NIS2 gives your EU customer 24 hours to raise an early warning. Their clock starts with your phone call.
Article 23 sets 24 hours for an early warning, 72 hours for an incident notification and one month for a final report. Supply chain security is one of the ten required measures, which is how a UAE supplier ends up inside somebody else regulatory deadline.

- 24 hoursEarly warning after becoming aware
- 72 hoursIncident notification deadline
- 1 monthFinal report after the notification
- 10 measuresRequired under Article 21(2)
Your customer has 24 hours. That means you have far less.
The reporting clock is the single most demanding thing NIS2 pushes onto a supply chain, and it is not something you can arrange after an incident starts.
- The early warning is due within 24 hours of the entity becoming aware of a significant incident. If the incident is in your platform, their awareness depends on your notification, and every hour you take is an hour removed from their assessment and filing time.
- An incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or has affected or is capable of affecting others by causing considerable material or non-material damage. Capable of causing is a low bar, deliberately.
- Then a full incident notification at 72 hours and a final report within one month of that notification. Those later stages need information from you as well, in a form your customer can put in front of a national authority.
- None of this works as an ad hoc arrangement. It needs a named contact, an agreed notification threshold, a channel that operates outside business hours, and a template both sides have seen before the day it is used in anger.
Eight things that matter to a UAE organisation.
The deadlines are short and they are hard
An early warning without undue delay and in any event within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report not later than one month after the notification. Those are the numbers everything else works backwards from.
Supply chain security is a named measure
Article 21(2) requires supply chain security including security related aspects concerning the relationships between each entity and its direct suppliers or service providers. Being a direct supplier to an in scope entity is what brings a UAE company into the conversation.
The management body can be held liable
Management bodies approve the cybersecurity risk management measures, oversee their implementation, and can be held liable for infringements. That single provision explains why NIS2 questions now arrive from boards rather than from technical teams.
Ten measures, and they are broad
Risk analysis policies, incident handling, business continuity including backup and crisis management, supply chain security, secure acquisition and development with vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, human resources security and access control, and multi-factor authentication.
An all-hazards approach, including the physical
The measures are based on an all-hazards approach aiming to protect network and information systems and the physical environment of those systems from incidents. Physical and environmental risk is inside the scope rather than adjacent to it.
Customers have to be told as well as regulators
Entities notify the recipients of their services, without undue delay, of significant incidents likely to adversely affect the provision of those services. Incident communication is therefore a dual obligation rather than a purely regulatory one.
Size matters, except when it does not
The Directive applies to entities of a type in Annex I or II that qualify as medium-sized enterprises or exceed those ceilings. It also applies regardless of size to communications providers, trust services, DNS services, sole providers of essential services and others.
Transposed nationally, so the detail varies
NIS2 is a directive rather than a regulation. Member States adopted measures by 17 October 2024 and applied them from 18 October 2024, and national implementations differ, so the customer country matters when you are working out what is actually being asked.
The ten required measures, and what each usually means in practice.
| Measure | What is usually examined | |
|---|---|---|
| Risk analysis and information system security policies | A current risk assessment and an approved policy set | |
| Incident handling | A tested process with roles, thresholds and timings | |
| Business continuity, backup and crisis management | Recovery objectives, tested restores, a crisis structure | |
| Supply chain security | Assessment of direct suppliers and contractual security terms | |
| Secure acquisition, development and maintenance | Vulnerability handling and disclosure in the lifecycle | |
| Assessing effectiveness of the measures | Evidence the controls are reviewed, not just implemented | |
| Cyber hygiene and training | A programme with completion records | |
| Cryptography and encryption policy | A stated position on where and how it is applied | |
| HR security, access control, asset management | Joiner mover leaver control and an accurate asset picture | |
| Multi-factor or continuous authentication | Coverage across remote access and privileged accounts |
Four things that make a NIS2 response useful rather than performative.
