What is NIS2

NIS2 is the EU cybersecurity directive that introduces mandatory risk management, incident reporting, and governance requirements for critical sectors.

What is NIS2

Table of content

What is NIS2? NIS2 is the European directive that sets mandatory cybersecurity requirements for organizations operating in critical sectors across the European Union. Directive (EU) 2022/2555 introduces risk management measures, incident reporting obligations, and responsibilities for organizational management.

NIS2 significantly expands the scope of the previous directive, introduces clearer requirements and mandatory cybersecurity risk management measures, as well as stricter reporting obligations.

Why Was the NIS2 Directive Introduced?

To better understand the directive, it is important to consider the context of increasing cyber threats across Europe.

NIS2 was adopted in response to the significant increase in cybersecurity threats and the need to create a common level of resilience across the EU. Compared with NIS1, the new directive:

  • expands the number of critical sectors covered;
  • introduces stricter responsibilities for essential and important entities;
  • strengthens cooperation between Member States;
  • sets clearer requirements for risk management and incident reporting.

The directive requires Member States to adopt coherent national cybersecurity strategies and develop stronger crisis response capabilities.

Who Falls Under NIS2?

A clear understanding of what NIS2 is helps organizations determine whether they fall within the scope of the new European directive.

NIS2 covers significantly more sectors than the previous directive, including both essential entities and important entities. In total, the directive applies across 18 sectors, including:

High-Criticality Sectors

  • energy;
  • transport;
  • healthcare;
  • public administration;
  • digital infrastructure;
  • banking and financial services;
  • water and wastewater management.

Other Critical Sectors

  • digital services, such as online marketplaces, cloud services, and search engines;
  • postal and courier services;
  • waste management;
  • manufacturing of critical equipment;
  • food industry;
  • space;
  • chemicals.

The entities concerned are generally medium-sized and large enterprises. However, NIS2 also provides exceptions under which certain organizations fall within scope regardless of their size, especially those operating in digital infrastructure or providing trust services.

When Does NIS2 Enter Into Force?

The NIS2 Directive had to be transposed into national law by EU Member States by 17 October 2024. After this date, covered organizations must comply with the new requirements on risk management and cybersecurity incident reporting.

What Obligations Does NIS2 Introduce?

Understanding what NIS2 is helps organizations identify the cybersecurity obligations imposed by European legislation.

The directive introduces a broad set of mandatory requirements for covered entities, including:

1. Risk Management Measures

Organizations must implement risk assessment and risk management processes through policies covering:

  • supply chain security;
  • vulnerability analysis;
  • access control;
  • operational security;
  • encryption and communication protection.

2. Incident Reporting

Significant cybersecurity incidents must be reported within strict deadlines to the competent national authorities.

3. Supervision and Controls

Entities may be subject to audits, inspections, and mandatory investigations in order to demonstrate compliance.

4. Management Responsibility

Management bodies may be held directly responsible for non-compliance. Sanctions may include financial penalties and temporary bans from exercising management functions.

What Sanctions Does NIS2 Provide?

The directive introduces a strict sanctions regime, similar to the one provided under GDPR. Penalties may reach up to:

  • EUR 10 million; or
  • 2% of the organization’s global annual turnover,
    whichever is higher.

In addition, for essential entities, authorities may impose immediate corrective measures, suspensions, or other mandatory actions.

Which Companies Must Comply with NIS2?

The NIS2 Directive mainly applies to organizations operating in critical sectors such as energy, transport, healthcare, digital infrastructure, and financial services. In general, medium-sized and large enterprises are targeted, although certain organizations may fall within scope regardless of size if they provide essential services.

Benefits of Implementing NIS2

For many organizations trying to understand what NIS2 is, compliance also represents an opportunity to strengthen cybersecurity.

Although the directive imposes rigorous requirements, compliance brings important benefits for organizations:

  • reduced operational risks;
  • increased resilience against cyberattacks;
  • higher trust from partners and clients;
  • improved business continuity;
  • alignment with international standards.

NIS2 contributes to the creation of a safer digital ecosystem, where incidents are handled consistently and effectively across the European Union.

NIS2 represents a major change in the EU cybersecurity landscape, setting common and strict standards for protecting information systems in critical sectors. Its expanded scope, management accountability, and severe sanctions highlight the importance of adopting a strong security culture.

Covered organizations must adapt their processes, invest in preventive measures, and strengthen their response capabilities in order to ensure compliance and reduce the risks generated by increasingly complex cyber threats.

If your organization wants to assess its cybersecurity level and strengthen digital resilience, the LEXA team provides cybersecurity audits and risk assessments for companies.

In conclusion, for organizations asking what NIS2 is and how it affects their activity, the directive introduces clear requirements on risk management and incident reporting.

Related posts

  • NIS2 vs Cyber Resilience Act

    NIS2 vs Cyber Resilience Act explains the key differences between EU cybersecurity rules for organizations…

    View post
    nis2 vs cyber resilience act diferențe NIS2 vs Cyber Resilience Act
  • What is Data Act

    The Data Act sets EU rules for access, sharing, and use of data generated by…

    View post
    Ce este Data Act regulament UE acces date conformitate ai act
  • What is AI Act?

    The AI Act is the EU regulation that sets rules for the responsible development, deployment,…

    View post
    Ce este AI Act regulament UE inteligență artificială