Key takeaways
- • For high-risk AI operators, NIS2 is an additional layer of obligations on the same infrastructure.
- • Affected are financial service providers, healthcare, HR software, critical infrastructure and B2B SaaS providers with EU customers.
- • NIS2, the EU AI Act and sector regulation meet on the same infrastructure: three regimes, one surface.
- • The pressure is shifting away from paper policies toward robust technical evidence.
Thesis The decisive question is: Can you prove it?
NIS2 is the EU's central directive for network and information security. For regulated companies with high-risk AI systems under the EU AI Act, it means an additional layer of obligations on the same infrastructure your AI runs on.
What the NIS2 directive aims to achieve
The NIS2 directive pursues three clearly defined goals:
- Higher security level for critical and important entities across the entire EU
- Binding minimum standards for technical and organizational protective measures
- Uniform framework for reporting obligations for security incidents, with concrete deadlines
For you, this means: your digital infrastructure must maintain a demonstrable security standard at all times, one that can be proven to supervisory authorities and auditors. The pressure is shifting away from paper policies toward robust evidence of technical states.
Relevance for companies with high-risk AI systems
If you operate high-risk AI under the EU AI Act, several regimes meet on the same surface: NIS2, sector-specific regulation (for example financial supervision or health law) and the EU AI Act itself. Particularly affected are:
- Financial service providers with AI-driven scoring, trading or monitoring systems
- Healthcare institutions and health-tech with AI-driven diagnostics or triage
- HR software providers with automated decision processes
- Critical infrastructure operators with AI in control or monitoring chains
- B2B SaaS providers with AI functionality for EU customers
For all these organizations, the same question keeps coming up: Can you prove it? This is exactly where a technical infrastructure evidence approach comes in that jointly addresses NIS2, DORA and the EU AI Act, for example through procedures described in NIS2 and DORA.
Key terms and the regulatory framework
Important and especially important entities
NIS2 distinguishes between categories of entities with graduated supervisory depth. Whether you count as important or especially important depends on sector, company size and the criticality of the services provided. For high-risk AI operators, this raises the expectation of formalized security and evidence processes.
- Reactive, downstream supervision
- Fines up to €10 million or 2% of worldwide annual turnover
- Sectors: HR platforms, SaaS, postal & courier, chemicals
- Self-reporting and evidence obligation upon request
- Proactive, regular authority inspections
- Fines up to €20 million or 4% of worldwide annual turnover
- Sectors: banks, healthcare, energy, KRITIS
- Ongoing evidence obligation without separate request
Network and information systems
NIS2 defines network and information systems as the entire technical infrastructure on which your services run. This includes hosting, network, DNS, identity and access management, logging, monitoring and the application stack on which your AI system operates in production.
Regulatory framework and interfaces
NIS2 interlocks with:
- EU AI Act requirements for high-risk AI
- Sector-specific regulation such as financial or health supervision
- National implementation standards in Germany
For compliance teams, this makes it clear: you need machine-readable, reproducible evidence of the state of your infrastructure at the time of the audit. This is exactly where CERTavia delivers cryptographically verifiable infrastructure evidence that feeds into your NIS2 and AI Act dossier as a building block. More on this at CERTavia infrastructure evidence.
Target groups and scope of application of the NIS2 directive
NIS2 targets services of high societal and economic importance. For organizations with high-risk AI, this means you fall within scope via two axes: through your sector and through the criticality of your digital services.
Which companies typically fall under NIS2
NIS2 primarily addresses entities classified as important or especially important. Whether your organization belongs depends on:
- the sector (for example financial markets, health, energy, transport, administration)
- the role in the value chain (operator of critical services or essential digital platforms)
- company size and the reach of your services
For AI-driven business models, this means: as soon as your platform or service becomes system-relevant for customers or infrastructure, you move into NIS2's focus.
| Sector | NIS2 classification | Typical high-risk AI (Annex III) |
|---|---|---|
| Financial markets (banks, payment providers, insurers) | Especially important | Scoring, trading, automated credit decisions |
| Health (hospitals, labs, health-tech) | Especially important | Diagnostic AI, triage, image analysis |
| Critical infrastructure (energy, water, transport) | Especially important | Control AI, anomaly detection, monitoring |
| HR platforms (large, cross-sector) | Important | Candidate-selection AI, workforce planning |
| B2B SaaS for regulated customers | Important (indirect) | Depends on customers' AI use on the platform |
Financial services
Banks, payment providers, insurers and marketplace platforms with AI-driven high-risk systems operate in a dual regime of financial supervision and NIS2. Concretely, this means:
- Availability, integrity and traceability of the infrastructure are examined equally
- Scoring, trading and decision systems need a documented infrastructure state at the time of the audit
- DORA and NIS2 overlap heavily: shared technical evidence reduces duplicate effort
Healthcare
Hospitals, labs, telemedicine and health-tech providers with diagnostic or triage-related AI are particularly exposed. The central requirements:
- Failure or compromise creates immediate patient risk. NIS2 classifies this as especially critical
- Structured security measures must be demonstrably proven, beyond mere documentation
- Networks and systems must maintain the protection level at the time of the audit. Retrospective statements fall short
HR software and high-risk AI
HR platforms with automated candidate selection or workforce planning fall into the high-risk classification via the EU AI Act. What this means for NIS2:
- NIS2 applies as soon as the platform is classified as an essential digital service, especially when used in critical sectors
- What is examined is how your infrastructure controls identities, access, logging and deployment of the AI models
- Missing evidence on IAM and deployment paths is the most common audit finding
Critical infrastructure
Operators of critical infrastructure use AI for monitoring, anomaly detection or control. NIS2, sector-specific special laws and the EU AI Act are closely intertwined here:
- Proof of a stable, correctly configured stack becomes an integral part of every audit
- Sector-specific authorities (BSI, BNetzA, BaFin) expect consistent evidence from a single evidence set
- A machine-readable infrastructure evidence via the Sovereign Validation Protocol reduces room for interpretation
B2B SaaS providers with AI functionality
B2B SaaS providers fall within NIS2 scope when their services function as essential digital services for regulated customers. The key implications:
- If your customers operate high-risk AI on your platform, your infrastructure effectively becomes part of the audit scope
- NIS2 significantly tightens requirements for suppliers and ICT third-party providers
- Contractual assurances alone fall short: technical evidence of the infrastructure's state is expected
Delimitation and classification of high-risk AI systems
Whether a system counts as high-risk is determined primarily via the EU AI Act, in particular Annex III. In practice, a three-step approach has proven effective:
- Mapping AI systems by business process and impact on persons
- Comparison against the Annex III categories using a fixed set of criteria
- Assignment of the relevant infrastructure scope for NIS2, including hosting, network, IAM and logging
A structured quick check, such as the EU AI Act quick test offers, provides initial clarity here. Whoever performs this classification early can consistently map NIS2, DORA and AI Act requirements onto the same infrastructure evidence and maintain a single documentation world instead of three separate ones.
CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, please consult an accredited conformity assessment body.