We start with the notification path
Because it is the only part with a 24 hour clock attached. A named contact, an agreed threshold and a rehearsed template are worth more to a customer than a policy set they will never read, and they take days rather than months.
We treat supply chain security in both directions
You are somebody supply chain, and you have one of your own. The measure covers relationships with direct suppliers and service providers, so an assessment that only looks outward at your customer misses half of what is being asked.
We put the governance record in place properly
Management bodies approve the measures, oversee implementation and can be held liable. That makes a recorded approval and delivered training part of the compliance position rather than administrative tidiness after the fact.
We do not sell you a directive you are outside of
NIS2 binds essential and important entities in the EU. If you do not supply one, and are not inside an EU group that contains one, then this is not currently your obligation and we will say so rather than scoping a programme.
Four phases across roughly eight to twelve weeks.
- 01Weeks 1 to 2
Establish how NIS2 reaches you
Whether you supply an essential or important entity, whether you sit inside an EU group with in scope entities, and which Member States are involved, since transposition differs and the national law is what actually applies to your customer.
- Customer and group exposure mapped
- Member States involved identified
- Contractual security obligations reviewed
- Scope agreed as supplier support or full measures
- 02Weeks 3 to 5
Build the incident notification path
The highest value work and the most time critical. A defined significance threshold, a named contact on both sides, an out of hours channel, an agreed template, and a rehearsal so the first use is not the first attempt.
- Notification threshold agreed and documented
- Contacts and out of hours channel established
- Notification template drafted and shared
- Tabletop rehearsal completed with the customer
- 03Weeks 6 to 9
Gap the ten measures
Assessed against Article 21(2) with evidence rather than assertion. The measures most often found weak are effectiveness assessment, vulnerability handling and disclosure, and supply chain security applied to your own direct suppliers.
- Gap assessment across all ten measures
- Evidence located or identified as missing
- Remediation plan with owners and dates
- Management body briefing prepared
- 04Weeks 10 to 12
Governance and durability
Management bodies approve the measures, oversee implementation and can be held liable, so the governance record matters as much as the controls. Training for management body members is a stated requirement rather than a recommendation.
- Management approval recorded formally
- Management body training delivered
- Effectiveness review cadence established
- Evidence pack assembled for customer due diligence
Six situations we see in the UAE.
A UAE software provider serving EU manufacturing
Manufacturing sits within the NIS2 sectors, and supply chain security is one of the ten measures. The customer now has to assess security aspects of its relationship with you, and it has to be able to show its regulator that it did.
A logistics technology company with European operators
Transport is in scope, and operational technology is exactly where an all-hazards approach covering the physical environment of network and information systems becomes more than a phrase. Physical access and environmental controls get examined.
A UAE entity inside an EU parent group
Where an EU group entity is essential or important, group security policy usually pushes the full set of ten measures across the group. The UAE operation is then implementing NIS2 requirements without being directly regulated by anybody.
A managed service provider during a customer incident
The customer has 24 hours for an early warning and 72 for the notification, and they also have to tell their own service recipients. Every one of those obligations depends on getting accurate information out of the provider quickly.
A hosting or connectivity provider
Providers of public electronic communications networks and services, trust services and DNS services are covered regardless of size. Where a UAE company operates in the EU in those categories, the size exemption that protects others does not apply.
A board asking what its exposure actually is
Management bodies of essential and important entities can be held liable for infringements of the risk management measures. Boards of UAE entities in EU groups reasonably want to know how much of that reaches them and how it is discharged.
How UAE suppliers sit against a NIS2 customer.
| Feature | Prepared | Controls exist, process does not | Neither |
|---|---|---|---|
Customer can meet the 24 hour warning | Yes | Only by luck | No |
Notification contact named | Both sides | A mailbox | None |
Significance threshold agreed | Documented | Judged in the moment | Undefined |
Evidence for the ten measures | Assembled | Scattered | Absent |
Own suppliers assessed | Yes | Partially | No |
Board has approved the measures | Recorded | Assumed | No |
Due diligence response time | Days | Weeks | Loses the account |
Behaviour during an incident | Rehearsed | Improvised | Delayed |
Exposure to contractual claim | Low | Real | High |
Suits a supplier to EU entities | Yes | Temporarily | No |
The text you need is your customer national law, not the Directive itself.
