NIS 2 Directive Explained: Who It Covers, What It Requires and How to Prepare

NIS 2 Directive network and information security

The NIS 2 Directive is the European Union’s cybersecurity law for essential and important entities. It sets minimum security measures, strict deadlines for reporting incidents and personal accountability for management. This guide explains who the NIS 2 Directive covers, what it requires and how to prepare.

Key points

  • The NIS 2 Directive is Directive (EU) 2022/2555. It replaced the first NIS Directive, and Member States had to write it into national law by 17 October 2024.
  • It covers medium and large organizations in 18 sectors, split into “essential” and “important” entities.
  • Article 21 lists ten areas of cybersecurity risk management that every entity in scope must address.
  • Significant incidents must be reported in stages: within 24 hours, within 72 hours and within one month.
  • Fines can reach EUR 10 million or 2% of worldwide annual turnover for essential entities.

What the NIS 2 Directive is

The NIS 2 Directive sets a common level of cybersecurity across the EU. It widens the scope of the first NIS Directive, makes the obligations more specific and gives national authorities stronger supervision and enforcement powers.

It is a directive, not a regulation. Each Member State writes it into its own law, so the details differ from country to country. Always check the national law of each country where you operate.

Who the NIS 2 Directive applies to

Scope depends on your sector and your size. As a rule, the NIS 2 Directive applies to medium and large organizations, meaning 50 or more employees or more than EUR 10 million in annual turnover. Some entities are in scope whatever their size, such as providers of public electronic communications networks, trust service providers and top-level domain name registries.

Sectors of high criticality (Annex I) Other critical sectors (Annex II)
Energy Postal and courier services
Transport Waste management
Banking Chemicals
Financial market infrastructures Food
Health Manufacturing
Drinking water Digital providers
Waste water Research
Digital infrastructure
ICT service management (business to business)
Public administration
Space

Large organizations in the Annex I sectors are generally essential entities. Most others in scope are important entities. Both must meet the same security requirements. The difference is in supervision and fines: essential entities are supervised proactively, important entities mainly after an incident or a complaint.

What the NIS 2 Directive requires

Ten risk management measures (Article 21)

Entities must take appropriate and proportionate technical, operational and organizational measures. At a minimum they must cover:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity, including backups, disaster recovery and crisis management
  4. Supply chain security, including relationships with suppliers and service providers
  5. Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure
  6. Policies and procedures to assess whether the measures are effective
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on the use of cryptography and, where appropriate, encryption
  9. Human resources security, access control and asset management
  10. Multi-factor authentication, secured communications and secured emergency communication systems

Incident reporting (Article 23)

Deadline What to send to the national CSIRT or authority
Within 24 hours of becoming aware An early warning, saying whether the incident may be malicious or have cross-border impact
Within 72 hours An incident notification with an initial assessment of severity and impact
Within one month A final report with the root cause, the mitigation applied and any cross-border impact

Management accountability (Article 20)

Management bodies must approve the cybersecurity risk management measures, oversee their implementation and follow training. They can be held liable if the entity does not comply. This is one of the main changes from the first NIS Directive: cybersecurity is now a board responsibility by law.

Penalties

Entity type Maximum administrative fine
Essential At least EUR 10 million or 2% of total worldwide annual turnover, whichever is higher
Important At least EUR 7 million or 1.4% of total worldwide annual turnover, whichever is higher

Authorities can also order audits, issue binding instructions and, for essential entities, ask for a manager to be temporarily barred from their role.

How to prepare for the NIS 2 Directive

  1. Confirm whether you are in scope. Check your sector, your size and the national law in each country where you operate.
  2. Register with the national authority where the law requires it.
  3. Run a gap analysis against the ten Article 21 measures.
  4. Assign responsibility and brief the management body on its duties and liability.
  5. Build the incident process so that the 24-hour, 72-hour and one-month deadlines can be met.
  6. Assess your suppliers and add security requirements to contracts.
  7. Train management and staff, and keep records.
  8. Test and improve. Check that the measures work and keep the evidence.

The NIS 2 Directive and ISO/IEC 27001

An information security management system built on ISO/IEC 27001 covers most of the Article 21 areas: risk assessment, incident management, supplier security, access control, cryptography and training. Many organizations use it as the framework for their NIS 2 Directive work. See ISO/IEC 27001 Lead Implementer.

The standard does not cover everything. The reporting deadlines, management liability and registration are legal duties that come from the directive and national law. For business continuity, ISO 22301 adds depth. Financial entities should also read our guide to DORA.

NIS 2 Directive training and certification

PECB offers two personal certifications. You take the course, pass the exam and apply for the credential.

Course Length Who it is for
NIS 2 Directive Foundation 2 days, 14 CPD credits People who need to understand the requirements. No prerequisites.
NIS 2 Directive Lead Implementer 5 days, 31 CPD credits People who plan and run a cybersecurity programme that meets the directive. A basic understanding of cybersecurity is expected.

Both are listed with the other NIS 2 Directive training courses.

Sources: Directive (EU) 2022/2555, the NIS 2 Directive (EUR-Lex) and the European Commission page on the NIS 2 Directive.

Frequently asked questions

Does the NIS 2 Directive apply to companies outside the EU?

It can. The NIS 2 Directive applies to entities that provide their services or carry out their activities in the EU, wherever they are established. Certain digital providers based outside the EU must designate a representative in a Member State where they offer services.

Is ISO/IEC 27001 certification enough for the NIS 2 Directive?

Not on its own. ISO/IEC 27001 covers much of what Article 21 asks for, and it is a recognised way to organise and evidence the work. The NIS 2 Directive adds legal duties that a certificate does not cover, such as the incident reporting deadlines, management accountability and registration with the national authority.

Is there a NIS 2 certification for organizations?

No. The NIS 2 Directive is a law, so an organization complies with it; it is not certified against it. Individuals can earn a personal credential, such as PECB Certified NIS 2 Directive Lead Implementer, by passing an exam.

What is the difference between the NIS 2 Directive and DORA?

DORA is a regulation for the financial sector and covers digital operational resilience in detail. For the financial entities it covers, DORA applies in place of the matching NIS 2 Directive provisions. Other sectors follow the NIS 2 Directive as written into national law.

Leave a Reply

Your email address will not be published. Required fields are marked *