Accountability & trust

NIS2 Directive

NIS2 is an EU law that sets minimum cybersecurity standards for important services, from energy to digital infrastructure.

The NIS2 Directive is an EU law that strengthens cybersecurity rules across member states. It covers sectors seen as critical: energy, transport, banking, health, and digital infrastructure like cloud providers. Companies covered by NIS2 must meet minimum security standards and report serious incidents. It builds on an earlier, narrower version (NIS1) and reflects a wider EU push to reduce dependence on foreign digital infrastructure that falls outside EU oversight.

Frequently asked questions

What is the NIS2 Directive?

NIS2 is an EU law about cybersecurity. It sets minimum security standards for companies that provide important services. This includes things like energy, transport, and digital infrastructure.

The goal is to make critical services harder to disrupt through cyberattacks. Companies covered by NIS2 must follow specific security rules. They must also report serious security incidents to regulators.

Which companies and sectors does NIS2 apply to?

NIS2 covers sectors seen as essential to society. This includes energy, transport, banking, health, drinking water, and digital infrastructure like cloud computing.

It also covers some "important" but slightly less critical sectors, like postal services and food production. The exact size and type of company that qualifies depends on detailed rules set by each EU country.

When did NIS2 come into force?

NIS2 became EU law in January 2023. But EU countries had until October 2024 to turn it into their own national laws.

This means the exact enforcement date can differ slightly between EU countries. Some countries moved faster than others to apply the new rules.

What's the difference between NIS1 and NIS2?

NIS1 was the EU's first cybersecurity law of this kind, introduced in 2016. It covered fewer sectors, and it left a lot of detail up to each individual country.

NIS2 covers more sectors and sets stricter, more consistent rules across the EU. It also increases the penalties for non-compliance. NIS2 is meant to close the gaps that NIS1 left open.