navlogo_blue

English

Dutch

Aligning Backup Strategies with NIS2 Directive Requirements

What NIS2 Actually Requires From Your Backups

Article 21 turns backup management from an IT practice into a legal obligation — with evidence requirements most backup setups can't meet yet.

A compliance officer at an energy supplier receives the audit questionnaire: describe your backup management policy, provide results of your most recent restore tests, and document how backup integrity is protected against tampering. The company has backups — it has had them for fifteen years. What it doesn't have is a written policy, a single documented restore test, or an answer to the tampering question. Under the old rules, that was sloppy. Under NIS2, it is non-compliance with personal consequences for management.

The NIS2 Directive expanded EU cybersecurity law to thousands of "essential" and "important" entities across energy, transport, health, digital infrastructure, manufacturing, and more. Among its risk-management measures, one is unambiguous: business continuity, explicitly including backup management and disaster recovery.

The misconception to clear: having backups equals complying. NIS2 asks three harder questions — is backup management governed by policy, is recovery tested and measured, and can you prove both? Most legacy setups answer none of them.

What Does NIS2 Say About Backups, Exactly?

The NIS2 Directive requires in-scope entities to take "appropriate and proportionate" cybersecurity risk-management measures. Article 21(2) lists the mandatory minimum, and point (c) names it directly: business continuity, such as backup management and disaster recovery, and crisis management.

Translated Into Operational Requirements

1

A written backup policy covering scope, frequency, and retention.

2

Defined and justified RTO/RPO targets per critical system.

3

Protection of backup integrity — tamper resistance, in the ransomware era effectively immutability.

4

Regular restore testing with documented results.

5

Integration with incident-handling and crisis procedures, including the 24-hour early-warning reporting duty.

five operational requirements
The five operational requirements auditors read into NIS2 Article 21(2)(c).

ENISA's technical implementation guidance elaborates these expectations measure by measure.

Is Your Current Backup Setup Already Compliant?

Probably not fully — three gaps recur in almost every assessment. First, mutability: backups an administrator (or an attacker with admin credentials) can delete or alter fail the integrity expectation; write-once (WORM) storage closes this. Second, evidence: backups that have never been test-restored, with no logs or measured recovery times, provide nothing an auditor can accept — the control exists only as an assertion. Third, jurisdiction: copies held by non-EU providers raise data sovereignty questions under GDPR and complicate the NIS2 supply-chain security assessment, particularly where the US CLOUD Act reaches the provider.

None of these gaps is exotic; all three are architectural. Which is why "we'll document what we have" rarely works — what most organizations have was designed for hardware failure, not for adversaries, auditors, and cross-border law.

What Non-Compliance Costs

The penalty framework has teeth: essential entities face administrative fines up to €10 million or 2% of global annual turnover (whichever is higher), important entities up to €7 million or 1.4%. Management bodies must approve and oversee the risk-management measures and can be held personally liable for serious neglect — a provision that has done more to fund backup projects than any technical argument.

The indirect costs bite sooner. Cyber insurers have converged on the same evidence set as NIS2 auditors — immutable copies, tested restores — and price or decline accordingly. And the incident itself remains the largest line: according to IBM's Cost of a Data Breach Report, the global average breach cost stood at USD 4.88 million in 2024, with recovery speed among the strongest cost differentiators. NIS2 compliance and incident economics point at the same architecture.

Building NIS2-Aligned Backup: A Five-Step Plan

1

Run a gap assessment against Article 21. Compare current backup scope, integrity protection, testing practice, and documentation against the requirements — and put the findings in writing; the assessment itself is audit evidence.

2

Write the policy and set justified targets. Define RTO/RPO per critical system based on business impact, and document why those targets are proportionate — NIS2's standard is risk-based, not one-size-fits-all.

3

Close the integrity gap with immutability. Move critical backups to storage-enforced WORM copies, isolated from production credentials, via a managed backup-as-a-service with EU-only data centers to settle the jurisdiction question simultaneously.

4

Institute tested recovery. Schedule quarterly restore tests and at least annual disaster recovery exercises; record durations, outcomes, and remediations. This file is what the auditor reads first.

5

Wire backups into incident response. Ensure crisis procedures reference recovery steps, and that a ransomware scenario — including ransomware-specific protection with clean-restore-point verification — is rehearsed, not just written down.

The Evidence Auditors Ask For

Requirement Weak answer Audit-ready answer
Backup management policy"IT handles backups"Written, board-approved policy with scope & retention
Recovery capability"We could restore"Quarterly test reports with measured RTO/RPO
Integrity protectionPassword-protected repositoryStorage-enforced immutability, isolated credentials
Supply chainUnknown sub-processorsEU-jurisdiction provider, documented in vendor register
GovernanceNo management involvementManagement sign-off, annual review cycle
audit-ready answer
The gap between a weak answer and an audit-ready one, requirement by requirement.

Reading the table bottom-up is instructive: every audit-ready answer is also simply better engineering. NIS2 did not invent new backup science — it made the difference between claimed and proven resilience legally visible.

Conclusion

NIS2 changed the question from "do you have backups?" to "can you govern, protect, test, and prove them?" — and attached fines and personal management liability to the answer. The compliant architecture is fortunately the same one that survives ransomware: policy-governed, immutable, EU-hosted copies with restore tests that produce evidence on a schedule. Organizations that build it get audit readiness, insurability, and actual resilience from one investment. If you'd like a structured gap assessment of your current backup setup against Article 21, we're glad to run one with you.

Frequently Asked Questions

What are the NIS2 requirements for backups?

NIS2 Article 21(2)(c) requires essential and important entities to implement business continuity measures, explicitly naming backup management and disaster recovery. In practice this means a written backup policy, defined and justified RTO/RPO targets, protection of backup integrity against tampering, regular documented restore testing, and integration with incident response procedures. Supervisors assess evidence, not intentions — test logs and immutability documentation are what demonstrate compliance.

Who falls under NIS2?

NIS2 covers essential and important entities across sectors including energy, transport, banking, health, drinking water, digital infrastructure, public administration, manufacturing of critical products, postal services, and food — generally organizations with 50+ employees or €10M+ turnover in those sectors, with some size-independent inclusions. Each EU member state transposes the directive into national law, so exact scope and enforcement details vary by country.

What fines can be imposed under NIS2?

Essential entities face administrative fines of up to €10 million or 2% of worldwide annual turnover, whichever is higher; for important entities the maximum is €7 million or 1.4%. Beyond fines, supervisory authorities can issue binding instructions and, for essential entities, temporarily suspend management from duties. NIS2 also establishes personal accountability of management bodies for approving and overseeing cybersecurity risk-management measures, including backup and recovery.

Recommended Content

  • All
  • Compliance
  • Cyber Security
  • Data Resilience
  • Managed IT Services
Scroll to Top