, drawing on DSET's field experience.

What Is NIS2, and Why Did It Replace NIS1?

When NIS1 (Network and Information Systems Directive) was published in 2016, it was the EU's first horizontal cybersecurity regulation. However, seven years of implementation revealed three core weaknesses:

  1. The scope was too narrow. It covered only 6 sectors (energy, transport, health, banking, financial market infrastructure, water, and digital infrastructure).
  2. Interpretation varied widely. Each member state defined "Essential Service Operator" in its own way, creating cross-border inconsistency.
  3. Enforcement was weak. There was no deterrent penalty structure in the event of a breach.

NIS2 was designed to solve all three problems at once. The official text is available via EUR-Lex 2022/2555 (eur-lex.europa.eu/eli/dir/2022/2555/oj), while implementation guidance is published by the EU Agency for Cybersecurity, ENISA (enisa.europa.eu/topics/nis-directive).

Who Is in Scope? Essential and Important Entities

NIS2 divides covered organizations into two main categories:

Essential Entities (EE): Large-scale, critical infrastructure providers. Typically operating in critical sectors with more than 250 employees or annual turnover above EUR 50 million.

Important Entities (IE): Mid-sized organizations that are still considered critical. More than 50 employees or turnover above EUR 10 million.

The number of sectors falling into these two categories rose from 6 under NIS1 to 18. The expanded list includes:

  • Energy (electricity, natural gas, oil, heating, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructure
  • Health (hospitals, pharmaceutical manufacturers, medical device manufacturers)
  • Drinking water and wastewater
  • Digital infrastructure (DNS, TLD, IXP, data centers, cloud, CDN)
  • ICT managed service providers (MSPs, MSSPs)
  • Public administration
  • Space
  • Postal and courier services
  • Waste management
  • Chemical manufacturing and distribution
  • Food production and distribution
  • Manufacturing (medical devices, computers, electronics, optics, machinery, motor vehicles)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research organizations

That final item is especially critical for Turkish manufacturing and supply chain companies. A Turkish OEM that exports automotive parts, medical devices, or machinery to the EU may lose contracts if it cannot demonstrate NIS2 obligations during its EU customer's supplier-security audit. We have a separate guide on OT/SCADA security in production environments: Manufacturing industry data recovery and SCADA security.

The 10 Minimum Security Measures (Article 21)

The technical heart of NIS2 is the ten minimum security measures in Article 21. Every covered organization must be able to produce written policies, procedures and evidence across these ten areas:

  1. Risk analysis and information system security policies
  2. Incident handling
  3. Business continuity and crisis management (BCP/DR), including backup management
  4. Supply chain security, including relationships with direct suppliers and service providers
  5. Security in the acquisition, development and maintenance of network and information systems, including vulnerability disclosure processes
  6. Policies and procedures to assess the effectiveness of cybersecurity risk management measures
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on the use of cryptography and encryption
  9. Human resources security, access control and asset management
  10. The use of multi-factor authentication (MFA), secured voice/video/text communications, and emergency communications

This list overlaps heavily with the ISO/IEC 27001:2022 Annex A controls and the functions of the NIST Cybersecurity Framework 2.0 (Govern, Identify, Protect, Detect, Respond, Recover). For an organization that is already ISO 27001 certified, the technical foundation of NIS2 is largely in place; the gaps are usually in incident reporting timelines, supply chain, board accountability and MFA coverage. For the ISO 27001 certification process, see: What Is the ISO 27001 Certificate and How Do You Obtain It.

Incident Reporting: 24 Hours, 72 Hours, 1 Month

The strictest and operationally most demanding provision of NIS2 is the Article 23 incident reporting timeline:

  • An "early warning" within 24 hours: A preliminary notification to the competent CSIRT or authority within the first 24 hours after the incident is detected. This covers only basic data, such as whether the incident is likely malicious and whether there is potential for cross-border impact.
  • An "incident notification" within 72 hours: An initial assessment, severity of impact, observed IOCs, and an updated picture based on the information available.
  • A "final report" within 1 month: Root cause analysis, mitigation measures taken, cross-border impact, and any lasting effects.

