en
Language
  • en
  • cs
  • hu
  • de
  • fr
  • es
  • br
  • ru
  • kr
  • jp
AI translation
  • it
  • pl
  • tr

What is NIS2 in cyber security?

NIS2 is the EU's main cybersecurity law. It requires medium and large organisations in critical sectors to manage cyber risks, report significant incidents and make management accountable for security. It replaced the original NIS Directive, with member states required to transpose it by 17 October 2024.

Article 21 of NIS2 lists minimum security measures that entities in scope must put in place, including:

  • Risk analysis and information system security policies.
  • Incident handling, business continuity, backups and crisis management.
  • Supply chain security, including risks from software and service providers.
  • Secure development, vulnerability handling and disclosure.
  • Cyber hygiene, staff training, cryptography and encryption.
  • Access control, asset management and multi-factor authentication.

Significant incidents must be reported in stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.

Penalties reach up to EUR 10 million or 2% of global annual turnover for essential entities, and up to EUR 7 million or 1.4% for important entities. Management bodies must approve the security measures and can be held personally liable.

Related content

What is NIS2 audit?

A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.

What is NIS2 audit?

A NIS2 audit is a review of whether an organisation meets the cybersecurity requirements of the NIS2 Directive. It can be an internal gap assessment, an independent security audit, or a supervisory audit ordered by the national competent authority. There is no single official NIS2 certificate; the audit checks compliance with the national law that transposes NIS2.

What is NIS2 and DORA?

NIS2 and DORA are two EU regulations that raise cybersecurity and digital resilience requirements. NIS2 (Directive (EU) 2022/2555) sets cybersecurity obligations for essential and important entities across 18 critical sectors. DORA (Regulation (EU) 2022/2554, the Digital Operational Resilience Act) applies specifically to the financial sector and has been in force since 17 January 2025.

Try Easy8 in 30 days free trial

  • Access all features
  • SSL protected
  • No credit card required