With the entry into force of the new European Union NIS2 Directive, which strengthens cybersecurity requirements, Ukrainian IT providers are facing new challenges and opportunities. This regulatory act, which replaces the previous NIS Directive, significantly expands its scope, covering a wider range of sectors and organizations, and establishes stricter rules for cybersecurity risk management and incident reporting. For Ukrainian companies operating or planning to enter the EU market, understanding and implementing NIS2 cybersecurity requirements in Ukraine is a critical success factor. Compliance with these standards not only opens doors to cooperation with European partners but also increases the overall level of cyber resilience and trust in the Ukrainian IT sector.
NIS2 cybersecurity: who is subject to the new requirements in Ukraine
The NIS2 Directive defines two main types of entities subject to its provisions: "essential" and "important" organizations. "Essential" entities include enterprises in critical sectors such as energy, transport, healthcare, finance, as well as digital infrastructure providers (DNS providers, TLD registries). "Important" organizations cover a broader spectrum, including digital service providers, manufacturers of certain types of products, and other sectors that could have a significant impact on the economy and society in the event of a cyber incident.
For Ukrainian IT companies working in the European market, this means both direct and indirect impact. If a Ukrainian company is a cloud service provider, a data center, a managed security service provider (MSSP), or another digital service provider for an entity registered in the EU, it is likely also subject to NIS2. This applies not only to companies directly providing services but also to those that are part of the supply chain for regulated entities.
The geographical scope of NIS2 is broad: the directive applies to companies providing services in the European Union, regardless of their place of registration. This means that Ukrainian IT providers, even without a physical presence in the EU but serving European clients, are required to comply with these requirements. Failure to do so may lead to blocked access to the European market and significant fines, which is a serious business risk.
Particular attention should be paid to sectors directly related to IT services. These include cloud computing providers, data centers, managed service and security providers, and content delivery network providers. If your company provides such services to European clients, preparation for NIS2 should be a priority.
Practical measures for NIS2 compliance: how to adapt cybersecurity
To ensure NIS2 compliance, Ukrainian IT companies need to implement comprehensive measures covering various aspects of cybersecurity. Central to this is the development and implementation of an effective risk management system. This involves regular cyber risk assessment, identification of critical assets, development and implementation of information security policies, as well as continuous monitoring and review of these policies. Companies must have a clear understanding of potential threats and vulnerabilities.
Another key element is the development and testing of incident response plans. NIS2 requires not only the ability to effectively respond to cyber incidents but also mandatory notification of relevant regulatory bodies (CSIRT or a competent authority) within 24 hours of detecting a significant incident. This requires creating internal procedures for rapid detection, analysis, and escalation of incidents, as well as establishing communication mechanisms with regulators.
The NIS2 Directive also strengthens supply chain security requirements. This means that Ukrainian providers must not only protect their own systems but also ensure an adequate level of cybersecurity among their partners and subcontractors. It is necessary to conduct supplier audits, include cybersecurity requirements in contracts, and regularly assess risks associated with third parties. This aspect is particularly relevant given the globalized nature of the IT industry.
Furthermore, NIS2 requires the implementation of a number of basic security measures. These include the use of multi-factor authentication (MFA), data encryption, regular backups and recovery, conducting security audits and penetration tests (pentests), as well as continuous staff training on cybersecurity issues. In 2024, as cyber threats become increasingly sophisticated, such measures are fundamental for protecting data and systems.
Consequences of NIS2 non-compliance: fines and reputational risks for Ukrainian providers
Non-compliance with the requirements of the NIS2 Directive can have significant and far-reaching negative consequences for Ukrainian IT companies. One of the most obvious is administrative fines. For "essential" organizations, these can reach up to 10 million euros or 2% of the total worldwide annual turnover, whichever is higher. For "important" organizations, fines are up to 7 million euros or 1.4% of the total worldwide annual turnover. Such amounts can be catastrophic even for large companies.
