Guide · NIS2

NIS2 explained

NIS2 significantly widens the EU's cybersecurity rules. Here's who it covers and what it asks of you.

What is NIS2?

NIS2 is the EU's updated Network and Information Security Directive. It broadens the original NIS directive — more sectors, stricter risk-management and incident-reporting duties, and real accountability for management.

Who does it apply to?

A much wider set of "essential" and "important" entities across critical sectors — energy, transport, health, digital infrastructure, public administration, manufacturing and more — operating in the EU, including many companies that weren't in scope before.

What does it require?

  • Risk-management measures — policies, access control, encryption, supply-chain security, and more.
  • Incident reporting — notify authorities within tight timelines.
  • Management accountability — leadership is responsible for compliance.
  • Supply-chain security — assess and manage third-party risk.
It overlaps with ISO 27001Most NIS2 measures map to controls you'd already run for ISO 27001. Collecting shared evidence once means your ISO work supports NIS2 — and a self-hosted, in-region deployment fits NIS2's data expectations. See NIS2 with Vallorix.

General guidance, not legal advice. Confirm your NIS2 obligations with your compliance and legal teams.

See Vallorix on your own infrastructure

Continuous evidence, auditor-ready reports, and controls that stay in your boundary.

Get a demo →
V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect