NIS2
NIS2 (Network and Information Security Directive 2) is an EU directive establishing cybersecurity requirements for essential and important entities with personal management liability and mandatory incident reporting.
What is NIS2?
NIS2 Definition
NIS2 (Network and Information Security Directive 2) is a European Union directive adopted in January 2023 that modernizes the EU cybersecurity legal framework. NIS2 replaced the original NIS Directive from 2016, significantly expanding the scope of entities covered and introducing stricter requirements.
Who does NIS2 apply to?
Essential entities:
- Energy (electricity, oil, gas)
- Transport (air, rail, water, road)
- Banking and financial infrastructure
- Healthcare
- Water supply
- Digital infrastructure (DNS, IXP, TLD)
- Public administration
Important entities:
- Postal and courier services
- Waste management
- Chemical production
- Food industry
- Manufacturing (medical devices, electronics)
- Digital services (marketplaces, search engines)
Key NIS2 requirements
Risk management:
- Risk analysis and security policy
- Incident management
- Business continuity
- Supply chain security
- Cryptography and encryption
Incident reporting:
- Early warning within 24 hours
- Full notification within 72 hours
- Final report within 1 month
Management liability:
- Personal liability of managers
- Mandatory security training
- Compliance oversight obligation
NIS2 penalties
- Essential entities: Up to €10M or 2% of global turnover
- Important entities: Up to €7M or 1.4% of turnover
- Management can be banned from performing functions
NIS2 implementation timeline
- January 2023: Directive entry into force
- October 2024: Deadline for national implementation
- 2025: Full application
NIS2 vs NIS1
| Aspect | NIS1 | NIS2 |
|---|---|---|
| Scope | OES and DSP | Essential and important entities |
| Sectors | 7 sectors | 18 sectors |
| Penalties | Undefined | Up to €10M |
| Management liability | None | Personal liability |
| Supply chain | No requirements | Mandatory |
Related Terms
- DORA - regulation for financial sector
- GDPR - personal data protection
- ISO 27001 - information security management standard
- SOC - Security Operations Center
Explore Our Services
Need NIS2 compliance support? Check out:
- NIS2 Compliance - comprehensive implementation support
- SOC 24/7 - monitoring required by NIS2
- Security Audits - NIS2 gap analysis
NIS2 is a fundamental regulation for cybersecurity in the EU, affecting thousands of organizations across various sectors.
Frequently asked questions
+ What is NIS2 in simple terms?
NIS2 (Network and Information Security Directive 2, EU 2022/2555) is the EU's updated cybersecurity directive that introduces mandatory cybersecurity obligations for 18 sectors of the economy — including energy, transport, finance, healthcare, digital services, public administration, water, food, and manufacturing. It replaced the original NIS Directive from 2016 and dramatically expanded the scope: from approximately 15,000 entities EU-wide to roughly 160,000. Member states had until 17 October 2024 to transpose NIS2 into national law, though many (including Poland) finalised their national implementation in 2024-2025.
+ Who is affected by NIS2 — essential vs important entities?
NIS2 splits regulated entities into two tiers: (1) **Essential entities** — operators in 11 high-criticality sectors (energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, B2B ICT, public administration, space) above the size threshold (>250 employees OR >€50M turnover), (2) **Important entities** — remaining sectors (postal, waste management, chemical production, food, medical devices, electronics, automotive, digital providers — marketplaces, search engines, social) at medium-enterprise threshold (>50 employees OR >€10M). Micro and small enterprises are excluded by default, but member states can include them based on criticality.
+ What does NIS2 require?
Ten risk management measures (Article 21 NIS2): (1) policy on risk analysis and information system security, (2) incident handling, (3) business continuity (BCP/DRP, backups, crisis management), (4) supply chain security — including ICT vendors, (5) security in the acquisition, development and maintenance of network and information systems, (6) policies and procedures to assess effectiveness of measures, (7) basic cyber hygiene practices and training, (8) cryptography and encryption, (9) human resources security (vetting, access control, asset policy), (10) MFA, continuous authentication, encrypted voice/video/text, secure emergency communications. Plus mandatory incident reporting (24h/72h/1 month) to the relevant national CSIRT.
+ What are the penalties under NIS2?
Two penalty tiers (Article 34): (1) **Essential entities** — fines up to **€10 million or 2% of worldwide turnover** (whichever is higher), (2) **Important entities** — fines up to **€7 million or 1.4% of turnover**. Additional measures: periodic penalty payments per day, immediate corrective orders, public communication of the violation, temporary suspension of certifications, and temporary bans on management positions for those responsible. **Personal management liability** (Article 20) — board members must approve risk management measures and can face personal sanctions including a temporary ban from holding executive positions. This is the biggest change from NIS1.
+ What are the NIS2 incident reporting deadlines?
A three-stage model (Article 23): (1) **Early warning** — within **24 hours** of becoming aware of a significant incident (with an indication of potential cross-border or malicious nature), (2) **Incident notification** — within **72 hours** of awareness (updated information, severity assessment, mitigation measures applied), (3) **Final report** — within **one month** of the initial notification (or after handling closure). Reports go to the relevant national CSIRT — for Polish entities: CSIRT NASK (private sector), CSIRT GOV (public administration), CSIRT MON (defence). 'Significant incident' = substantial loss of availability, integrity or confidentiality + service disruption + financial impact + harm to individuals.
+ How do you prepare for NIS2 compliance?
Six-phase roadmap (typically 9-15 months): (1) Scope analysis — does the entity fall under NIS2 (essential/important)? Which sectors? (2) Compliance audit — gap analysis against the 10 risk management measures (4-8 weeks), (3) Remediation roadmap with priorities and budget, (4) Implementation — most common gaps: MFA on every account, network segmentation, 24/7 monitoring (SOC), ransomware-resistant backups, IR plan with tabletop exercises, (5) Process — incident register, supply chain security policy, regular training, board approvals, (6) Testing — penetration testing, IR drills, mock CSIRT reporting. Additionally required: written board approval (Article 20).
+ NIS2 vs DORA — what's the difference?
Both regulations address EU cybersecurity but differ in scope and depth: **NIS2** — horizontal, applies to 18 sectors with general cybersecurity requirements, applicable from 17 Oct 2024; **DORA** (Digital Operational Resilience Act) — vertical, financial sector only (banks, insurers, fintech, asset managers, crypto), with very detailed ICT requirements (TLPT, vendor register, direct CTPP supervision), applicable from 17 Jan 2025. For financial entities: **DORA takes precedence** as lex specialis. A bank classified as essential under NIS2 follows DORA for its ICT requirements. Multinational financial groups must map both regimes plus equivalents in non-EU jurisdictions (UK PRA, Swiss FINMA, US OCC).