NIS2 Directive (EU) 2022/2555
The NIS2 Directive is a European Union legislative framework designed to increase the collective cybersecurity resilience of Member States. It mandates that organizations in critical sectors implement specific risk management measures and adhere to strict incident reporting requirements to protect essential services from cyber threats.
Who it applies to
- Essential Entities (EE) operating in high-criticality sectors such as energy, transport, banking, health, and drinking water.
- Important Entities (IE) in sectors such as postal services, waste management, chemicals, food production, and manufacturing.
- Digital providers including cloud computing services, data center services, and online marketplaces.
- Public administration entities at central and regional levels.
How it works
NIS2 is a Directive rather than a Regulation, meaning the EU sets the overarching requirements but individual Member States transpose these into their own national laws. Consequently, an organization's specific legal obligations are determined by the legislation of the country where they operate.
The framework focuses on "all-hazards" risk management. Organizations must implement technical, operational, and organizational measures to manage security risks, covering areas such as supply chain security, vulnerability handling, and cryptography. Management bodies are also held personally accountable for ensuring these measures are implemented.
Compliance is not achieved through a single EU-wide certification. Instead, national supervisory authorities conduct audits or ex-post checks to verify that an entity has the required controls in place. Failure to comply can result in significant administrative fines and management liability.
Getting started
- Determine if your organization is classified as an "Essential" or "Important" entity based on national law and sector definitions.
- Conduct a gap analysis against the NIS2 risk management requirements to identify deficiencies in current security controls.
- Create a comprehensive inventory of critical assets, including hardware, software, and third-party service dependencies.
- Establish an incident reporting workflow capable of meeting strict timelines, such as the 24-hour early warning notification.
- Implement mandatory cybersecurity training for all employees and specialized training for senior management.
Controls & requirements
- Art. 2 & Annexes Who is in scope: essential and important entities
- Art. 20 Governance and management accountability
- Art. 21 The minimum cybersecurity risk-management measures
- Art. 21(2)(d) Supply chain security
- Art. 21(2)(c) Business continuity and crisis management
- Art. 21(2) Cryptography, encryption and multi-factor authentication
- Art. 21(2)(g) Cyber hygiene and security training
- Art. 23 Incident reporting: the 24-hour, 72-hour and final reports
- Arts. 31–36 Supervision, enforcement and fines
- What changed from NIS1 to NIS2
Common misconceptions
- That it only applies to companies headquartered in the EU; it also applies to non-EU entities providing essential or important services within the Union.
- That achieving ISO 27001 certification equals NIS2 compliance, whereas NIS2 includes specific governance and reporting mandates not covered by that standard.