We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Compliance
  2. NIS2 compliance
NIS2 readiness, UAE

NIS2 gives your EU customer 24 hours to raise an early warning. Their clock starts with your phone call.

Article 23 sets 24 hours for an early warning, 72 hours for an incident notification and one month for a final report. Supply chain security is one of the ten required measures, which is how a UAE supplier ends up inside somebody else regulatory deadline.

Book a NIS2 exposure reviewSee the ten measures
NIS2 readiness for UAE organisations
  • 24 hoursEarly warning after becoming aware
  • 72 hoursIncident notification deadline
  • 1 monthFinal report after the notification
  • 10 measuresRequired under Article 21(2)
The part UAE suppliers underestimate

Your customer has 24 hours. That means you have far less.

The reporting clock is the single most demanding thing NIS2 pushes onto a supply chain, and it is not something you can arrange after an incident starts.

  • The early warning is due within 24 hours of the entity becoming aware of a significant incident. If the incident is in your platform, their awareness depends on your notification, and every hour you take is an hour removed from their assessment and filing time.
  • An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or has affected or is capable of affecting others by causing considerable material or non-material damage. Capable of causing is a low bar, deliberately.
  • Then a full incident notification at 72 hours and a final report within one month of that notification. Those later stages need information from you as well, in a form your customer can put in front of a national authority.
  • None of this works as an ad hoc arrangement. It needs a named contact, an agreed notification threshold, a channel that operates outside business hours, and a template both sides have seen before the day it is used in anger.
Ask us to design the notification path
What NIS2 requires

Eight things that matter to a UAE organisation.

NIS2 has applied in Member States since 18 October 2024. It binds essential and important entities in the EU, and it reaches their suppliers through the supply chain security measure and through incident reporting deadlines that depend on supplier cooperation.

The deadlines are short and they are hard

An early warning without undue delay and in any event within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report not later than one month after the notification. Those are the numbers everything else works backwards from.

Supply chain security is a named measure

Article 21(2) requires supply chain security including security related aspects concerning the relationships between each entity and its direct suppliers or service providers. Being a direct supplier to an in scope entity is what brings a UAE company into the conversation.

The management body can be held liable

Management bodies approve the cybersecurity risk management measures, oversee their implementation, and can be held liable for infringements. That single provision explains why NIS2 questions now arrive from boards rather than from technical teams.

Ten measures, and they are broad

Risk analysis policies, incident handling, business continuity including backup and crisis management, supply chain security, secure acquisition and development with vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication.

An all-hazards approach, including the physical

The measures are based on an all-hazards approach aiming to protect network and information systems and the physical environment of those systems from incidents. Physical and environmental risk is inside the scope rather than adjacent to it.

Customers have to be told as well as regulators

Entities notify the recipients of their services, without undue delay, of significant incidents likely to adversely affect the provision of those services. Incident communication is therefore a dual obligation rather than a purely regulatory one.

Size matters, except when it does not

The Directive applies to entities of a type in Annex I or II that qualify as medium-sized enterprises or exceed those ceilings. It also applies regardless of size to communications providers, trust services, DNS services, sole providers of essential services and others.

Transposed nationally, so the detail varies

NIS2 is a directive rather than a regulation. Member States adopted measures by 17 October 2024 and applied them from 18 October 2024, and national implementations differ, so the customer country matters when you are working out what is actually being asked.

Article 21(2)

The ten required measures, and what each usually means in practice.

The Directive states the measures. The right column is what an assessment typically looks for when testing whether they exist, based on how these obligations are evidenced.
MeasureWhat is usually examined
Risk analysis and information system security policiesA current risk assessment and an approved policy set
Incident handlingA tested process with roles, thresholds and timings
Business continuity, backup and crisis managementRecovery objectives, tested restores, a crisis structure
Supply chain securityAssessment of direct suppliers and contractual security terms
Secure acquisition, development and maintenanceVulnerability handling and disclosure in the lifecycle
Assessing effectiveness of the measuresEvidence the controls are reviewed, not just implemented
Cyber hygiene and trainingA programme with completion records
Cryptography and encryption policyA stated position on where and how it is applied
HR security, access control, asset managementJoiner mover leaver control and an accurate asset picture
Multi-factor or continuous authenticationCoverage across remote access and privileged accounts
How we approach it

Four things that make a NIS2 response useful rather than performative.

Directives generate a lot of documentation. The parts that change an outcome are narrower than the parts that generate paperwork.

