The NIS2 Directive covers sectors key to the functioning of the economy and society, such as energy, transport, healthcare, public administration, digital infrastructure, and the water and food sectors. It introduces expanded requirements for cybersecurity, risk management, and incident reporting. The scope has also been extended to sectors not previously covered, such as space, medical device manufacturing, and waste management.
📚 Start here: what the NIS2 Directive is — definition, objectives and key deadlines.
What is the NIS2 Directive and What Are Its Main Objectives?
The NIS2 Directive (Network and Information Security 2) is EU legislation aimed at raising the level of cybersecurity across all member states. It constitutes an update and expansion of the original NIS Directive from 2016. The main objectives of NIS2 are to strengthen resilience against cyberattacks, improve cooperation between EU countries, and harmonize security requirements for key sectors of the economy. The directive aims to create a uniform, high standard of protection for networks and information systems throughout the Union, to ensure continuity of services essential to society and the economy.
📚 Read the complete guide: SOC: Security Operations Center - czym jest, jak działa, jak wybrać
Which Sectors Were Covered by the Original NIS Directive?
The original NIS Directive from 2016 covered two main categories of entities: operators of essential services and digital service providers. Among the sectors considered essential were: energy, transport, banking, financial market infrastructure, healthcare, drinking water supply, and digital infrastructure. Member states were required to identify specific entities operating in these sectors that had to implement appropriate security measures and report serious incidents.
Which New Sectors Have Been Added in the NIS2 Directive?
The NIS2 Directive significantly expands the scope of regulated sectors compared to the original NIS Directive. Added to the list are, among others: public administration, space, medical device manufacturing, chemical production and distribution, food production, waste management, postal and courier services, public transport, and digital service providers such as social media and cloud services. The expansion aims to eliminate gaps in the security system and provide protection for all sectors critical to the functioning of the EU economy and society.
How Does the NIS2 Directive Classify Regulated Entities?
NIS2 introduces a new division of entities covered by the directive into two categories: essential entities and important entities. This replaces the previous distinction between operators of essential services and digital service providers. Essential entities are organizations of critical importance for maintaining key social or economic functions, whose disruption would have a significant impact on public safety, public health, or economic welfare. Important entities are those that play a significant role for specific sectors or types of services but are not considered essential. This division determines the level of supervision and severity of security requirements.
Which Sectors Are Classified as Essential Entities Under NIS2?
According to Annex I of the NIS2 Directive, sectors recognized as essential entities include: energy, transport, banking, financial market infrastructure, healthcare, drinking water, wastewater, digital infrastructure, public administration, and space. Within these sectors, member states are required to identify specific entities meeting the criteria for recognition as essential, taking into account their significance for maintaining critical social or economic functions.
Which Sectors Are Recognized as Important Entities Under NIS2?
The NIS2 Directive, in Annex II, lists sectors classified as important entities. These include: postal and courier services, waste management, chemical production and distribution, food production and processing, medical device manufacturing, automotive, digital service providers (e.g., social media, cloud services), and the research sector. Entities operating in these sectors, although not considered essential, play a significant role in the functioning of the economy and society, and disruption of their activities could have a significant impact on the security and welfare of EU citizens.
Do All Companies in a Given Sector Fall Under the NIS2 Directive?
Not all companies operating in sectors covered by the NIS2 Directive automatically fall under its provisions. The directive introduces size criteria, under which it generally covers medium and large enterprises employing more than 50 people and achieving annual turnover exceeding 10 million euros. However, in some cases, even smaller entities may be recognized as essential or important if they provide services of critical importance to a given sector or region. The final identification of entities covered by NIS2 lies with member states, which may designate additional criteria or exclude some organizations from the directive’s scope.
How Does the NIS2 Directive Treat the Public Administration Sector?
NIS2 for the first time explicitly includes the public administration sector in the scope of regulation. Public bodies at central, regional, and local levels that meet the definition of an essential or important entity will need to implement security measures and report serious incidents. This is particularly important given the increasing digitization of public services and the sensitivity of processed data. However, the directive provides for certain exceptions, e.g., for parliaments or central banks. The inclusion of public administration aims to ensure a high level of cybersecurity across all key sectors, regardless of ownership characteristics.
How Does NIS2 Expand the Scope of the Digital Infrastructure Sector?
