NIS2 and Moroccan companies: why an EU directive is landing in your contracts
The NIS2 directive does not apply in Morocco, yet it makes your European clients accountable for your security posture. A look at the real scope, how it interacts with Morocco’s law 09-08, and which work to start first.
7 min readThe Corevia team
The same scene has been repeating itself at Moroccan service providers for two years: a European client sends a security questionnaire, imposes an incident notification clause measured in hours, and asks for evidence of a risk assessment. The reflex answer comes in one sentence: “NIS2 is an EU directive, we are in Morocco, it is not enforceable against us.” It is legally almost correct and practically irrelevant. The directive is not addressed to you; it is addressed to your client, and it makes that client accountable for your security.
What the directive requires, and of whom
NIS2 is the common name of Directive (EU) 2022/2555, which entered into force on 16 January 2023 and had to be transposed by Member States by 17 October 2024 at the latest. It replaces Directive 2016/1148, whose scope was too narrow and whose application too uneven. First thing to remember: the text is a directive. Unlike the GDPR it is therefore not directly applicable; it lives in twenty-seven national laws that diverge on very concrete points (entity identification, thresholds, reporting arrangements, penalty scales). When a client invokes “NIS2”, what is actually being invoked is French, Belgian or German law.
Scope combines two sector annexes with a size criterion. Annex I covers sectors of high criticality (energy, transport, banking, health, water, digital infrastructure, ICT service management between businesses, public administration), while Annex II covers other critical sectors, from postal services to food. The general threshold captures medium-sized enterprises and above, with exceptions that apply regardless of size. Entities are then classified as “essential” or “important”. That classification governs the supervisory regime, ex ante or ex post, as well as the ceiling on fines: at least ten million euros or 2 % of worldwide annual turnover for the former, seven million or 1.4 % for the latter.
Three routes into scope
Your clients’ supply chain
This is the most common route, and the one that leaves no room for negotiation. Article 21 requires in-scope entities to adopt risk-management measures based on an “all-hazards” approach, and its minimum list explicitly includes supply chain security, covering relationships with direct suppliers and service providers. The following paragraph adds that the entity must take into account the vulnerabilities specific to each direct supplier and the overall quality of its cybersecurity practices. A German hospital is therefore no longer answerable only for its own security: it must demonstrate that it assesses and governs the security of its providers. And to do that it has only one instrument: the contract.
Digital services offered within the Union
This route is more direct and far less well known. Article 26 sets territorial jurisdiction. An entity normally falls under the Member State in which it is established; for certain categories, however, jurisdiction follows the main establishment in the Union: DNS services, domain name registries, cloud computing, data centres, managed service providers and managed security service providers, online marketplaces, search engines. And where an entity in those categories is not established there yet offers services within the Union, it must designate a representative in the Union and falls under the jurisdiction of the Member State where that representative is established. A Moroccan managed services firm, hosting provider or MSSP selling to European clients fits that description precisely. Implementing Regulation (EU) 2024/2690 also sets out the technical requirements expected of those same categories: it is the most precise guide available today.
A subsidiary established in the Union
If the group has a legal entity in Europe, that entity may itself be in scope once it meets the size threshold in a listed sector. The common mistake is to look at local headcount and conclude too quickly: thresholds are assessed under Recommendation 2003/361/EC, which aggregates linked enterprises. A ten-person subsidiary owned by a group of eight hundred employees is not automatically a small enterprise.
What your contracts will require
Policies on risk analysis and information system security: written, dated, approved.
Business continuity: backup management, disaster recovery, crisis management.
Supply chain security, including your own subcontractors, since the clause cascades downwards.
Security in acquisition, development and maintenance, including vulnerability handling.
Procedures to assess the effectiveness of the measures: tests and audits, not merely procedures.
Basic cyber hygiene practices and cybersecurity training.
Policies on the use of cryptography and, where appropriate, encryption.
Human resources security, access control and asset management.
Multi-factor or continuous authentication and secured communications, including for emergencies.
That minimum list holds no surprises for anyone familiar with ISO/IEC 27001. Article 20, by contrast, adds a requirement that changes the nature of the conversation: the management body approves the measures, oversees their implementation, can be held liable for breaches, and its members must undergo training. Your counterpart is therefore no longer only the IT department. A provider able to produce a dated risk assessment, an incident procedure and a restore test report on request saves considerable time in a tender.
Law 09-08 and the CNDP: what Moroccan law already covers
Law 09-08 on the processing of personal data, enacted by the dahir of 18 February 2009, gives the CNDP oversight of processing activities: prior formalities, data subject rights, controls on transfers outside Morocco. Its purpose differs from that of NIS2, since it protects individuals rather than the resilience of services, but the two texts intersect on operational points: log retention, outsourcing monitoring to a SOC, clauses imposed on sub-processors. Morocco is not on the European Commission’s list of countries recognised as adequate, so transfers from the Union rely on the GDPR’s appropriate safeguards. Conversely, a company already subject to the national framework established by law 05-20 and overseen by the DGSSI has built part of the expected baseline; its remaining gap concerns mainly deadlines and evidence.
Where to start
1Establish your position first: supplier to an in-scope entity, digital service provider offering services within the Union, or group with a European subsidiary. The three situations do not carry the same obligations.
2Map your European clients and their sectors against Annexes I and II: the three or four accounts that weigh most will set the level of requirement you need to meet.
3Re-read existing contracts as closely as new ones: security annex, audit rights, notification deadlines, onward subcontracting conditions. A six-hour deadline signed without on-call capability is a dormant breach.
4Build the notification capability before the documentation: a permanently reachable contact, a qualification procedure, a reporting template, a timestamped decision log.
5Align your baseline with the ten points of Article 21. There is no formal equivalence with ISO/IEC 27001, but a certified management system covers most of it and produces the evidence expected.
6If Article 26 applies to you, treat the appointment of a representative as a management decision: it determines which authority may supervise you.
7Run the NIS2 and 09-08 work together: the processing register, retention policy and subcontracting clauses serve both, and running them separately means paying twice for the same work.