NIS2 is the European Union's updated law for the cybersecurity of essential and important services. It covers more sectors than the earlier NIS Directive and expects organisations to manage cyber risk before an incident, not only explain it afterwards.
The directive entered into force in January 2023. EU countries had until 17 October 2024 to transpose it into national law, and NIS1 was repealed the following day. The practical rules for an organisation therefore depend on the national law that applies to it.
Who should check whether NIS2 applies
NIS2 covers 18 critical sectors. They include energy, transport, banking, health, drinking water, digital infrastructure, public administration, postal services, waste management, manufacturing and certain digital providers.
Do not decide from the company name alone: Scope can depend on sector, organisation size, the service provided and national rules. A supplier may also receive stronger security requirements through contracts even when it is not directly classified as a NIS2 entity.
Start with the official scope in the directive and the guidance from the relevant national authority. Legal and security teams should make the final determination together.
What organisations are expected to manage
NIS2 is broader than buying a security product. It asks for proportionate technical, operational and organisational measures.
- Document risks to networks, systems and critical services.
- Prepare incident handling, backup, recovery and crisis-management plans.
- Manage security risks in suppliers and service providers.
- Use appropriate access control, encryption and multifactor authentication.
- Test whether controls work and train staff for their role.
- Give management enough information to oversee and approve the programme.
Management bodies are expected to approve and oversee the risk measures. That changes NIS2 from a task left only to the security team into a governance responsibility.
Incident reporting has a timetable
When a significant incident occurs, waiting for a perfect investigation is not the plan. ENISA summarises the NIS2 sequence as an early warning within 24 hours and an incident notification within 72 hours. A final report normally follows later, with the exact process handled through the competent national authority or CSIRT.
Keep the service safe without destroying logs needed for the investigation.
Check disruption, affected users, duration, geography and possible wider impact.
Notify the designated authority or CSIRT within the required initial window.
Add the known severity, indicators and impact as the investigation becomes clearer.
Record the cause, mitigation and measures intended to prevent a repeat.
A sensible readiness plan
Begin with a service map: which systems keep the organisation running, who owns them, which suppliers they depend on and how long the business can tolerate an outage. Then compare the present controls with the national NIS2 requirements.
Why NIS2 matters beyond compliance
The useful result is not a folder prepared for an inspection. It is a service that can resist an attack, recover with less disruption and communicate clearly when customers or authorities need answers.
This article is general information, not legal advice. Confirm obligations with the competent authority and qualified advisers in the relevant country.
