The NIS2 Directive is the European Union’s updated cybersecurity framework and replaces NIS1. The European Commission explains that NIS2 introduces a wider scope, clearer rules, and stronger supervision tools to raise the common level of cybersecurity across the Union [4]. It focuses on protecting network and information systems, their users, and other affected individuals from cyber threats and incidents.
NIS2 establishes a common legal framework across 18 critical sectors [4]. In addition to energy, transport, healthcare, finance, water management, and digital infrastructure, the framework extends to areas such as electronic communications, broader digital services, waste and wastewater management, critical product manufacturing, postal and courier services, public administration, and space. Applicability must be assessed together with the organisation’s sector, size, role, and national implementing rules.
The Directive addresses cybersecurity risk management, incident reporting, supply-chain security, vulnerability management, business continuity, crisis management, and cyber hygiene. Significant incidents must be reported to the relevant national authorities, while Member States are expected to maintain national cybersecurity strategies [4]. NIS2 also increases top-management accountability, bringing cyber risk firmly into the boardroom.
For companies, NIS2 means that cybersecurity cannot remain solely an IT responsibility. A measurable programme should involve management, legal, procurement, operations, human resources, and information-security teams. Because transposition differs across Member States, organisations should monitor both the EU text and the guidance of the competent authority in each country where they operate.