Software publishers · NIS2

Software publishers & NIS2: are you affected?

The NIS2 directive (EU 2022/2555) significantly extends cybersecurity obligations, particularly for digital providers and ICT service management. A software publisher exceeding the 'medium entity' threshold falls under important entities and must structure its cyber risk management. This guide clarifies the thresholds, the measures to be implemented, the incident notification regime, and the now-engaged liability of management.

DPO / CISO team — Data Comply One Updated on 15 June 2026

In brief

  • Regulation: NIS2.
  • A publisher providing digital services (SaaS, marketplace, cloud) or ICT service management, beyond the 'medium entity' threshold, is covered as an important entity.
  • Analysing and managing risks.
  • Securing the supply chain.
  • Notify incidents.
  • For important entities, fines can reach €7M or 1.4% of global turnover (€10M or 2% for essential entities).

Regulatory deadlines

The key dates of this regulation.

January 2023

Entry into force (EU directive)

In force

October 2024

Transposition deadline (EU)

In force

2026

French transposition (Resilience Act)

In force

What does NIS2 cover?

NIS2 classifies organisations into essential and important entities based on their sector (Annexes I and II) and size. Important entities are subject to ex-post supervision, while essential entities are subject to more stringent oversight.

Publishers most often fall into the category of 'digital service providers' or 'ICT service management (B2B)', once they exceed the size threshold.

Is the 'Software Publishers' sector concerned?

A publisher providing digital services (SaaS, marketplace, cloud) or ICT service management, above the "medium entity" threshold, is covered as an important entity. Exceptions exist for certain players deemed critical regardless of their size.

Below the threshold, the obligation frequently flows back through the chain: clients subject to NIS2 must secure their supply chain and therefore cascade requirements contractually.

Detailed obligations

Analyse and manage risks

Implement the measures under Article 21: security policy, incident management, business continuity, supply chain security, encryption, access control, multi-factor authentication, among others.

Secure the supply chain.

Assessing and managing the security of suppliers and integrated software components is a central issue for a software vendor.

Notify incidents

Issue an early warning very promptly after becoming aware of a significant incident, followed by an intermediate report and a final report within the established timeframes.

Ensuring continuity and crisis management

Have a business continuity and recovery plan, tested backups and a crisis management organisation in place.

Involve management

Have the framework approved and monitored by the governing body, which is now accountable and must receive training on cyber risks.

Sanctions & risks

For important entities, fines can reach €7M or 1.4% of global turnover (€10M or 2% for essential entities). Most notably, NIS2 introduces personal liability for executives, who may be subject to enforcement measures and, in certain cases, a temporary ban from holding management positions.

The commercial risk is equally real: a compliance gap can disqualify a software vendor from tenders with clients that are themselves subject to NIS2.

Application timeline

  • 1Directive. Adopted end of 2022; transposition expected by Member States.
  • 2France. Transposition law currently being finalised; anticipate obligations without waiting for entry into force.

Common mistakes in the sector

  • 1"Reserved for large corporations". Believing NIS2 only applies to large enterprises, when the threshold is reached from 50 employees or €10M in turnover.
  • 2Supply chain overlooked. Neglecting the security of components and suppliers, which are at the core of NIS2.
  • 3No incident process. Not having an alert and notification procedure in place.
  • 4Absent leadership. Leaving cybersecurity solely to the technical team, without involvement of the governing body.

Practical case

A software publisher with 80 employees and €12M in revenue supplies SaaS solutions to local authorities. Exceeding the threshold, it qualifies as an important entity. It structures its compliance by deploying organisation-wide multi-factor authentication, an incident response plan and an assessment of its cloud suppliers, then has the framework validated by its management — three requirements drawn directly from Article 21.

Compliance roadmap

  1. 1

    Qualify. Determine whether you are an important entity, an essential entity, or out of scope.

  2. 2

    Analyse risks. Conducting a cyber risk analysis and a status review against Article 21.

  3. 3

    Deploying measures. Implement missing measures and an incident response plan.

  4. 4

    Secure suppliers. Mapping and governing the software supply chain.

  5. 5

    Equip the notification process. Establishing the incident alerting and reporting process.

Frequently asked questions

Rarely directly, but obligations frequently cascade down through the contractual requirements of clients subject to NIS2, who must secure their supply chain.

Take action on NIS2

Free assessment or a chat with an expert dedicated to software publishers.

They already trust us

See how organisations in the software publishers sector secured their compliance with DCO.

See testimonials