Definition

NIS2 is an EU directive that sets binding requirements for risk management, reporting and management accountability at entities in critical and important sectors. It widens the circle of affected organisations considerably compared with its predecessor.

At a glance

NIS2 covers considerably more organisations than the old NIS directive.

Management is accountable – cybersecurity is no longer an IT-only task.

Reporting deadlines are short: a first report within 24 hours.

NIS2 moves cybersecurity from a technical question to a duty of the management body.

What the directive requires

It requires documented risk management, measures to secure the supply chain, defined reporting paths with short deadlines, and trained management bodies. National transposition determines the detail.

Real-world examples

  • A supplier in scope must demonstrate the security of its own suppliers.
  • A reportable incident requires an initial report within 24 hours and a full report within a month.

Common misconception

Myth “NIS2 only affects operators of critical infrastructure.”

Reality The scope also covers many mid-sized companies in important sectors – and through the supply chain it reaches further still.

Frequently asked questions

When does NIS2 apply?

The directive had to be transposed into national law; the applicable national act governs. The text is on EUR-Lex.

How does it differ from ISO 27001?

ISO 27001 is a voluntary standard for a management system; NIS2 is a legal obligation. An existing ISO 27001 system makes compliance easier but does not replace it.