Regulatory compliance · EU

NIS2 Compliance Handbook 2026 by Kai London

NIS2 moved cyber security from an IT budget line to a management board obligation with personal consequences. This handbook translates the directive into a programme: what brings you into scope, what the measures actually demand, and what you have to be able to show a supervisory authority.

Available on Amazon. An independent practitioner guide — not legal advice, and not affiliated with or endorsed by any regulator or supervisory authority.

What is inside

Scope and classification

Essential versus important entities, sector tests, size thresholds, and how national transposition changes the answer.

Article 21 risk-management measures

The required measures translated into controls, owners and evidence — rather than a restated list of the article.

Supply chain obligations

Assessing and contracting suppliers and service providers, and proving that the assessment is more than a questionnaire.

Incident reporting under pressure

Early warning, notification and final report obligations, and the internal decision process that meets the clock.

Management accountability

Approval, oversight and training duties for directors, and what personal responsibility means in practice.

Supervisory readiness

Inspections, audits and enforcement — assembling the evidence file before an authority asks for it.

Who it is for: CISOs and compliance leads at in-scope entities, group functions covering multiple member states, suppliers pulled in through customer obligations, and boards carrying the accountability.

NIS2IEC 62443ISO/IEC 27001DORACRA
“

NIS2 did not ask the board to understand cyber risk. It made them answerable for it.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.