
NIS2 Directive
Directive (EU) 2022/2555 (NIS2) is new EU cybersecurity legislation replacing the earlier NIS Directive. NIS2 entered into force at EU level on 16 January 2023. Member States were required to transpose the Directive into national law by 17 October 2024.
NIS2 Directive – Comprehensive Support from Cybernite
Why was NIS2 adopted?
NIS2 is the EU’s response to:
- the growing number and complexity of cyberattacks;
- the economy’s increased exposure to ransomware, phishing, and supply chain attacks; and
- the need to strengthen the resilience of essential sectors, from energy to public administration.
The Directive brings more sectors within its scope and introduces stricter risk-management rules and incident-reporting obligations. In practice, it is intended to strengthen the resilience of the entire EU market to cyber threats. Its principal aim is to harmonise cybersecurity standards across the Member States and require organisations to manage cyber risk proactively.
The main objectives of NIS2 are to:
- raise the level of cybersecurity across the European Union;
- reduce the risk of disruption to essential services and sectors;
- harmonise risk-management and incident-reporting rules;
- strengthen the accountability of management bodies; and
- improve cooperation between Member States.
NIS2 treats cybersecurity as a business and operational risk, not merely as a technical matter for the IT department.
Who does NIS2 apply to?
The legislation does not apply to every business; it focuses on entities of strategic importance to the state and the economy. The principal criteria are the size of the organisation – typically medium-sized and large enterprises with more than 50 employees – and the sector in which it operates.
Entities are divided into two groups, subject to different levels of supervisory oversight.
1. Essential entities
These entities operate in sectors of the highest criticality and are subject to rigorous, proactive supervision:
- energy, including electricity, gas, oil, and district heating;
- air, rail, waterborne and road transport;
- banking and financial market infrastructures;
- healthcare, including hospitals, laboratories and pharmaceutical manufacturers;
- drinking water and wastewater; and
- digital infrastructure, including cloud computing service providers, data centre service providers, and electronic communications networks.
2. Important entities
These entities operate in sectors subject primarily to ex post supervision, usually after an incident has occurred:
- postal and courier services;
- waste management;
- the manufacture and distribution of chemicals;
- food production, processing, and wholesale distribution;
- manufacturing, including electronics, machinery, and vehicles; and
- digital service providers, including online marketplaces and search engines.
Main requirements for organisations
NIS2 imposes specific obligations that must be embedded in an organisation’s day-to-day operations:
- Risk management: The organisation must maintain documented security policies, conduct regular audits, and assess potential failures and threats affecting its IT systems.
- Business continuity: In the event of a ransomware attack or system failure, the organisation must have business continuity and disaster recovery plans and backups in place so that services can be restored as quickly as possible.
- Supply chain security: A company is responsible not only for its own cybersecurity but must also verify that its software and IT service providers have appropriate cybersecurity measures in place.
- Encryption and MFA: The organisation must implement modern safeguards such as data encryption and multi-factor authentication – for example, approving sign-in attempts through a mobile app.
- Incident reporting: If a significant incident occurs, the organisation must notify the relevant CSIRT within the prescribed time limits:
- an initial warning within 24 hours;
- a full assessment of the incident within 72 hours.
What does this mean for businesses?
For businesses, NIS2 entails:
- reviewing and updating security processes;
- establishing a risk-management system;
- strengthening supply chain security;
- introducing regular security audits;
- imposing stricter requirements on IT providers, service operators, and software development companies; and
- promptly reporting incidents and maintaining the required documentation.
The Directive covers far more entities than its predecessor, including medium-sized enterprises and certain smaller businesses in critical sectors.
Management body accountability
This is one of the most important aspects of NIS2. Cybersecurity is no longer solely a matter for the IT department.
- The management body approves cybersecurity measures and oversees their implementation.
- Members of management bodies may incur personal financial liability for gross negligence.
- The management body is under a statutory obligation to undergo regular training on cyber threats.
Penalties for non-compliance
The fines provided for under NIS2 are comparable to those imposed under the GDPR and may be levied directly by the supervisory authorities:those laid down in GDPR and may be imposed directly by supervisory authorities:
- essential entities: up to EUR 10 million or 2% of total worldwide annual turnover;
- important entities: up to EUR 7 million or 1.4% of total worldwide annual turnover.
In addition to fines, supervisory authorities may issue corrective orders and warnings, temporarily suspend service certification and, in extreme cases, prohibit responsible individuals from performing managerial functions.
Summary
NIS2 is one of Europe’s most important pieces of cybersecurity legislation. It is intended to strengthen the resilience of the economy as a whole to growing cyber threats and introduce harmonised protection standards.
For businesses, NIS2 means adapting processes, raising security standards, and preparing for stringent reporting and supervisory requirements. Although implementation may be demanding, it will strengthen organisational resilience and the security of the wider ecosystem.
Prepared by Professor Grzegorz Strupczewski
Through Cybernite Status we help organisations assess their current cybersecurity posture and regulatory readiness.
Through Cybernite Safe, we provide ongoing support with cybersecurity management, regulatory obligations, and compliance with industry standards under a Cybersecurity as a Service (CSaaS) model.

Do you need support with NIS2, the CRA, DORA or the AI Act – from determining whether the requirements apply and conducting a gap analysis to reviewing the measures already taken and addressing any remaining gaps?
Cybernite can help you organise your documentation, implement the missing measures and maintain compliance in practice.