NIS2 and Ransomware in 2026: What Georgian Companies Should Prepare
The EU’s 2026 cybersecurity package targets NIS2 changes and ransomware reporting. Why Georgian companies should prepare an incident plan, data-protection procedure and supplier security controls.
A ransomware attack is no longer only an IT issue. On 20 January 2026 the European Commission presented a cybersecurity package including targeted NIS2 changes and stronger ransomware reporting. A Georgian company serving EU clients, participating in a critical supply chain or processing personal data may face contractual, data-protection and cybersecurity duties at the same time.
Why NIS2 matters to Georgian business
NIS2 is an EU Directive, and not every Georgian company automatically becomes an in-scope entity. An EU customer may nevertheless require incident reporting, risk management, multi-factor authentication, business continuity and subprocessor controls. The legal pressure often arrives through the contract before a direct regulatory duty.
The Commission’s 2026 package shows the direction of travel: hiding a cyber incident becomes more expensive, and supply-chain security is a separate control problem. Partners should know in advance who reports, to whom, when and with what evidence.
A 24-hour response plan
- Contain the spread without destroying evidence; do not rush into a factory reset.
- Appoint an incident lead, technical team, management contact and legal/data-protection lead.
- Assess whether personal data, trade secrets, customer accounts or a third-party system were affected.
- Preserve logs, backups, emails, ransom notes and the incident timeline.
- Notify customers and authorities under the deadlines and process required by the applicable regime.
If the incident occurs in Georgia
The Georgian Law on Personal Data Protection may apply if ransomware affects the confidentiality, integrity or availability of personal data. The company should assess the incident, document the decision, follow the relevant notification and data-subject information duties, and not delay merely because the investigation is incomplete.
Unauthorised access, alteration, destruction or extortion may also trigger cybercrime provisions of the Criminal Code of Georgia. Contracts will separately govern customer notice, damages and service-restoration duties.
What the contract should contain
- an incident definition and 24/7 contact channel;
- initial and updated notification windows;
- forensic access, log retention and evidence preservation;
- backup, business-continuity and recovery-time objectives;
- subcontractor responsibility and cross-border data-transfer rules;
- liability, indemnity and regulator-cooperation terms.
Frequently asked questions
- Does NIS2 directly apply to a Georgian company? Not always; assess the sector, EU connection and the relevant national implementation.
- Can a company pay ransom? Only after a combined review of legal, sanctions, insurance and investigative risk.
- When should a lawyer be involved? From the first hours, because containment, data protection, contractual notice and possible investigation interact.
Primary sources: European Commission, 2026 cybersecurity package — https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_105/IP_26_105_EN.pdf ; NIS2 Directive — https://eur-lex.europa.eu/eli/dir/2022/2555/oj ; Georgian Law on Personal Data Protection — https://www.matsne.gov.ge/en/document/view/5827307 ; Criminal Code of Georgia — https://www.matsne.gov.ge/en/document/view/16426
NoticeThis publication is for general information and is not individual legal advice.