NIS2 requirements for operational continuity and resilience
The NIS2 (Network and Information Security 2) directive introduces strict obligations forcyber risk management, and aims to strengthen theoperational resilienceof critical infrastructures in Europe. In particular, the standard requires critical and important organizations to adopt technical and organizational measures to guarantee the security of networks and information systems, and ensure continuity of services in the event of an incident. Key requirements (art. 21) include:
- Risk analysis and information security policies, with an ”all-risk” (global) approach that takes into account all relevant threats (cyber, physical, etc.) to systems and their operating environment.
- Incidenthandling, including procedures for detecting, responding to and notifying significant incidents.
- Business continuity and crisis management, e.g. through adequate backup management and disaster recovery plans, so that critical functions can be re-established after destructive events. The directive requires the adoption ofbusiness continuityplans to guarantee operation in the event of an incident, by requiring themapping of critical processes,regular testing of plansandrisk assessment throughout the supply chain.
- Supply chain security: security aspects relating to critical (direct) suppliers and partners need to be taken into account, by assessing their vulnerabilities and reliability, given that an IT incident at a supplier can have repercussions for the company itself.
These measures are all aimed atminimizing the impactof potential incidents on the recipients of essential services and on society, by strengthening the organization’s resilience. In short, NIS2 makes the link withbusiness continuityexplicit, recognizing it as a fundamental element of security: the ability to prepare for and respond to operational disruptions is an integral part of regulatory compliance.
Why business continuity must go beyond IT
Implementing business continuity from an NIS2 perspective meansgoing beyond the mere continuity of IT systems. Historically, many companies have focused on IT disaster recovery, butNIS2 emphasizes the continuity of the company’s business processesas a whole. In other words, the “objective” is not just to restore servers and data, but also toensure that processes essential to the delivery of products and services can continueeven in the event of serious incidents. This requires a holistic approach: for example, an IT disaster recovery plan alone “doesn’t make much sense” if restoration requirements have not been defined in line with the needs of the business processes supported by the systems.
To achieve this, thefirst stepis to carry out aBusiness Impact Analysis (BIA): an analysis that assesses the consequences of an interruption to the company’s various processes, and identifies the functions to be restored as a priority. BIA helps define the company’sdowntime tolerance, taking into account not only internal economic losses, but also external impacts (social, on customers or on the territory), which NIS2 encourages to be mitigated. Thanks to the BIA, the company identifiescritical dependencies: the resources required to keep processes running, ranging from personnel, premises and raw materials to external services and strategic suppliers. This dependency mapping highlights weak points where a failure or interruption (not only IT, but also logistics, energy, etc.) could paralyze operations.
The NIS2 places particular emphasis ondependencies on critical suppliers: a cyber attack or serious malfunction at a supplier can interrupt the supply of essential goods/services, and thus impact on the continuity of the business concerned.It‘s no coincidence that the directive requires each direct supplier to be assessedin terms of risk. For example, an essential manufacturing company will need to consider what would happen if its key component supplier were to be affected, and plan countermeasures (alternative suppliers, stocks, etc.). Similarly, a hospital covered by NIS2 cannot simply protect its own servers: it must ensure that its suppliers of digital services, energy, medical equipment, etc. also have adequate continuity plans in place. In essence, to comply with NIS2,business continuity must extend to the entire organization and supply chain, not just ICT. After all, the directiveapplies to the entire organization, requiringall areas supporting critical services to be protected, including functions such as logistics, human resources and the supply chain. This all-encompassing approach guarantees completeoperational resilience: the company becomes capable of absorbing and overcoming operational shocks because it has taken into account in advance all the elements essential to its business.
Integrating business continuity into NIS2 compliance plans
To meet NIS2 requirements, companies need tointegrate business continuityinto their compliance and security management programs. One effective way is to adopt abusiness continuity management system (BCMS)inspired byinternational best practicessuch asISO 22301and theprofessional practicesof theDisaster Recovery Institute International (DRI). These frameworks provide a systematic approach to establishing, implementing and maintaining business continuity, helping to cover precisely the areas required by NIS2. In practical terms, companies can:
- Perform a business impact analysis and risk assessment:identify essential processes and services, critical support resources and potential risks of disruption. ISO 22301, for example, requires a BIA to be carried out to identifytime-sensitiveprocesses and assess the impact of downtime, as well as an associated risk analysis. This includes assessing IT and non-IT risks, and consideringcrisisscenariosboth internally and along the supply chain(as required by NIS2).
- Define continuity strategies and plans: based on the results of the BIA/risk analysis, develop countermeasures and solutions to keep the company operational even under adverse conditions. This includes business continuity plans for business processes and disaster recovery plans for supporting IT systems. ISO 22301 places particular emphasis on the development ofdocumented plansto ensure continuity andrecovery within acceptable timescales. It is important that these plans cover not only IT infrastructure, but also alternative sites, manual emergency procedures, replacement of critical suppliers or supplies, etc., in line with the “beyond IT” approach mentioned above.
- Set up a crisis and communication structure: put in place a crisis team and emergency management procedures (crisis management) that can be activated immediately when needed. This meets the “crisis management” aspect mentioned in NIS2. Best practices such as DRI’s suggest definingroles and responsibilitiesin advance (e.g. command team, internal and external communication plans) to avoid confusion during an incident.
- Training and awareness: train staff in continuity plans and their role in the event of an incident. All stakeholders – not just the IT department, but also business unit managers, critical suppliers, etc. – must be familiar with emergency procedures. – must be familiar with emergency procedures. NIS2 also requires basic cybersecurity practices and security training. Integrating BC/DR training into corporate awareness programs therefore increases overall preparedness.
- Tests, exercises and continuous improvement: an effective BCMS includesperiodic tests(simulations, exercises, recovery drills) of plans to verify their effectiveness and update them according to the results. For example, disaster recovery exercises on IT systems, simulations of supply disruptions or power failures to assess organizational response. DRI’sProfessional Practicesemphasize the importance of implementing and maintaining plans, as well as regularly reviewing them to fill any gaps. This iterative process ensures that the company continually improves its resilience.
By following these practices, a company integrates business continuity into its NIS2 compliance planin a practical way.ISO 22301provides a certifiable framework for demonstrating the existence of robust business continuity processes (although it does not by itself guarantee full NIS2 compliance, it does provide a solid foundation). At the same time, adherence to DRI or similar guidelines ensures that no critical aspect is overlooked in the continuity program. Ultimately, the implementation of a comprehensive business continuity system, encompassing technology, people, sites and suppliers, is not only useful, but also necessary to comply with NIS2. It enables specific requirements to be met (business continuity plans, supply chain resilience, crisis management, etc.) while strengtheningoverall corporate resilience. Organizations prepared in this way will be able toabsorb and overcomeeven the most serious incidents, guaranteeing the continuity of essential services and protecting their customers, partners and stakeholders – which is, after all, the primary objective of the NIS2 directive.
ck here to add your own text
This post is also available in:

