Cybersecurity Glossary

What is the NIS2 Directive?

NIS2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the European Union. It expands the sectors and entities covered by its predecessor and strengthens management responsibility, risk management, incident reporting, supply-chain security and supervision.

As a directive, NIS2 is implemented through national law. The EU transposition deadline was 17 October 2024, but national details differ. Organizations must assess the law in each relevant member state rather than treating the directive text or a generic company-size rule as the complete answer.

Which organizations can be affected?

The directive covers specified sectors including energy, transport, health, digital infrastructure, public administration and several manufacturing and digital-service categories. Size thresholds are important, but special cases can bring smaller entities into scope. Supply-chain requirements also affect providers that are not directly regulated.

Scope cannot be determined from sector or employee count alone. Legal form, activity, size, establishment, member state and special rules all matter. Certain providers of digital infrastructure and public services may be covered regardless of general thresholds. Groups also need to determine how size is calculated and which legal entity provides the regulated service. A documented applicability assessment is therefore the first reliable implementation step.

Essential and important entities

At EU level, NIS2 distinguishes essential entities from important entities. Both must implement the risk-management and reporting requirements. The main difference concerns supervision and the measures available to authorities. National legislation determines the precise terminology and classification in each member state.

AspectEssential entitiesImportant entities
Core dutiesRisk management and incident reportingRisk management and incident reporting
SupervisionProactive and incident-driven supervision may applyGenerally incident-driven ex-post supervision
ClassificationParticularly critical sectors and servicesOther critical sectors named by the directive

What are the central obligations?

  • - Management oversight and training.
  • - Proportionate technical, operational and organizational risk controls.
  • - Incident handling, continuity, crisis management and supply-chain security.
  • - Early warning and staged reporting of significant incidents within the applicable national process.

Article 21 includes risk analysis, incident handling, business continuity, backup and crisis management, supply-chain security, secure acquisition and development, effectiveness assessment, cyber hygiene, cryptography, access control and multi-factor authentication. Measures must be proportionate to risk. A firewall or annual vulnerability scan alone cannot satisfy this duty; the organization needs a managed and evidenced process across technology, people and operations.

Which reporting deadlines apply?

  1. Early warning:
    generally within 24 hours of becoming aware of a significant incident.
  2. Incident notification:
    generally within 72 hours, including an initial assessment, severity and known impact.
  3. Intermediate report:
    when requested by the competent authority or CSIRT.
  4. Final report:
    generally no later than one month after the incident notification; an ongoing incident first receives a progress report.

The clock starts when the organization becomes aware of the significant incident, not after full forensic investigation. Organizations therefore need defined assessment and escalation criteria, reachable decision-makers and prepared reporting channels. Data-protection notifications, customer communication and sector-specific reporting may apply in parallel.

What is management responsible for?

Management bodies must approve the cybersecurity risk-management measures, oversee implementation and receive training. Information security cannot be delegated completely to IT or an external provider. Management needs to understand risks, priorities, resources and accepted residual risk. In practice, this requires regular reporting with understandable metrics, documented decisions and clear accountability rather than a signature on policies alone.

How can NIS2 be implemented?

Determine legal scope with qualified advice, identify essential services and dependencies, compare existing controls with national requirements, assign management ownership and close gaps with evidence. In Germany, affected organizations should use the current BSI guidance and portal; the BSI states that the statutory registration deadline has already passed.

  1. Applicability and scope:
    identify regulated entities, services, locations, systems and dependencies.
  2. Accountability:
    connect management, security, operations, legal, privacy and communications through clear roles.
  3. Gap analysis:
    compare existing controls with national requirements and Article 21.
  4. Risk treatment:
    prioritize measures, assign owners and deadlines, and justify exceptions.
  5. Incident exercises:
    test detection, assessment, 24-/72-hour reporting and crisis communication.
  6. Effectiveness:
    demonstrate controls through technical testing, audits, metrics and finding remediation.
Testing technical security controls for NIS2

What evidence is useful?

Useful evidence includes an up-to-date service and asset inventory, risk assessments, policies, training records, supplier reviews, backup and recovery tests, incident records and documented effectiveness checks. An ISMS can organize this evidence. Penetration tests demonstrate selected technical controls, but do not replace governance or continuous risk management.

NIS2, DORA and ISO 27001 compared

DORA is directly applicable EU law for the financial sector and contains detailed digital operational resilience requirements. NIS2 covers many sectors and is implemented nationally. ISO/IEC 27001 is a voluntary certifiable management standard. They overlap in risk management, incidents, suppliers and effectiveness review. Existing ISO 27001 processes are therefore a useful foundation, but do not automatically demonstrate full NIS2 compliance.

Penetration Tests

Uncover Security Vulnerabilities

Professional penetration testing for your business

Web Apps
Networks
Mobile Apps
10% New Customer Discount
Plan Now

Thank you for your feedback! We will review it and optimize this content.

Do you have feedback on NIS2? Tell us!