We start with the notification path

Because it is the only part with a 24 hour clock attached. A named contact, an agreed threshold and a rehearsed template are worth more to a customer than a policy set they will never read, and they take days rather than months.

We treat supply chain security in both directions

You are somebody supply chain, and you have one of your own. The measure covers relationships with direct suppliers and service providers, so an assessment that only looks outward at your customer misses half of what is being asked.

We put the governance record in place properly

Management bodies approve the measures, oversee implementation and can be held liable. That makes a recorded approval and delivered training part of the compliance position rather than administrative tidiness after the fact.

We do not sell you a directive you are outside of

NIS2 binds essential and important entities in the EU. If you do not supply one, and are not inside an EU group that contains one, then this is not currently your obligation and we will say so rather than scoping a programme.

How an engagement runs

Four phases across roughly eight to twelve weeks.

For a supplier the work concentrates on incident notification and supply chain evidence. For a UAE entity inside an EU group it is the full set of ten measures.
  1. 01
    Weeks 1 to 2

    Establish how NIS2 reaches you

    Whether you supply an essential or important entity, whether you sit inside an EU group with in scope entities, and which Member States are involved, since transposition differs and the national law is what actually applies to your customer.

    • Customer and group exposure mapped
    • Member States involved identified
    • Contractual security obligations reviewed
    • Scope agreed as supplier support or full measures
  2. 02
    Weeks 3 to 5

    Build the incident notification path

    The highest value work and the most time critical. A defined significance threshold, a named contact on both sides, an out of hours channel, an agreed template, and a rehearsal so the first use is not the first attempt.

    • Notification threshold agreed and documented
    • Contacts and out of hours channel established
    • Notification template drafted and shared
    • Tabletop rehearsal completed with the customer
  3. 03
    Weeks 6 to 9

    Gap the ten measures

    Assessed against Article 21(2) with evidence rather than assertion. The measures most often found weak are effectiveness assessment, vulnerability handling and disclosure, and supply chain security applied to your own direct suppliers.

    • Gap assessment across all ten measures
    • Evidence located or identified as missing
    • Remediation plan with owners and dates
    • Management body briefing prepared
  4. 04
    Weeks 10 to 12

    Governance and durability

    Management bodies approve the measures, oversee implementation and can be held liable, so the governance record matters as much as the controls. Training for management body members is a stated requirement rather than a recommendation.

    • Management approval recorded formally
    • Management body training delivered
    • Effectiveness review cadence established
    • Evidence pack assembled for customer due diligence
Where this comes up

Six situations we see in the UAE.

Almost all of them begin with a security questionnaire that is noticeably longer and more specific than the previous year version.

A UAE software provider serving EU manufacturing

Manufacturing sits within the NIS2 sectors, and supply chain security is one of the ten measures. The customer now has to assess security aspects of its relationship with you, and it has to be able to show its regulator that it did.

A logistics technology company with European operators

Transport is in scope, and operational technology is exactly where an all-hazards approach covering the physical environment of network and information systems becomes more than a phrase. Physical access and environmental controls get examined.

A UAE entity inside an EU parent group

Where an EU group entity is essential or important, group security policy usually pushes the full set of ten measures across the group. The UAE operation is then implementing NIS2 requirements without being directly regulated by anybody.

A managed service provider during a customer incident

The customer has 24 hours for an early warning and 72 for the notification, and they also have to tell their own service recipients. Every one of those obligations depends on getting accurate information out of the provider quickly.

A hosting or connectivity provider

Providers of public electronic communications networks and services, trust services and DNS services are covered regardless of size. Where a UAE company operates in the EU in those categories, the size exemption that protects others does not apply.

A board asking what its exposure actually is

Management bodies of essential and important entities can be held liable for infringements of the risk management measures. Boards of UAE entities in EU groups reasonably want to know how much of that reaches them and how it is discharged.

Three positions

How UAE suppliers sit against a NIS2 customer.

