What is NIS2 Directive?
The EU’s updated cybersecurity directive, (EU) 2022/2555, which sets risk management and incident reporting obligations for essential and important entities across 18 sectors.
How it works
NIS2 replaced the original NIS Directive. EU member states had to transpose it into national law by 17 October 2024, though several were late. It covers sectors such as energy, transport, banking, health, digital infrastructure and manufacturing.
In-scope entities must manage cybersecurity risk, secure their supply chain and report significant incidents: an early warning within 24 hours, a notification within 72 hours and a final report within one month. Management bodies can be held personally accountable.
Key points
- Applies to essential and important entities in the EU
- 24-hour, 72-hour and one-month reporting stages
- Covers supply chain security
- Fines up to €10M or 2% of global turnover for essential entities
Common questions
Does NIS2 apply outside the EU?
It can apply to non-EU organisations that provide in-scope services in the EU.
Does ISO 27001 cover NIS2?
It covers much of it, but NIS2 adds specific requirements such as incident reporting timelines and management accountability.
Talk to someone who does this every day
Questions about NIS2? Our team will give you a straight answer.