What is NIS 2 Directive?
Definition
The NIS 2 Directive (Directive (EU) 2022/2555) is the European Union's updated cybersecurity legislation that establishes a high common level of cybersecurity across member states. It significantly expands the scope of covered sectors, strengthens cybersecurity requirements, introduces strict incident reporting obligations, and imposes personal liability on management bodies.
In Depth
NIS 2 replaces the original NIS Directive from 2016, which was deemed insufficient due to inconsistent implementation, limited scope, and weak enforcement. The updated directive expands coverage from 7 to 18 sectors organized into Sectors of High Criticality (Annex I) and Other Critical Sectors (Annex II). It applies to medium and large organizations (50+ employees or 10M+ euro turnover) operating in covered sectors, with member states able to designate smaller critical entities. NIS 2 introduces a two-tier classification: Essential Entities (large organizations in Annex I sectors) face proactive supervision and fines up to 10 million euros or 2% of global turnover, while Important Entities face reactive supervision and fines up to 7 million euros or 1.4% of turnover. Article 20 requires management bodies to approve and oversee cybersecurity measures with personal liability for infringements. Article 21 mandates 10 specific cybersecurity risk management measures including supply chain security, multi-factor authentication, and incident handling. Article 23 establishes a three-phase incident reporting timeline: early warning within 24 hours, incident notification within 72 hours, and final report within one month. Member states were required to transpose NIS 2 into national law by October 17, 2024. Organizations with existing ISO 27001 certifications have a strong foundation for NIS 2 compliance but must address additional requirements around incident reporting, management accountability, and supply chain security.
Related Frameworks
Related Terms
Essential Entity (NIS 2)
An Essential Entity under the NIS 2 Directive is a large organization operating in a Sector of High Criticality (Annex I) that is subject to proactive (ex ante) supervision and higher penalty ceilings. Essential Entities face administrative fines of up to 10 million euros or 2% of total annual worldwide turnover, whichever is higher.
Incident Response
Incident response is a structured approach to detecting, containing, eradicating, and recovering from security incidents. A well-defined incident response plan outlines roles, communication procedures, escalation paths, and post-incident review processes.
ISO 27001
ISO 27001 is an international standard published by the International Organization for Standardization (ISO) that specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). It follows a risk-based approach to managing sensitive information.
Breach Notification
Breach notification is the legal requirement for organizations to inform regulatory authorities and affected individuals when a security incident results in unauthorized access to protected data. Notification timelines and requirements vary significantly by framework and jurisdiction.
Generate compliance docs with PoliWriter
Stop reading about compliance and start achieving it. PoliWriter generates audit-ready policies customized to your organization in hours.
Get Started Free