The EU's cybersecurity directive turns backup management into a legal duty, and the enforcement phase has started.
For years, backing up business data was a best practice you could defer. NIS2 changes the category. For organisations in scope, backup management is now a legal obligation, with fines and personal liability for management attached to getting it wrong.
The transposition deadline passed in October 2024, and as of September 2026 the map has largely filled in. Most member states have national NIS2 laws in force. Germany's implementation took effect on 6 December 2025 with no transition period, and in July 2026 the European Commission referred the remaining laggards, including Ireland, Spain, France and the Netherlands, to the Court of Justice. The first national fines have already been issued.
Yet many operations and IT leads at mid-sized companies still treat NIS2 as an enterprise problem. The size thresholds say otherwise. This post covers who is in scope, where backups sit in the directive, and what a defensible backup posture looks like for the data your teams keep in SaaS platforms.
What is NIS2 and who is in scope?
NIS2 is Directive (EU) 2022/2555, the EU's network and information security directive. It entered into force in January 2023, replaced the original NIS Directive, and required member states to transpose it into national law by 17 October 2024. It sets minimum cybersecurity risk-management measures and incident-reporting duties for "essential" and "important" entities across sectors such as energy, transport, banking, healthcare, water, digital infrastructure, waste management, chemicals, food production, and manufacturing of machinery, vehicles, medical devices and electrical equipment.
The scope test is the part mid-sized companies underestimate. Under most national implementations, an entity in a covered sector is in scope if it has 50 or more employees or annual turnover above EUR 10 million. Reed Smith's January 2026 client alert on the German implementation notes that many organisations never previously regulated under EU or German IT security law are now captured, including medium-sized enterprises in key value chains.
Germany is a useful anchor for how national enforcement now works. Its NIS2 law applied immediately from 6 December 2025, without a grace period, and in-scope entities had to register with the BSI, the federal cybersecurity office, by 6 March 2026. Fines can reach EUR 10 million or 2% of annual turnover for large "very important" entities, and management bodies carry personal liability for culpable failures (Reed Smith, January 2026). Other member states differ in detail, so check the transposing act in each country where you operate.
Key takeaway: if your organisation operates in a covered sector anywhere in the EU and has 50 or more employees or more than EUR 10 million in turnover, assume you are in scope until a proper assessment says otherwise.
Where backups sit in the directive
Article 21(2) of NIS2 lists the minimum risk-management measures every in-scope entity must implement. Point (c) requires "business continuity, such as backup management and disaster recovery, and crisis management." Backup management is named in the directive's text, not inferred from it. An auditor or supervisory authority reviewing your Article 21 measures will expect to see a backup programme as a distinct, evidenced control.
Two neighbouring provisions widen the blast radius. Article 21(2)(d) requires supply chain security, which means in-scope customers must assess the security of their suppliers and service providers. Even if your company sits below the thresholds, expect NIS2-style backup and continuity questions to arrive through customer security reviews and contracts. And the management accountability rules mean continuity failures are no longer an IT problem alone: in Germany, management members must undergo regular cybersecurity training and can be held personally liable.
Incident reporting adds urgency. Under Germany's implementation, a significant incident triggers an initial notification within 24 hours, a detailed report within 72 hours, and a final report within a month (Reed Smith, January 2026). Meeting a 24-hour clock while also recovering operations is only realistic if restore procedures already exist and have been tested.
Important context: NIS2 does not prescribe a backup technology, frequency or vendor. It requires measures that are appropriate and proportionate to the risk. In practice that is a governance test: can you show what you back up, how often, where the copies live, and that restoring from them actually works?
Why SaaS data is the gap in most NIS2 backup programmes
Most NIS2 remediation work centres on infrastructure: servers, endpoints, databases, network equipment. The operational data your teams keep in cloud apps such as Asana, ClickUp, monday.com, HubSpot, Jira or Notion often never makes it into the backup inventory, because everyone assumes the vendor handles it.
The vendor does back up data, but for its own disaster recovery. If a team member deletes a project, an import overwrites the wrong field, or a third-party integration corrupts records, the vendor's infrastructure backup will not roll your account back. Under the shared responsibility model that governs SaaS, data inside your account is yours to protect, and if the business depends on that data, it belongs inside your Article 21 continuity measures.
Agentic AI sharpens the point. AI agents now create, edit and bulk-delete records inside these platforms autonomously. A misfired agent or a badly scoped instruction can corrupt thousands of records at machine speed, before anyone notices. A continuity programme written in 2023 that never contemplated this failure mode is due an update.
