The impact of the NIS2 Directive on the IT sector
In October 2024, the EU's NIS2 Directive came into force. It applies to 18 critical sectors, automatically involving IT contractors through supply chain security requirements.
What it means for companies
Ukrainian IT contractors serving EU clients in critical sectors are now directly affected by supply chain security audits. Non-compliance with these strict EU standards could lead to a loss of European contracts and partnerships.
Next steps
To maintain compliance and continue working with EU clients, Ukrainian IT contractors should take the following practical steps:
- Implement robust risk management processes and establish protocols to report security incidents within 24 hours.
- Adopt a Zero Trust architecture, including multi-factor authentication (MFA), microsegmentation, and the principle of least privilege.
- Ensure compliance with the Data Act regarding data portability and avoiding vendor lock-in.
Prepared by a Software Ukraine member. Original publication.