The 24-hour window will be the greatest challenge for most Turkish companies, because it requires a 24/7 SOC or at least an on-call IR team. For this reason, in NIS2 preparation it is essential that the incident response playbook be written according to the NIST SP 800-61 framework and validated through exercises: Cybersecurity Incident Response (IR) Playbook and NIST 800-61.

For equivalent guidance on the U.S. side, publications from CISA (cisa.gov), especially the Known Exploited Vulnerabilities (KEV) catalog and the Cybersecurity Performance Goals (CPG), align well with the NIS2 incident timelines.

Administrative Fines: The Real Numbers

According to Article 34 of the directive, the maximum administrative fines (official figures) are:

  • Essential Entities (EE): At least EUR 10,000,000 or 2% of global annual turnover, whichever is higher.
  • Important Entities (IE): At least EUR 7,000,000 or 1.4% of global annual turnover, whichever is higher.

These figures are the floor for EU member states; a member state may set a higher ceiling, but not a lower one. By way of comparison, the GDPR (gdpr.eu) ceiling is 4% or EUR 20 million, meaning that if the same incident constitutes both a KVKK/GDPR breach and a NIS2 breach, the penalties may be applied cumulatively.

In Turkey, the equivalent data protection framework is Law No. 6698 (KVKK), supervised by the KVKK Authority (kvkk.gov.tr). It is nearly impossible for a Turkish company that is not KVKK-compliant to achieve NIS2 compliance, because both rest on the same data governance foundations: KVKK compliance consulting: VERBIS, policies and auditing.

Board Accountability: A New Personal Risk

The most significant cultural shift introduced by NIS2 is the Article 20 board accountability. The management bodies of covered organizations must:

  1. Approve the cybersecurity risk management measures,
  2. Oversee their implementation,
  3. Be held personally accountable for non-compliance,
  4. Receive regular cybersecurity training.

This is a provision that breaks the "cybersecurity is IT's job" culture. The CISO's reporting is no longer a recommendation; it is a legal obligation trigger for the board. Across the 14 NIS2 pre-audits DSET has carried out in the field since the start of 2026, the single biggest gap, in every one of them, has been under the "board cybersecurity training records" item.

NIS2, ISO 27001, ISO 27701, NIST CSF and KVKK: A Compliance Map

It is possible to build a single control set that serves multiple frameworks at once. The following mapping has been tested through our field experience:

Topic NIS2 (Art. 21) ISO 27001:2022 NIST CSF 2.0 KVKK
Risk management 21(2)(a) Clause 6, A.5 GV.RM, ID.RA Art. 12 data security
Incident management 21(2)(b), Art. 23 A.5.24 - A.5.28 RS.MA, RS.AN Art. 12(5) notification
BCP/DR 21(2)(c) A.5.29 - A.5.30 RC.RP Art. 12 administrative measures
Supply chain 21(2)(d) A.5.19 - A.5.23 GV.SC Art. 12 data processor
Secure development 21(2)(e) A.8.25 - A.8.28 PR.PS -
Cryptography 21(2)(h) A.8.24 PR.DS Art. 12
MFA 21(2)(j) A.8.5 PR.AA Art. 12
Training 21(2)(g), Art. 20 A.6.3 PR.AT Art. 12
Privacy extension - ISO 27701 PR.DS All of KVKK

ISO 27001 + ISO 27701 + an incident response exercise + a supplier security addendum close roughly 80% of the NIS2 gaps. The remaining 20% is mostly the 24-hour reporting and the board training records.

A 12-Month NIS2 Roadmap for Turkish Companies

DSET's NIS2 preparation package spans 12 months. For field efficiency, the following sequence is recommended:

Month 1 - Scope and Gap Analysis. The company's sales to the EU, EU subsidiaries, and EU supply chain interactions are mapped. EE/IE status, and which member state's competent authority notifications will go to, are clarified. An inventory of the current ISO 27001, KVKK, and sector-specific regulation (BDDK, EPDK, the Ministry of Health) status is drawn up.

Month 2 - Board Approval and Budget. As required by the Article 20 obligation, the board resolution, CISO appointment or authorization, budget and sponsor are settled. The first board cybersecurity training is scheduled.

Months 3-4 - Risk Management and Policy Framework. Information asset inventory, threat modeling, risk register. For Turkey's threat landscape, see: Turkey's cyber threat landscape 2026.

Month 5 - Supply Chain Security. Critical supplier inventory, NIS2 / ISO 27001 / KVKK addenda to contracts, supplier self-assessment questions, and a separate control set for MSPs/MSSPs.

Month 6 - Technical Controls. MFA on all administrator accounts, and where possible phishing-resistant (FIDO2) on critical systems. Disk and backup encryption, log collection, SIEM/MDR. The EDR's real detection capability should be validated through a pentest: The pentest process, pricing and when it is needed.

Month 7 - Incident Response Playbook and 24-Hour Readiness. On-call rotation, communication tree, legal counsel coordination, EU CSIRT contact points, an early-warning template, and legal privilege protection.

Month 8 - Business Continuity and Disaster Recovery. RTO/RPO targets are set according to sector criticality. Offline or immutable copies of backups, and restore exercises.

Month 9 - Training and Awareness. Basic cyber hygiene for all staff, strategic training for the board, role-based training for the technical team. Phishing simulation.

Month 10 - Tabletop Exercise. A combined ransomware + data breach scenario. A 24-hour reporting simulation. Board participation.

Month 11 - Independent Audit and Gap Closure. Third-party audit, ISO 27001 pre-audit or full certification, and a NIS2 gap list.

Month 12 - Sustainability. Continuous monitoring, a KPI/KRI dashboard, an annual risk assessment, and a full-exercise schedule every three years.

Frequently Asked Questions (FAQ)

Q1: We have no EU subsidiary; we only export. Does NIS2 bind us? Not directly; however, if your EU customer is within NIS2 scope, they will ask you for evidence of compliance because of the supplier-security provision. In practice it is binding.

Q2: We hold an ISO 27001 certificate. Are we ready for NIS2? You are roughly 70-80% ready. The typical remaining gaps are: 24/72-hour reporting, supply chain addenda, personal board accountability, and MFA coverage.

Q3: Does KVKK compliance replace NIS2? No. KVKK focuses on personal data, whereas NIS2 covers all information systems and operational continuity. The two frameworks are applied together.

Q4: Does Turkey have its own equivalent of NIS2? Work on a national cybersecurity law is ongoing in Turkey; Laws No. 5651 and 5809, along with BDDK and KVKK regulations, introduce similar obligations piece by piece. NIS2 is not directly part of domestic law, but it is being used as a reference.

Q5: What are the maximum fines? For Essential Entities, at least EUR 10 million or 2% of global turnover; for Important Entities, at least EUR 7 million or 1.4%. A member state may set a higher figure.

Q6: Is a 24/7 SOC mandatory for the 24-hour notification? It is not mandatory, but at a minimum an on-call IR team tied to a call rota is required. Small companies can outsource this through an MDR/MSSP.

Q7: As a board member, is my personal property at risk? The directive does not directly define personal penalties; however, a member state may provide for this in its national law. Some member states already derive director liability from general commercial law.

Q8: Which documents should we retain? Risk assessment, policy sets, training records, incident logs, exercise minutes, supplier audit results, board resolutions, and MFA rollout evidence.

Conclusion and DSET NIS2 Readiness Consulting

NIS2 is not "the EU's business"; it is the new minimum standard for the global supply chain. Every company that sells from Turkey to the EU, has an EU subsidiary, or serves an EU customer will encounter this framework in supplier audits throughout 2026. Those who start preparing early turn NIS2 compliance into a marketing advantage rather than losing contracts.

As DSET NIS2 Readiness Consulting, we offer the following package: scope and gap analysis, ISO 27001/27701 integration, KVKK mapping, supply chain contract addenda, an incident response playbook and exercise, board training, a 12-month roadmap, and a monthly progress dashboard.

DSET Information Security Consulting Hacettepe Teknokent, Ankara +90 536 662 38 09

Your NIS2 clock has already started. Begin preparing before your next supplier audit request arrives.