What Is NIS2 (Network and Information Security Directive)?

Also called: NIS2 Directive

Related problems: We operate in the EU and don't know whether we are an essential or important entity; EU customers asking about our supply chain security and incident reporting; Board members told they are personally accountable for cybersecurity; Not sure how fast an incident has to be reported in Europe

The Network and Information Security Directive (NIS2) is the European Union’s main cybersecurity law for organizations in critical sectors. It replaced the original NIS Directive, widened the list of sectors covered, and requires medium and large organizations in those sectors to manage cybersecurity risk, report significant incidents quickly and hold their management accountable. Because it is a directive, each member state implements it in national law, so details vary by country. This entry is an overview for buyers, not legal advice.

At a glance

  • NIS2 covers medium and large organizations in a long list of sectors, including energy, transport, health, finance, water, digital infrastructure, ICT service management, public administration, manufacturing and postal services.
  • Covered organizations are classed as essential or important entities, which affects supervision and maximum fines more than the obligations themselves.
  • Required measures include risk analysis, incident handling, business continuity, supply chain security, multi-factor authentication where appropriate, cryptography and staff training.
  • Significant incidents follow a staged timeline: early warning within 24 hours, notification within 72 hours and a final report within one month.
  • Management bodies must approve cybersecurity measures, oversee them, take training and can be held accountable.

What problem it solves

The first NIS Directive left gaps: member states defined covered organizations differently, many important sectors were left out, and enforcement was uneven. Meanwhile, attacks on hospitals, utilities and suppliers showed how one weak link can disrupt services across borders. NIS2 sets a common, higher baseline, brings far more organizations into scope and gives regulators stronger powers.

For a mid-market buyer, NIS2 appears in two ways. If you operate in the EU in a covered sector, you may be directly regulated. If you sell to covered organizations, especially as a cloud, data center, managed service or security provider, expect detailed supplier security questions and contract terms.

How it works

Scope. National laws identify covered entities by sector and size, with some entities, such as certain digital infrastructure providers, covered regardless of size. Many countries require entities to register with the authority.

Risk-management measures. Entities take appropriate and proportionate technical, operational and organizational measures, including policies on risk analysis, incident handling, business continuity and crisis management, supply chain security, secure development and vulnerability handling, effectiveness assessment, cyber hygiene and training, cryptography, access control and multi-factor authentication.

Governance. Management bodies approve the measures, oversee their implementation and follow training, and can be held liable for failures under national law.

Incident reporting. Significant incidents are reported to the national CSIRT or competent authority in stages, and recipients of the service may need to be informed.

Supervision and penalties. Authorities can audit, inspect, issue binding instructions and impose fines, with higher maximums for essential entities.

Entity categories

Category Who it typically covers Supervision What entities typically show
Essential entity Large organizations in the highest-criticality sectors, plus some providers designated regardless of size Proactive (ex ante): audits, inspections and information requests without waiting for an incident Risk-management policies, audit results, incident reports, registration
Important entity Medium-sized organizations in high-criticality sectors and medium or large ones in other critical sectors Reactive (ex post): typically after evidence or an incident Same measures, documented and ready for inspection
Supplier to covered entities Vendors not directly in scope Indirect, through customer contracts Questionnaires, certifications such as ISO/IEC 27001, contract commitments

Sector lists and size tests come from the directive, but national laws apply them; confirm your classification in each country.

When it matters for buyers

  • When you operate in an EU covered sector. Confirm your classification and registration in each country.
  • When choosing cloud, data center, MSP or MSSP providers. They may be covered entities, and their resilience and reporting become part of yours.
  • When your board asks about accountability. NIS2 makes cybersecurity a management duty.
  • When planning incident response. The 24-hour early warning needs a process that works on a weekend.

Our governance, risk and compliance, incident response and managed detection and response overviews cover help with the measures and reporting.

Questions to ask vendors

  • Are you a covered entity under NIS2 in any member state, and in which category?
  • How quickly will you notify us of incidents affecting our service, so we can meet our own deadlines?
  • What security certifications or reports can you share, and are they scoped to this service?
  • How do you manage security in your own supply chain and subcontractors?
  • Where is our data processed, and how do you support business continuity across regions?
  • Will you support our audits and regulators’ requests for information?

How it differs from DORA

The Digital Operational Resilience Act (DORA) is an EU regulation that applies directly to financial entities and sets detailed rules for ICT risk, incident reporting, resilience testing and third-party risk. For financial entities covered by DORA, its rules generally take precedence over NIS2’s equivalent requirements. NIS2 is a directive covering many sectors through national laws. Both are separate from the General Data Protection Regulation (GDPR), which governs personal data: one incident can trigger NIS2 or DORA reporting and GDPR breach notification at the same time. Frameworks such as ISO/IEC 27001 can support NIS2 measures, but they are not the same as compliance, and a solid incident response (IR) plan and risk assessment process sit at the center of both. A governance, risk and compliance (GRC) program usually tracks them together.

Frequently Asked Questions

Does NIS2 apply to companies outside the EU?
It can. It applies to entities that provide services or carry out activities in the EU in covered sectors, and certain digital providers without an EU establishment may need to designate a representative there. Suppliers to covered entities also feel it through contracts. Whether it applies to you depends on the facts and national law; check with counsel. This is not legal advice.
What is the difference between essential and important entities?
Both must take the same kinds of risk-management measures and report significant incidents. Essential entities, generally larger organizations in the most critical sectors, face proactive supervision and higher maximum fines; important entities are mainly supervised after the fact, for example following an incident or complaint. Member states can also designate entities regardless of size.
How quickly must incidents be reported under NIS2?
For significant incidents, the directive sets an early warning within 24 hours of becoming aware, an incident notification within 72 hours and a final report within one month, sent to the national CSIRT or competent authority. National laws implement the details, so confirm the rules in each country.
Is NIS2 a law that applies directly?
No. It is a directive, so each EU member state writes it into national law, and requirements, registration steps and enforcement vary by country. Member states were due to do this by October 2024, and some were late, so check the status in each country where you operate.
Does NIS2 affect our IT and cloud suppliers?
Yes, in two ways. Cloud, data center, managed service and managed security providers can be covered entities themselves. And covered entities must address supply chain security, so they push requirements to their suppliers through questionnaires and contracts.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.