BusinessWire India
Bengaluru (Karnataka) [India], October 7: Opsio, the Sweden-headquartered managed cloud, cybersecurity and AI services company, today announced a marked increase in demand for its NIS2 compliance services from organisations in India. The demand is led by IT and managed service providers, SaaS companies, Global Capability Centres (GCCs) and manufacturers whose customers in the European Union are subject to the bloc's Network and Information Security Directive (NIS2).
NIS2 and Europe's compliance landscape
NIS2 (Directive (EU) 2022/2555) is the European Union's principal cybersecurity law. It replaced the original NIS Directive of 2016 and extends mandatory security and incident reporting obligations to medium and large organisations across 18 sectors, from energy, transport, banking, health and digital infrastructure to manufacturing, food, chemicals and digital services. Organisations are classed as essential or important entities, with supervision and penalties scaled accordingly.
NIS2 is one part of a wider European rulebook. The General Data Protection Regulation (GDPR) governs personal data, the Digital Operational Resilience Act (DORA) has applied to financial institutions and their ICT providers since January 2025, the Cyber Resilience Act sets security requirements for connected products, and the EU AI Act governs artificial intelligence. Together, they make security and data governance a condition of doing business in Europe.
Member states were required to transpose NIS2 into national law by 17 October 2024. Most have now done so, and supervisory authorities are moving from guidance to active enforcement. For Indian businesses, the impact is increasingly direct.
Why NIS2 matters to Indian businesses
Although NIS2 is an EU directive, its reach extends well beyond Europe. Article 21 requires in-scope EU entities to manage cybersecurity risk across their supply chains, and European customers are now building NIS2-aligned security requirements into contracts, vendor assessments and renewals with their Indian partners. In addition, cloud, data centre, managed service and managed security service providers established outside the EU that offer services within the Union fall under the directive and must designate a representative in a member state.
The obligations are substantial. NIS2 requires an early warning of significant incidents within 24 hours, an incident notification within 72 hours and a final report within one month. Management bodies must approve and oversee cybersecurity measures and can be held accountable for failures, while fines for essential entities can reach €10 million or 2 per cent of worldwide annual turnover, whichever is higher.
The conclusion of the India–EU Free Trade Agreement in January 2026 has added urgency. As Indian companies prepare to grow their European business, demonstrable cyber resilience is becoming a commercial prerequisite as much as a regulatory one.
“Over the past few quarters, our conversations with Indian clients have shifted from ‘Does NIS2 apply to us?’ to ‘How quickly can we show our European customers that we are ready?’” said Praveena Shenoy, Country Manager, India, Opsio. “Indian enterprises have long been trusted partners to Europe's leading organisations, and NIS2 raises the bar on how that trust is evidenced. Companies that already follow CERT-In's incident reporting directions and are preparing for the Digital Personal Data Protection Rules have a strong foundation. Our role is to bring these frameworks together into a single, audit-ready programme, so that compliance becomes a competitive advantage rather than simply a cost of doing business.”
A full-journey approach to NIS2 compliance
As a NIS2 compliance consultant, Opsio covers the complete compliance lifecycle, delivered in four phases:
- Scoping and classification: determining whether an organisation, or the customers it serves, falls within NIS2 scope as an essential or important entity
- Gap assessment and roadmap: evaluating security posture against the Article 21 measures and building a prioritised remediation plan
- Implementation: risk management, incident reporting procedures, supply chain security, board-level governance and technical security controls
- Continuous compliance: ongoing monitoring, tracking of regulatory changes across member states and audit support, backed by Opsio's 24/7 Security Operations Centre
Opsio maps NIS2 controls to ISO/IEC 27001 and the NIST Cybersecurity Framework, and delivers them alongside its GDPR compliance and DPDP Act services, so organisations build on existing investments rather than run parallel programmes. The company also brings first-hand experience from supporting organisations in Sweden, where the national Cybersecurity Act implementing NIS2 came into force in January 2026. Organisations can begin with a complimentary NIS2 readiness assessment at opsiocloud.com/in/nis2-directive.
(ADVERTORIAL DISCLAIMER: The above press release has been provided by BusinessWire India. ANI will not be responsible in any way for the content of the same)