In addition to financial sanctions, companies that do not follow NIS2 cybersecurity requirements in Ukraine risk suffering serious reputational losses. Cyber incidents caused by insufficient security and public reports of non-compliance with regulatory requirements can undermine the trust of clients, partners, and investors. Restoring a reputation is a long and expensive process, and sometimes impossible, which can lead to the loss of significant contracts and the client base.
Legal consequences are not limited to fines. Affected parties whose data or services were compromised due to non-compliance with NIS2 requirements may file lawsuits against the company. This adds another layer of financial and reputational risk. In some cases, non-compliance can even lead to restricted or completely blocked access to the European market, which for many Ukrainian IT companies is a key source of revenue.
Loss of competitiveness is an inevitable consequence. European clients will increasingly require their suppliers to confirm NIS2 compliance. Companies that cannot provide such guarantees will be pushed out of the market by better-prepared competitors. This dynamic is already observed in areas where cybersecurity regulation is strict, such as the financial sector, where over 60% of companies actively check their suppliers for compliance with standards.
Why is it important for Ukrainian IT companies to implement NIS2 requirements now?
Proactive implementation of NIS2 requirements is not just about meeting regulatory standards, but a strategic investment in the future of Ukrainian IT companies. Firstly, it allows for maintaining and expanding access to the EU market. NIS2 compliance is becoming a mandatory prerequisite for concluding new contracts and continuing cooperation with existing European clients. Companies that demonstrate compliance will gain a significant competitive advantage.
Secondly, a high level of cybersecurity and compliance with European standards significantly increases the trust of investors and partners. Demonstrating a mature cyber risk management system is a sign of a reliable and responsible business. This attracts new investments, opens opportunities for strategic partnerships, and strengthens the company's position on the international stage. For example, in 2023, investments in companies with proven cyber resilience grew by 34% compared to the previous year.
Thirdly, implementing NIS2 is an important preparation for Ukraine's future integration into the EU. Harmonization of legislation and standards in the field of cybersecurity is a key step on this path. Proactive adoption of European norms will allow Ukrainian companies to be prepared for changes and avoid the shock of sudden regulatory requirements in the future. It also demonstrates the ability of the Ukrainian IT sector to meet global standards.
Finally, NIS2 compliance contributes to strengthening the company's own cyber resilience. Implementing best practices in risk management, incident response, and data protection is an effective shield against growing cyber threats. This minimizes business risks associated with cyberattacks, data leaks, and operational disruptions, ensuring stability and business continuity. Thus, NIS2 cybersecurity requirements in Ukraine become a catalyst for comprehensive improvement of the protection level.
Given the dynamics of the digital market and increasing regulatory pressure, Ukrainian IT companies need to actively analyze their cybersecurity processes now and strategically plan the implementation of the NIS2 Directive requirements. This is not just a formality, but a fundamental step to ensure sustainable growth, maintain competitiveness, and strengthen trust at the international level. Investments in NIS2 compliance are investments in long-term success and business security in the face of global cyber threats.
Frequently asked questions
What is the NIS2 Directive and what is its purpose?
The NIS2 Directive is an EU legislative act aimed at increasing the overall level of cybersecurity in the European Union. Its goal is to strengthen the resilience of critical sectors and digital service providers to cyber threats by establishing uniform standards and response mechanisms.
Which Ukrainian IT companies are subject to NIS2?
Ukrainian IT companies that provide services to entities in the EU and are classified as "essential" or "important" organizations under the Directive are subject to NIS2. This applies to cloud service providers, data centers, managed security services, and other digital services that have an impact on European infrastructure.
What are the main NIS2 cybersecurity requirements?
The main NIS2 requirements include implementing comprehensive cybersecurity risk management systems, effective incident response, ensuring supply chain security, using multi-factor authentication, encryption, and regular audits. Companies are also required to report significant cyber incidents to the relevant authorities.
What fines are provided for non-compliance with NIS2?
Significant administrative fines are provided for non-compliance with NIS2 requirements. For "essential" organizations, they can reach up to 10 million euros or 2% of the total worldwide annual turnover, and for "important" ones – up to 7 million euros or 1.4% of the total worldwide annual turnover. In addition to financial sanctions, companies also risk reputational losses and loss of access to the EU market.