The NIS2 Directive significantly expands the scope of the digital infrastructure sector compared to the original NIS Directive. In addition to previously covered entities, such as operators of essential services (e.g., DNS service providers, top-level domain registries) or digital service providers (e.g., cloud services, internet search engines), NIS2 adds new categories. These include content delivery network (CDN) providers, domain name registries, trust service providers, autonomous system administrators, and data center service providers. The expansion aims to adapt regulations to the dynamically changing digital ecosystem and provide protection for all key infrastructure elements on which the modern economy and society depend.
Which Industrial Sectors Are Included in the NIS2 Directive?
NIS2 covers several key industrial sectors, recognizing their importance for supply chain security and continuity of EU economic operations. Among them is chemical production and distribution, covering the manufacture of basic chemicals, pesticides, fertilizers, and pharmaceuticals. Another important sector is food production, covering all stages from agriculture to processing, packaging, and distribution. NIS2 also includes medical device manufacturing, including in vitro diagnostic devices, and the manufacture of computers, electronic and optical products. Additionally, the directive addresses the automotive sector, covering the manufacture of motor vehicles, trailers and semi-trailers, and other transport equipment.
How Does the NIS2 Directive Approach the Food and Drinking Water Sector?
The NIS2 Directive pays special attention to the food and drinking water sector, recognizing their critical importance for security and public health. The food sector, covering production, processing, distribution, and sale of food products, has been classified as an important entity. This means that companies operating in this sector will need to implement appropriate security measures and report serious incidents. Similarly, drinking water suppliers responsible for extraction, treatment, and distribution of water intended for human consumption have been recognized as essential entities. This is due to the fact that disruption of clean water supplies could have serious consequences for the health and welfare of citizens. The inclusion of these sectors in the NIS2 scope aims to ensure a high level of protection against cyberattacks that could threaten food and water security.
Is the Space Sector Covered by the NIS2 Directive?
Yes, the NIS2 Directive for the first time includes the space sector in the scope of cybersecurity regulation at the EU level. This sector has been recognized as essential due to its strategic importance for many areas, such as communication, navigation, Earth observation, and scientific research. Entities operating in the space sector, such as satellite system operators, providers of satellite data-based services, and ground control centers, will need to implement appropriate security measures and report serious incidents. The inclusion of the space sector in NIS2 aims to protect critical space infrastructure from cyberattacks that could disrupt its functioning and have far-reaching consequences for the economy, security, and society.
What Changes Does NIS2 Introduce in the Energy Sector?
The energy sector, covering generation, transmission, distribution, and storage of electricity, oil, and gas, was already covered by the original NIS Directive as one of the essential sectors. However, NIS2 introduces several significant changes and expansions. First, the directive explicitly includes in the scope of regulation entities responsible for the production, processing, and distribution of synthetic and renewable fuels. Second, NIS2 places greater emphasis on supply chain security in the energy sector, requiring operators to manage risks associated with suppliers and subcontractors. Third, the directive strengthens requirements for incident reporting and cooperation with state authorities. These changes aim to adapt regulations to the energy transformation and the growing share of renewable energy sources, as well as to increase the sector’s resilience to cyber threats.
Which Transport Subsectors Are Included in the NIS2 Directive?
The NIS2 Directive covers key transport subsectors, recognizing their importance for citizen mobility and the functioning of the EU economy. These include air transport, including aircraft operators, airports, and air traffic management entities. Another subsector is rail transport, covering rail infrastructure managers and railway undertakings. NIS2 also includes water transport, including ship operators, maritime and inland ports, and traffic control services. Additionally, the directive addresses road transport, particularly intelligent transport systems and road traffic management. All these entities, if they meet the criteria for recognition as essential or important, will need to implement security measures and report serious incidents.
How Does NIS2 Treat the Healthcare Sector?
The healthcare sector is treated in the NIS2 Directive as essential for the security and welfare of EU citizens. It covers entities providing medical care, such as hospitals, clinics, laboratories, and primary care facilities. NIS2 imposes on these entities the obligation to implement appropriate technical and organizational measures for managing cyber risk and reporting serious incidents. The directive places particular emphasis on protecting sensitive medical data and ensuring continuity of healthcare services. Additionally, NIS2 for the first time explicitly includes medical device manufacturers in the scope of regulation, recognizing their key role in the healthcare ecosystem. Strengthening cybersecurity in the healthcare sector is particularly important in the context of increasing digitization of medical services and the use of innovative technologies such as telemedicine and remote diagnostics.
Do Small and Medium Enterprises from Key Sectors Fall Under NIS2?
The NIS2 Directive generally covers medium and large enterprises from sectors recognized as essential or important. However, in some cases, even smaller entities may fall under the provisions if they provide services of critical importance to a given sector or region. Member states have some flexibility in identifying entities covered by the directive, taking into account national specificities. NIS2 also provides for a proportionate and risk-adapted approach to security requirements for SMEs. This means that requirements placed on smaller entities should be adequate to their size, nature of activity, and level of risk. The directive encourages member states to develop special guidelines and tools that will help SMEs in risk assessment and implementation of appropriate security measures.
What New Obligations Does NIS2 Impose on Covered Sectors?
The NIS2 Directive introduces a number of new obligations for entities from regulated sectors. Above all, organizations must conduct regular cyber risk assessments and implement proportionate technical and organizational measures to manage identified risks. This includes, among others, security policies, network segmentation, data encryption, incident management, and employee training. NIS2 places great emphasis on supply chain security, obliging entities to assess and monitor risks associated with suppliers and subcontractors. The directive also introduces stricter incident reporting requirements - entities must inform competent authorities about serious incidents within 24 hours of their detection. Additionally, NIS2 requires organizations to designate a cybersecurity contact point and cooperate with state authorities and CSIRTs. The directive also encourages the use of European cybersecurity certification schemes to demonstrate compliance with requirements.
In summary, the NIS2 Directive significantly expands the scope of sectors covered by cybersecurity regulations compared to the original NIS Directive. In addition to previously included sectors such as energy, transport, banking, and healthcare, NIS2 adds public administration, space, food and chemical production, waste management, and social media, among others.
The directive introduces a new division of entities into essential and important, depending on their significance for the functioning of the economy and society. Among essential entities are energy suppliers, transport operators, hospitals, and digital infrastructure. Important entities include food production, automotive, and postal services. NIS2 also expands the scope of the digital infrastructure sector, including cloud service providers, internet search engines, and content delivery networks. The space sector has been covered by EU cybersecurity legislation for the first time.
The directive imposes new obligations on covered entities, such as regular risk assessments, implementation of security measures, incident reporting, and cooperation with state authorities. It also emphasizes supply chain security.
Although NIS2 generally covers medium and large enterprises, in some cases even smaller entities may fall under the provisions if they provide services of critical importance. The directive provides for a proportionate approach to requirements for SMEs.
The expansion of NIS2 scope aims to eliminate gaps in the security system and provide protection for all sectors critical to the functioning of the EU economy and society. In the era of increasing digitization and interdependence, a comprehensive approach to cybersecurity is essential to ensure the resilience and continuity of critical services.
NIS2 implementation will require significant efforts from member states and covered entities. However, the benefits - in the form of strengthened protection against cyberattacks, increased consumer trust, and support for digital economy development - will certainly be worth it. NIS2 is an important step in building a strong and resilient cybersecurity ecosystem across the European Union.
Related Terms
Learn key terms related to this article in our cybersecurity glossary:
- Security Operations Center (SOC) — Security Operations Center (SOC) is a central location where a team of security…
- Ransomware — Ransomware is a type of malicious software (malware) that blocks access to a…
- SOC as a Service — SOC as a Service (Security Operations Center as a Service), also known as…
- Network Security — Network security is a set of practices, technologies, and strategies aimed at…
- Cybersecurity — Cybersecurity is a collection of techniques, processes, and practices used to…
Learn More
Explore related articles in our knowledge base:
- Key Technologies for NIS2: Comprehensive Cybersecurity Solutions Overview
- How Does the NIS2 Directive Affect Enterprises? A New Era of Business Cybersecurity
- NIS2 national implementation: how the directive is changing cybersecurity law across Europe
- What Are the Main NIS2 Directive Requirements? Comprehensive Guide for Regulated Entities
- What Are the Penalties for Non-Compliance with the NIS2 Directive? Guide to Consequences of Violating New Cybersecurity Regulations
Explore Our Services
Need cybersecurity support? Check out:
- Security Audits - comprehensive security assessment
- Penetration Testing - identify vulnerabilities in your infrastructure
- SOC as a Service - 24/7 security monitoring
Cybersecurity for Your Industry
Learn more about cybersecurity in your industry:
Related topics
See also:
- NIS2 for hospitals — implementation and funding
- Security Audit Pricing Calculator
- NIS2 for hospitals — compliance
