In brief
- Regulation: NIS2.
- A publisher providing digital services (SaaS, marketplace, cloud) or ICT service management, beyond the 'medium entity' threshold, is covered as an important entity.
- Analysing and managing risks.
- Securing the supply chain.
- Notify incidents.
- For important entities, fines can reach €7M or 1.4% of global turnover (€10M or 2% for essential entities).
Regulatory deadlines
The key dates of this regulation.
January 2023
Entry into force (EU directive)
In forceOctober 2024
Transposition deadline (EU)
In force2026
French transposition (Resilience Act)
In forceWhat does NIS2 cover?
NIS2 classifies organisations into essential and important entities based on their sector (Annexes I and II) and size. Important entities are subject to ex-post supervision, while essential entities are subject to more stringent oversight.
Publishers most often fall into the category of 'digital service providers' or 'ICT service management (B2B)', once they exceed the size threshold.
Is the 'Software Publishers' sector concerned?
A publisher providing digital services (SaaS, marketplace, cloud) or ICT service management, above the "medium entity" threshold, is covered as an important entity. Exceptions exist for certain players deemed critical regardless of their size.
Below the threshold, the obligation frequently flows back through the chain: clients subject to NIS2 must secure their supply chain and therefore cascade requirements contractually.
Detailed obligations
Analyse and manage risks
Implement the measures under Article 21: security policy, incident management, business continuity, supply chain security, encryption, access control, multi-factor authentication, among others.
Secure the supply chain.
Assessing and managing the security of suppliers and integrated software components is a central issue for a software vendor.
Notify incidents
Issue an early warning very promptly after becoming aware of a significant incident, followed by an intermediate report and a final report within the established timeframes.
Ensuring continuity and crisis management
Have a business continuity and recovery plan, tested backups and a crisis management organisation in place.
Involve management
Have the framework approved and monitored by the governing body, which is now accountable and must receive training on cyber risks.
Sanctions & risks
For important entities, fines can reach €7M or 1.4% of global turnover (€10M or 2% for essential entities). Most notably, NIS2 introduces personal liability for executives, who may be subject to enforcement measures and, in certain cases, a temporary ban from holding management positions.
The commercial risk is equally real: a compliance gap can disqualify a software vendor from tenders with clients that are themselves subject to NIS2.
Application timeline
- 1Directive. Adopted end of 2022; transposition expected by Member States.
- 2France. Transposition law currently being finalised; anticipate obligations without waiting for entry into force.
Common mistakes in the sector
- 1"Reserved for large corporations". Believing NIS2 only applies to large enterprises, when the threshold is reached from 50 employees or €10M in turnover.
- 2Supply chain overlooked. Neglecting the security of components and suppliers, which are at the core of NIS2.
- 3No incident process. Not having an alert and notification procedure in place.
- 4Absent leadership. Leaving cybersecurity solely to the technical team, without involvement of the governing body.
Practical case
A software publisher with 80 employees and €12M in revenue supplies SaaS solutions to local authorities. Exceeding the threshold, it qualifies as an important entity. It structures its compliance by deploying organisation-wide multi-factor authentication, an incident response plan and an assessment of its cloud suppliers, then has the framework validated by its management — three requirements drawn directly from Article 21.
Compliance roadmap
- 1
Qualify. Determine whether you are an important entity, an essential entity, or out of scope.
- 2
Analyse risks. Conducting a cyber risk analysis and a status review against Article 21.
- 3
Deploying measures. Implement missing measures and an incident response plan.
- 4
Secure suppliers. Mapping and governing the software supply chain.
- 5
Equip the notification process. Establishing the incident alerting and reporting process.
Frequently asked questions
Rarely directly, but obligations frequently cascade down through the contractual requirements of clients subject to NIS2, who must secure their supply chain.
Take action on NIS2
Free assessment or a chat with an expert dedicated to software publishers.
They already trust us
See how organisations in the software publishers sector secured their compliance with DCO.