Auditen
Home / Frameworks / NIS2 / What changed from NIS1 to NIS2

What changed from NIS1 to NIS2

NIS2 expands the scope of regulated sectors and introduces a harmonized, more stringent set of cybersecurity risk-management requirements compared to NIS1. It shifts from a flexible framework to mandatory obligations with strict enforcement mechanisms, including higher fines and personal liability for senior management.

What it means

The transition represents a shift toward systemic resilience across the EU. While NIS1 allowed significant variation in how member states implemented security requirements, NIS2 mandates specific areas of focus—such as supply chain security and incident handling—across all regulated entities to ensure a baseline level of protection regardless of geography.

Scope has broadened significantly. The distinction between "Operators of Essential Services" (OES) and "Digital Service Providers" (DSPs) is replaced by "Essential Entities" (EE) and "Important Entities" (IE). This brings in sectors previously excluded, such as waste management, food production, and postal services, based on their criticality to the economy and society.

Crucially, NIS2 elevates cybersecurity from a technical concern to a governance requirement. Senior management is now legally responsible for ensuring risk-management measures are implemented; failure to do so can lead to personal liability and professional sanctions.

How to meet it

Evidence an auditor asks for

  • A documented risk assessment that explicitly identifies vulnerabilities within the supply chain and third-party dependencies.
  • Timestamps and copies of incident notifications sent to the national competent authority or CSIRT.
  • Training logs and completion certificates proving senior management has undergone cybersecurity governance training.
  • Records of business continuity exercises, including "after-action reports" showing how plans were tested and improved.
  • Signed security addendums or Service Level Agreements (SLAs) with critical vendors that mandate specific security controls.

Common pitfalls

  • Assuming a certification like ISO 27001 provides automatic compliance without mapping the specific gaps in NIS2, particularly regarding reporting timelines and supply chain mandates.
  • Treating implementation as an IT-led project rather than a corporate governance initiative, resulting in a lack of documented management oversight.
  • Overlooking "Important Entity" status under the assumption that only large or highly critical organizations are subject to supervision and enforcement.