The NIS2 (Network and Information Systems Directive 2) is a key European Union regulatory act that significantly strengthens cybersecurity and risk management requirements in the digital space. For Ukrainian IT providers actively working with European companies, understanding how NIS2 cybersecurity requirements Ukraine affect their operations is critical. This directive expands the scope of entities subject to its provisions and establishes clearer obligations, making it relevant not only for European but also for international service providers. Ukrainian companies aiming to maintain and expand their presence in the European market must not only be aware of these changes but also actively implement appropriate measures to ensure compliance. This is a strategic step to maintain competitiveness and trust from European partners.
NIS2: who falls under the new cybersecurity requirements in Ukraine
The NIS2 Directive significantly expands the range of organizations and sectors subject to its provisions compared to the previous version. This expansion is fundamental to understanding its impact on Ukrainian IT companies. The new rules cover a larger number of critical economic sectors that provide vital services and digital infrastructure, and also add a number of new industries.
The directive distinguishes between two categories of entities: "essential" and "important." "Essential" entities include, for example, companies in energy, transport, banking, healthcare, digital infrastructure, and public administration. "Important" entities include sectors such as manufacturing, chemical and food industries, postal and courier services, waste management, as well as digital providers, including cloud services, data centers, content delivery networks (CDN), and domain name registries.
For Ukrainian IT companies, this means that if they provide services (outsourcing, cloud solutions, software development, infrastructure support) to European clients belonging to any of these categories, they become indirect subjects of NIS2. Even if a Ukrainian company is not directly subject to NIS2, its European clients will be required to ensure their suppliers comply with the directive's requirements. This creates a direct necessity for Ukrainian IT service exporters to adapt to new standards, as otherwise, their clients in the EU may face regulatory risks.
Mandatory NIS2 security measures: what Ukrainian companies need to implement
The NIS2 Directive establishes a clear minimum set of cybersecurity measures that must be implemented by entities. These are not just recommendations but mandatory requirements concerning various aspects of information system protection. For Ukrainian IT providers striving to meet European market standards, these measures become a roadmap for increasing their own cyber resilience.
Key requirements include comprehensive risk management, which involves regular threat analysis and the development and implementation of appropriate security policies. Effective incident management is also crucial, involving not only detection and response but also mandatory reporting of significant cyber incidents to the relevant authorities. The directive also emphasizes the need to ensure business continuity, which includes backup strategies, disaster recovery plans, and crisis management.
Special attention is paid to supply chain security, which is critical for Ukrainian companies. This means that security requirements must be implemented not only for one's own systems but also for the systems of suppliers and partners. Additionally, NIS2 requires the implementation of multi-factor authentication, the use of cryptographic solutions, and regular staff training on cyber hygiene and the security of networks and information systems. All these steps require investment in technology and training, but at the same time, they serve as a powerful competitive advantage in the European market.
How do NIS2 cybersecurity requirements affect the supply chain of Ukrainian IT providers?
One of the most significant aspects of the NIS2 Directive for the Ukrainian IT sector is its focus on supply chain security. The new rules clearly shift the responsibility for cybersecurity to all participants in the chain, including external service providers. This means that European clients are now obligated not only to ensure their own cybersecurity but also to thoroughly vet and require compliance from their third parties, which often include Ukrainian IT companies.
In practice, this means that clients in the EU will actively demand that their Ukrainian IT partners demonstrate compliance with strict cybersecurity standards. This includes conducting detailed risk assessments related to the involvement of third parties, as well as incorporating appropriate contractual obligations. Contracts may now include clauses on regular security audits, monitoring of policy compliance, and requirements for reporting incidents that occur on the supplier's side.
Ukrainian companies must be prepared to not only implement their own internal security measures but also actively demonstrate their effectiveness. This may include providing documentary evidence of measure implementation, undergoing independent cybersecurity audits, and participating in penetration testing. This approach creates new requirements for contract drafting, risk management, and building partnerships, demanding transparency and accountability in cybersecurity at all stages of cooperation. Successfully demonstrating NIS2 compliance can be a key factor in securing new contracts and retaining existing ones in the European market.
According to Ivan Abramov, Development Manager at SL-IT, "Ukrainian IT companies should view NIS2 requirements as an opportunity to strengthen their reputation on the international stage. Proactively integrating these standards into their own operational processes will allow them not only to avoid potential risks but also to act as a reliable and responsible partner for European customers."
Penalties and liability for NIS2 non-compliance: risks for Ukrainian IT
Non-compliance with NIS2 requirements entails serious financial and reputational consequences for European companies. These consequences indirectly but very tangibly affect their Ukrainian IT providers. Although Ukrainian companies are not directly subject to EU fines, their non-compliance can lead to catastrophic consequences for their European clients, and consequently, for themselves.
The directive provides for significant fines for violations. For "essential" entities, they can reach up to 10 million euros or 2% of the company's total annual worldwide turnover, whichever is higher. For "important" entities, fines can be up to 7 million euros or 1.4% of the annual worldwide turnover. In addition to financial penalties, other sanctions are possible, such as reputational damage, suspension of operations, or even the revocation of permits for certain types of activities.
For Ukrainian IT companies, this means direct commercial risks. If a Ukrainian provider's non-compliance leads to a cyber incident at a European client, which in turn causes an NIS2 violation, the client may terminate the contract, demand compensation for damages, or even file a lawsuit. Such scenarios not only lead to significant financial losses but also cause irreparable damage to the reputation of the Ukrainian company in the international market, making it difficult to attract new clients and retain existing ones. Therefore, adhering to NIS2 is not just a legal requirement but a critical business necessity for Ukrainian IT exports.
Adapting to NIS2 requirements is an integral part of the development strategy for any Ukrainian IT company working or planning to work in the European Union market. This requires a comprehensive approach: from reviewing internal cybersecurity policies and investing in technology to training personnel and implementing strict incident management protocols. Proactively implementing these standards will not only protect companies from potential risks and fines but will also significantly increase their competitiveness, strengthen the trust of European partners, and open new opportunities for growth amidst tightening global cybersecurity requirements. The Ukrainian IT sector has every opportunity to turn these challenges into new growth points.
Frequently asked questions
What is the NIS2 Directive and why is it important for Ukraine?
The NIS2 Directive is an EU legislative act aimed at increasing the level of cybersecurity in Europe by establishing unified standards and requirements. It is important for Ukraine due to its integration into the European digital market and the large number of IT companies providing services to EU clients. NIS2 compliance is becoming a mandatory condition for successful cooperation and competitiveness.
Which Ukrainian companies are subject to NIS2?
European companies classified as "essential" or "important" entities are directly subject to NIS2. However, Ukrainian IT providers that serve these European companies (especially those in critical sectors) will need to comply with its requirements through contractual obligations and requests from their clients. This applies to software developers, cloud providers, infrastructure solution suppliers, and other IT services.
What are the main NIS2 cybersecurity requirements?
NIS2 requires the implementation of comprehensive risk management measures, including information system security policies, incident management, business continuity, supply chain security, the use of multi-factor authentication, encryption, and regular staff training. These measures must be proportional to the risks faced by the entity.
What are the consequences of NIS2 non-compliance for Ukrainian IT companies?
Non-compliance with NIS2 requirements can lead to the loss of European clients, contract termination, significant reputational damage, and potential financial losses if the Ukrainian company causes a violation for its European partner. Although direct EU fines do not apply to Ukrainian companies, the indirect consequences can be very significant for their export business.