View all 190 features →
Blog Our Story Client area Product Request a Demo →
Technologie

NIS2: the directive that forces you to rethink how your data flows

7 min read
Réseau de données interconnectées illustrant la directive NIS2 sur la cybersécurité

The NIS2 directive is now the reference framework for European cybersecurity. For CIOs and CISOs, it is not just another compliance box to tick: it forces a rethink of how data enters the information system, moves through it and leaves it. Here is what it actually requires, and why the way you route your data flows is becoming a front-line concern.

NIS2, a directive on a new scale

NIS2 is directive (EU) 2022/2555, adopted at the end of 2022 and in force since January 2023. It succeeds the first NIS directive of 2016, which had become too narrow given the scale reached by cyberattacks. The European Commission presents it as the foundation for a common, high level of cybersecurity across the Union.

The timeline is easy to remember: member states had to transpose it into national law before 17 October 2024. In France, ANSSI is leading this transposition and supporting the organisations concerned. The text does not merely add obligations: it significantly broadens the scope covered by NIS1, as ENISA points out.

This change of scale is anything but cosmetic. Where the first directive left member states a great deal of room for interpretation, NIS2 harmonises the criteria, thresholds and penalties. For a company already subject to NIS1, the challenge is to gauge what becomes stricter; for the newly affected entities, it often means starting from a near-blank page.

Who is affected, and on what basis

Where NIS1 targeted a limited number of players, NIS2 covers around eighteen sectors. These include critical infrastructure as much as digital and industrial activities, as the European Commission sets out in detail.

  • Energy, transport, banking and financial markets
  • Health, drinking water, wastewater
  • Digital infrastructure, public administration, space
  • Postal services, waste management, agri-food, manufacturing

Above all, NIS2 introduces a defining distinction: essential entities and important entities. The former group together the most critical players, subject to enhanced supervision; the latter fall under a lighter regime but remain fully liable in the event of a breach. ANSSI sets out the size and sector criteria that place an organisation in one category or the other.

This classification has a practical consequence: it determines the intensity of the controls, but not the nature of the obligations, which remain largely common to both. In other words, being classified as « important » rather than « essential » exempts you from almost nothing. It is therefore best to check your status early in order to size the necessary effort correctly.

What NIS2 requires in practice

The core of the directive lies in a series of obligations that every CIO or CISO must be able to demonstrate, not merely declare. ENISA, the Union’s agency for cybersecurity, provides the technical framework and guidelines for them.

  • Cyber risk management measures, proportionate and documented
  • Supply chain security, including suppliers and subcontractors
  • Incident notification on a strict timeline
  • The direct accountability of management bodies

Supply chain security deserves particular attention. NIS2 makes you responsible not only for your own systems, but also for links you do not directly control: service providers, software vendors, hosting companies. Yet these links exchange data with you constantly, which shifts the security question towards interfaces and flows.

The notification component is particularly tightly framed. According to the text of the directive, an early warning must be issued within 24 hours of detection, a fuller notification within 72 hours, then a final report within one month. This pace assumes that you know very quickly which data was affected, and by which paths it was travelling.

Meeting these deadlines is a demanding operational exercise. You cannot reconstruct in 24 hours a history you did not collect beforehand. This is where the ability to trace flows continuously makes the difference between a controlled notification and a last-minute reconstruction.

Two points change governance. First, senior managers are held directly liable, which pushes the subject all the way up to the executive committee. Second, the penalties are dissuasive: up to 10 million euros or 2% of annual worldwide turnover for essential entities, as ANSSI notes.

Why this directly affects how data flows

Most of NIS2’s requirements come down to one concrete question: do you know where your data goes, and can you prove it? ENISA’s threat landscape shows that attacks passing through the supply chain and through flows between systems are growing year after year.

Yet every time a piece of data is copied into a warehouse, duplicated in an intermediate system or kept « just in case », you add a zone to protect, monitor and justify. IBM’s Cost of a Data Breach report puts a figure each year on what these zones cost when they are compromised.

Every copy of data you did not create is a breach you will not have to defend.

Reducing the attack surface is therefore not merely a security principle: it is a direct way to make compliance more sustainable over time. The less data you accumulate at rest, the fewer points you have to encrypt, trace and audit. The logic of NIS2 pushes in this direction: master the flows, rather than multiply the copies.

Orchestrating data in transit, a structural response

Processing data « in transit » means moving it, transforming it and distributing it in real time, without freezing it in storage at each step. This approach addresses several NIS2 requirements at once, instead of treating them as separate projects.

The first benefit concerns the attack surface. Without an intermediate copy at rest, there are inherently fewer zones to defend, a point that Gartner’s cybersecurity analyses regularly underline. The second benefit concerns traceability: if every flow is logged, you have a usable history for incident notification as well as for audit.

This link between traceability and notification is often underestimated. An incident can be assessed all the faster when you know which flows were affected, to which recipients and for how long. Logging the movement of data, rather than only its final state, turns the notification obligation into simply reading a history that has already been built.

The third benefit touches on sovereignty and resilience. Orchestration that stays within the organisation’s perimeter, deployable on-premise, limits transfers to third-party systems whose location and availability you do not control. ENISA explicitly links this control to resilience and to the security of the data supply chain.

An illustration of the approach

To make this logic concrete, take the case of an orchestration middleware such as iD4Connect. Its principle is to process flows in real time, without intermediate storage, which by design limits the number of copies created along the data’s journey.

In practice, each flow passes through, is transformed if necessary, then distributed, all while being logged. The whole remains deployable within the organisation’s perimeter, on-premise, in the cloud or at the edge, depending on sovereignty constraints. This is not a silver bullet: it is a way to align the technical architecture with NIS2‘s requirements rather than catching up with them after the fact.

For a CIO, the value lies in thinking upstream: reducing storage points, tracing exchanges and keeping control over location. It is an architectural stance, not a product you bolt on at the end to tick a box.

Where to start

The first step is not technical, it is cartographic: mapping your data flows, their entry points, their copies and their recipients. Without this overall view, none of the obligations of directive (EU) 2022/2555 can be met sustainably.

This mapping is not just a documentation exercise. It serves as the basis for risk analysis, for securing the interfaces with your suppliers and for preparing notifications. Without it, each new obligation is handled piecemeal, which costs more and protects less well over time.

Then comes the question to ask for each flow: does this data really need to be stored here, or can it simply pass through? Every « pass through » answer reduces your exposure and your burden of proof accordingly on the day of an incident.

To go further, rely on the official sources: the European Commission’s dossier, ENISA‘s recommendations and ANSSI‘s tracking page. NIS2 is not just one more constraint: it is an opportunity to overhaul a data flow that has often become too complex to defend with any peace of mind.