Five backup gaps that surface in NIS2 assessments
- SaaS platforms missing from the backup inventory. The gap assessment maps servers and databases but skips the work management and CRM tools that actually run daily operations.
- No restore testing. Backups exist, but nobody has restored a record, a project or a whole workspace from them. An untested backup is an assumption, and assumptions do not satisfy auditors.
- Retention too short for slow-burn incidents. Data corruption is often noticed weeks or months later. If your version history only reaches back days, the clean copy is already gone.
- Copies stored inside the system they protect. Periodic exports saved into the same workspace, or backups reachable with the same credentials, fail together with the source.
- No evidence trail. Backups run, but there are no logs, status reports or documented procedures to show a supervisory authority or a customer's security review.
What good looks like
- Inventory every system the business depends on, cloud apps included, and record which ones hold data you could not afford to lose.
- Keep an independent copy outside the source platform, under separate credentials, encrypted at rest and in transit.
- Back up daily and keep version history long enough to survive incidents discovered late.
- Document a restore procedure that covers both granular recovery (one record, one file) and bulk recovery (a whole project or board), and test it on a schedule.
- Write the facts down: what is covered, what the platform API cannot expose, where copies are stored, and who owns the process. This documentation doubles as audit evidence.
- Ask your own critical vendors the same questions your in-scope customers will ask you.
Where a SaaS backup service fits
ProBackup is a SaaS backup service that takes automated daily snapshots of your cloud app data and lets you restore individual records, files or whole projects back to the original account.
For the SaaS slice of an Article 21 continuity programme, the relevant facts are these: daily automated snapshots with no scheduling required, two restore modes (safe duplicates or field-by-field overwrite), AES-256 encryption at rest and TLS in transit, a SOC 2 Type II report (certified May 2025), GDPR compliance, and storage in one of nine AWS regions that you select at signup, which keeps data residency under your control. Version history runs six months on Plus, two years on Pro and unlimited on Premium, which matters directly for the slow-burn incident problem above.
Good for: covering the cloud app portion of your backup inventory; demonstrating an independent, encrypted, residency-controlled copy to auditors and customer reviews; granular rollback after human or AI-agent error.
Not recommended for: your entire NIS2 programme (a SaaS backup tool says nothing about your network, endpoints or incident response); data a platform's API does not expose; a substitute for legal advice on whether and where you are in scope.
ProBackup Expert Note: a backup you have never restored from is a liability wearing the costume of a control. Restore one record and one full project each quarter, screenshot the result, and file it with your compliance evidence. It takes minutes and it is exactly the artefact an assessor asks for first.
Frequently asked questions
How does NIS2 define backup requirements?
Article 21(2)(c) requires business continuity measures, explicitly including backup management and disaster recovery. The directive does not prescribe tools or frequencies; measures must be appropriate and proportionate to the entity's risk, and demonstrable to the supervisory authority.
Why does NIS2 matter if my company is below the size thresholds?
Because of Article 21(2)(d) on supply chain security. In-scope customers must assess their suppliers' cybersecurity, so smaller vendors inherit backup and continuity expectations through security questionnaires and contract clauses even without a direct legal obligation.
Where should NIS2-relevant backups be stored?
Outside the system they protect, under separate access controls, encrypted at rest and in transit. If data residency matters to your obligations, choose a provider that lets you pick the storage region. ProBackup stores snapshots in the AWS region you select from nine options at signup.
How fast must incidents be reported under NIS2?
The directive sets a layered scheme that national laws implement: an early warning within 24 hours of becoming aware of a significant incident, a detailed notification within 72 hours, and a final report within a month. Germany's implementation follows this pattern (Reed Smith, January 2026).
The basics, evidenced
NIS2 does not ask for heroics. It asks organisations to prove that the basics work: know what you depend on, keep independent copies, restore on demand, and show the paperwork. The companies that struggle with enforcement will not be the ones missing exotic tooling. They will be the ones that cannot produce a tested restore when a regulator, an auditor or a customer asks.
If your gap assessment has not yet reached the data in your cloud apps, that is the cheapest item on the list to fix, and after the first incident it is the one you will be gladdest you did.
This article is written for IT managers and operations leads at organisations in or near NIS2 scope who are responsible for business data held in SaaS platforms. It is general information, not legal advice; scoping decisions belong with your counsel.






