NIS2 Compliance Handbook 2026 by Kai London
NIS2 moved cyber security from an IT budget line to a management board obligation with personal consequences. This handbook translates the directive into a programme: what brings you into scope, what the measures actually demand, and what you have to be able to show a supervisory authority.
Available on Amazon. An independent practitioner guide — not legal advice, and not affiliated with or endorsed by any regulator or supervisory authority.
What is inside
Scope and classification
Essential versus important entities, sector tests, size thresholds, and how national transposition changes the answer.
Article 21 risk-management measures
The required measures translated into controls, owners and evidence — rather than a restated list of the article.
Supply chain obligations
Assessing and contracting suppliers and service providers, and proving that the assessment is more than a questionnaire.
Incident reporting under pressure
Early warning, notification and final report obligations, and the internal decision process that meets the clock.
Management accountability
Approval, oversight and training duties for directors, and what personal responsibility means in practice.
Supervisory readiness
Inspections, audits and enforcement — assembling the evidence file before an authority asks for it.
Who it is for: CISOs and compliance leads at in-scope entities, group functions covering multiple member states, suppliers pulled in through customer obligations, and boards carrying the accountability.
NIS2 did not ask the board to understand cyber risk. It made them answerable for it.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.