This distinction changes how a supplier should respond to a NIS2 request, and it is the one most often missed.
- A directive sets out what Member States must achieve and leaves them to transpose it into national law. Member States were required to adopt and publish the necessary measures by 17 October 2024 and to apply them from 18 October 2024, each in their own legislation.
- That means two customers in different Member States can ask you for materially different things while both citing NIS2 correctly. Establishing which national implementation sits behind a request avoids a negotiation conducted against the wrong text entirely.
- It also affects how obligations reach you. Supply chain security including security related aspects of relationships with direct suppliers is in the Directive, and how strictly that is applied to suppliers is shaped by national transposition and by sector regulators.
- The practical approach for a UAE supplier is to build to the Directive requirements, since they are the common denominator, and then handle national specifics as customer by customer variations rather than trying to satisfy every Member State separately.
Five steps, ordered by how quickly each one matters.
- 1
Establish the route by which NIS2 reaches you
Direct supply to an essential or important entity, membership of an EU group, or activity in one of the categories covered regardless of size. Which Member State is involved matters, because the Directive was transposed into national law rather than applying uniformly.
- 2
Build and rehearse the incident notification path
A documented significance threshold, named contacts on both sides, an out of hours channel, an agreed template and one rehearsal. This is the deliverable that most directly determines whether your customer can meet a 24 hour early warning.
- 3
Assess against the ten Article 21(2) measures
With evidence rather than self assessment. The measures most often found thin are assessing the effectiveness of the measures themselves, vulnerability handling and disclosure, and applying supply chain security to your own direct suppliers.
- 4
Remediate in priority order
Sequenced by what a customer assessment will look at first and by what carries the most risk if an incident happens tomorrow. Multi-factor authentication coverage and tested backup restores are usually near the top of both lists.
- 5
Record governance and keep the evidence current
Management approval recorded, management body training delivered, an effectiveness review cadence set, and a due diligence pack maintained. Evidence that is assembled fresh for every questionnaire quietly consumes more effort than maintaining it does.
What UAE organisations ask about NIS2.
Fifteen questions to answer before an incident, not during one.
Incident notification
- Who do we call, by name?Not a shared mailbox.
- What triggers a notification?Agree the threshold in advance.
- Does the channel work at 3am?Incidents rarely respect hours.
- Is there a template?Drafting under pressure loses hours.
- Have we rehearsed it?Once, with the customer.
The measures
- Is there a current risk assessment?Measure one of ten.
- Are backups tested by restore?Not just monitored.
- Do we assess our own suppliers?Supply chain is named.
- Is there vulnerability disclosure?Handling and disclosure both.
- Is MFA on all remote access?Explicitly listed.
Governance
- Has the board approved the measures?An explicit requirement.
- Is that approval recorded?Liability attaches to it.
- Have board members had training?Required, not encouraged.
- Do we review effectiveness?A measure in its own right.
- Who owns this ongoing?Name somebody.
Work out who your EU customer would telephone at 2am.
Then check whether that person knows they are on the list, and whether they know what to say. Their 24 hour early warning clock starts with your call.
Related Services
Explore more solutions that work great with this service
DORA compliance
What EU financial customers now require from UAE ICT suppliers.
Incident Response Plan
Written, exercised, and findable when the network is not
Third Party Risk Audit
Who can actually reach your systems, and what to do about it
ISO 27001 Certification UAE
The 2022 edition, and whether you should certify at all
IT Risk Assessment
A short register with an owner against every risk
Business Continuity Planning
BCP, RPO/RTO design, and DR runbook authoring
Compliance as a Service
Keeping the position true between assessments
Virtual CISO Dubai
Security governance and accountability, not more tools