← Back to Blog
NIS2

What Is the NIS2 Directive? Europe’s Updated Cybersecurity Framework

NIS2

The NIS2 Directive is the European Union’s updated cybersecurity framework and replaces NIS1. The European Commission explains that NIS2 introduces a wider scope, clearer rules, and stronger supervision tools to raise the common level of cybersecurity across the Union [4]. It focuses on protecting network and information systems, their users, and other affected individuals from cyber threats and incidents.

NIS2 establishes a common legal framework across 18 critical sectors [4]. In addition to energy, transport, healthcare, finance, water management, and digital infrastructure, the framework extends to areas such as electronic communications, broader digital services, waste and wastewater management, critical product manufacturing, postal and courier services, public administration, and space. Applicability must be assessed together with the organisation’s sector, size, role, and national implementing rules.

The Directive addresses cybersecurity risk management, incident reporting, supply-chain security, vulnerability management, business continuity, crisis management, and cyber hygiene. Significant incidents must be reported to the relevant national authorities, while Member States are expected to maintain national cybersecurity strategies [4]. NIS2 also increases top-management accountability, bringing cyber risk firmly into the boardroom.

For companies, NIS2 means that cybersecurity cannot remain solely an IT responsibility. A measurable programme should involve management, legal, procurement, operations, human resources, and information-security teams. Because transposition differs across Member States, organisations should monitor both the EU text and the guidance of the competent authority in each country where they operate.

References

  1. [4] European Commission — NIS2 Directive: Securing Network and Information Systems
Publisher's note: This content is for general information only and is not legal advice or a company-specific compliance assessment. Product scope, national implementation and applicable secondary legislation should be checked against current sources before publication.