Category: NIS2
The NIS2 Directive is EU cybersecurity legislation covering essential and important entities across eighteen sectors. As a Directive it is transposed into national law by each member state, so the detail — and the penalties — vary by country. The transposition deadline was 17 October 2024.
It widened the original NIS Directive substantially, both in the sectors covered and in what is required. Article 21 sets out risk-management measures spanning risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, cryptography, access control and more.
Two features distinguish NIS2 from what came before. Management bodies must approve and oversee cybersecurity measures and can be held personally liable, which moves the conversation into the boardroom. And reporting is fast: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.
An ISO 27001 ISMS covers a large share of the Article 21 measures and is the most efficient way to build the evidence — but NIS2 compliance is a legal determination made by your national authority, not something a certificate confers.
The guides below cover what NIS2 requires, who is in scope, the penalties and deadlines, and how it compares with ISO 27001 and DORA.