NIS2 significantly widens the EU's cybersecurity rules. Here's who it covers and what it asks of you.
What is NIS2?
NIS2 is the EU's updated Network and Information Security Directive. It broadens the original NIS directive — more sectors, stricter risk-management and incident-reporting duties, and real accountability for management.
Who does it apply to?
A much wider set of "essential" and "important" entities across critical sectors — energy, transport, health, digital infrastructure, public administration, manufacturing and more — operating in the EU, including many companies that weren't in scope before.
What does it require?
- Risk-management measures — policies, access control, encryption, supply-chain security, and more.
- Incident reporting — notify authorities within tight timelines.
- Management accountability — leadership is responsible for compliance.
- Supply-chain security — assess and manage third-party risk.
General guidance, not legal advice. Confirm your NIS2 obligations with your compliance and legal teams.