The middle column describes most organisations honestly. It is survivable until there is an incident, at which point the gap becomes visible to a regulator through your customer.
Customer can meet the 24 hour warning
PreparedYes
Controls exist, process does notOnly by luck
NeitherNo
Notification contact named
PreparedBoth sides
Controls exist, process does notA mailbox
NeitherNone
Significance threshold agreed
PreparedDocumented
Controls exist, process does notJudged in the moment
NeitherUndefined
Evidence for the ten measures
PreparedAssembled
Controls exist, process does notScattered
NeitherAbsent
Own suppliers assessed
PreparedYes
Controls exist, process does notPartially
NeitherNo
Board has approved the measures
PreparedRecorded
Controls exist, process does notAssumed
NeitherNo
Due diligence response time
PreparedDays
Controls exist, process does notWeeks
NeitherLoses the account
Behaviour during an incident
PreparedRehearsed
Controls exist, process does notImprovised
NeitherDelayed
Exposure to contractual claim
PreparedLow
Controls exist, process does notReal
NeitherHigh
Suits a supplier to EU entities
PreparedYes
Controls exist, process does notTemporarily
NeitherNo
Feature
Prepared
Controls exist, process does not
Neither
Customer can meet the 24 hour warning
YesOnly by luckNo
Notification contact named
Both sidesA mailboxNone
Significance threshold agreed
DocumentedJudged in the momentUndefined
Evidence for the ten measures
AssembledScatteredAbsent
Own suppliers assessed
YesPartiallyNo
Board has approved the measures
RecordedAssumedNo
Due diligence response time
DaysWeeksLoses the account
Behaviour during an incident
RehearsedImprovisedDelayed
Exposure to contractual claim
LowRealHigh
Suits a supplier to EU entities
YesTemporarilyNo
Directive, not regulation

The text you need is your customer national law, not the Directive itself.

This distinction changes how a supplier should respond to a NIS2 request, and it is the one most often missed.

  • A directive sets out what Member States must achieve and leaves them to transpose it into national law. Member States were required to adopt and publish the necessary measures by 17 October 2024 and to apply them from 18 October 2024, each in their own legislation.
  • That means two customers in different Member States can ask you for materially different things while both citing NIS2 correctly. Establishing which national implementation sits behind a request avoids a negotiation conducted against the wrong text entirely.
  • It also affects how obligations reach you. Supply chain security including security related aspects of relationships with direct suppliers is in the Directive, and how strictly that is applied to suppliers is shaped by national transposition and by sector regulators.
  • The practical approach for a UAE supplier is to build to the Directive requirements, since they are the common denominator, and then handle national specifics as customer by customer variations rather than trying to satisfy every Member State separately.
How an engagement runs

Five steps, ordered by how quickly each one matters.

If you only do one thing, do the second. The incident notification path is the part with a clock on it and the part your customer feels immediately.
  1. 1

    Establish the route by which NIS2 reaches you

    Direct supply to an essential or important entity, membership of an EU group, or activity in one of the categories covered regardless of size. Which Member State is involved matters, because the Directive was transposed into national law rather than applying uniformly.

  2. 2

    Build and rehearse the incident notification path

    A documented significance threshold, named contacts on both sides, an out of hours channel, an agreed template and one rehearsal. This is the deliverable that most directly determines whether your customer can meet a 24 hour early warning.

  3. 3

    Assess against the ten Article 21(2) measures

    With evidence rather than self assessment. The measures most often found thin are assessing the effectiveness of the measures themselves, vulnerability handling and disclosure, and applying supply chain security to your own direct suppliers.

  4. 4

    Remediate in priority order

    Sequenced by what a customer assessment will look at first and by what carries the most risk if an incident happens tomorrow. Multi-factor authentication coverage and tested backup restores are usually near the top of both lists.

  5. 5

    Record governance and keep the evidence current

    Management approval recorded, management body training delivered, an effectiveness review cadence set, and a due diligence pack maintained. Evidence that is assembled fresh for every questionnaire quietly consumes more effort than maintaining it does.

Straight answers

What UAE organisations ask about NIS2.

Not directly. It binds essential and important entities in EU Member States. It reaches UAE companies as a supply chain requirement, because supply chain security including relationships with direct suppliers is one of the ten measures those entities must implement.

Member States were required to adopt and publish measures by 17 October 2024 and to apply them from 18 October 2024. Because it is a directive, the operative law is each Member State national implementation rather than the Directive itself.

An early warning without undue delay and within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report not later than one month after that notification. Those timings drive everything else.

One that has caused or is capable of causing severe operational disruption of the services or financial loss, or that has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage.

Yes. Entities notify the recipients of their services, without undue delay, of significant incidents likely to adversely affect the provision of those services. Regulatory notification and customer notification are separate obligations running in parallel.

Article 20 states that management bodies approve the risk management measures, oversee their implementation and can be held liable for infringements. That is why a recorded approval and delivered board training are part of the compliance position.

Members of management bodies are required to follow training. Entities are encouraged, rather than required, to offer similar training to employees on a regular basis, which is a meaningful difference in how the two obligations are worded.

That the measures aim to protect network and information systems and the physical environment of those systems from incidents. Physical access, power, cooling and environmental risk are inside scope rather than treated as a separate facilities concern.

Generally the Directive applies to entities in the Annex I or II types that are medium-sized enterprises or larger. But it applies regardless of size to communications and trust service providers, DNS services, sole providers of essential services and several other cases.

DORA is a regulation targeted at the financial sector with directly applicable requirements and detailed contractual provisions. NIS2 is a directive covering a much broader range of sectors, transposed into national law, with a stronger emphasis on governance and reporting.

Build the incident notification path. A named contact, an agreed threshold, an out of hours channel and a template. It takes days, it is what your customer needs most, and it is the only part with a 24 hour clock attached to it.

It covers a good proportion of the ten measures and it will help substantially in a customer assessment. It does not by itself address the incident notification timings your customer depends on, or the governance and liability provisions in Article 20.

Yes. The measure covers security related aspects of the relationship between each entity and its direct suppliers or service providers, so your subcontractors and platform providers become part of what a customer is assessing when they assess you.

The one that applies to your customer. Since transposition differs, two customers in different Member States can ask for materially different things, and knowing which national implementation is behind a request avoids arguing about the wrong text.

We scope by whether this is supplier support or a full assessment against the ten measures. The free first step: work out who your EU customer would telephone at 2am, and whether that person knows they are on the list.

The measure covers security related aspects concerning the relationships between each entity and its direct suppliers or service providers. Where you contract directly with an essential or important entity, that is the relationship the measure is describing.

Increasingly, yes. Your customer applies the supply chain measure to you, and your subprocessors and platform providers form part of what they are assessing, which is why the measure works in both directions rather than only downward.

Both are in scope for the risk management and reporting obligations. The distinction affects supervisory treatment rather than the substance of what is required, so for a supplier the practical obligations arriving through contracts look much the same.

Yes. The measures are based on an all-hazards approach aiming to protect network and information systems and the physical environment of those systems from incidents, which brings access control, power and environmental risk into scope explicitly.

Your customer makes that determination, using the test of severe operational disruption or financial loss, or considerable material or non material damage to others. Your obligation is to give them the facts fast enough for them to apply it.

It follows the incident notification within one month and covers the detailed description, threat type, mitigation and cross border impact. Suppliers usually contribute root cause and remediation detail, which is why post incident analysis matters commercially.

Build the notification path regardless, because it is cheap and useful for every incident. The wider measures are worth doing on their own merits, and having them already in place shortens the conversation when a customer eventually does ask.
Readiness check

Fifteen questions to answer before an incident, not during one.

The first group is the one that decides whether your customer can meet a 24 hour deadline. The rest can be worked through over months.

Incident notification

  • Who do we call, by name?
    Not a shared mailbox.
  • What triggers a notification?
    Agree the threshold in advance.
  • Does the channel work at 3am?
    Incidents rarely respect hours.
  • Is there a template?
    Drafting under pressure loses hours.
  • Have we rehearsed it?
    Once, with the customer.

The measures

  • Is there a current risk assessment?
    Measure one of ten.
  • Are backups tested by restore?
    Not just monitored.
  • Do we assess our own suppliers?
    Supply chain is named.
  • Is there vulnerability disclosure?
    Handling and disclosure both.
  • Is MFA on all remote access?
    Explicitly listed.

Governance

  • Has the board approved the measures?
    An explicit requirement.
  • Is that approval recorded?
    Liability attaches to it.
  • Have board members had training?
    Required, not encouraged.
  • Do we review effectiveness?
    A measure in its own right.
  • Who owns this ongoing?
    Name somebody.
Related reading

The pages around this one.

DORA compliance

The financial sector equivalent, and stricter on contracts.

Learn more

Incident response plan

What the notification path has to sit on top of.

Learn more

Third-party risk audit

Supply chain security in both directions.

Learn more
Next step

Work out who your EU customer would telephone at 2am.

Then check whether that person knows they are on the list, and whether they know what to say. Their 24 hour early warning clock starts with your call.

Book a NIS2 exposure reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

DORA compliance

What EU financial customers now require from UAE ICT suppliers.

Learn more

Incident Response Plan

Written, exercised, and findable when the network is not

Learn more

Third Party Risk Audit

Who can actually reach your systems, and what to do about it

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more

IT Risk Assessment

A short register with an owner against every risk

Learn more

Business Continuity Planning

BCP, RPO/RTO design, and DR runbook authoring

Learn more

Compliance as a Service

Keeping the position true between assessments

Learn more

Virtual CISO Dubai

Security governance and accountability, not more tools

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy