GlossaryNIS2

NIS2

Short answer

NIS2 (Directive (EU) 2022/2555) is the EU law that sets cybersecurity obligations for organisations in critical and important sectors. It requires risk management measures, incident reporting within strict deadlines and direct accountability from management.

Who is in scope

NIS2 covers medium and large organisations in sectors listed in its two annexes, such as energy, transport, banking, health, digital infrastructure, ICT service management, manufacturing and food. They are classified as essential or important entities, which determines how closely they are supervised.

Main obligations

Entities in scope must apply cybersecurity risk management measures, including incident handling, business continuity, supply chain security, access control, encryption and staff training. Management bodies must approve these measures and can be held accountable for failures.

Incident reporting

Significant incidents must be reported to the national CSIRT or authority in stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month.

Penalties

Fines can reach 10 million euros or 2% of global annual turnover for essential entities, and 7 million euros or 1.4% for important entities. Each EU country applies NIS2 through its own national law, which designates the supervisory authorities.

Related terms

Keep reading on this topic

The NIS2 directive and its Spanish transposition: which entities fall in scope, governance duties, incident reporting deadlines and management liability.

Go to the topic hub