What is NIS2 and Why Does it Matter?

NIS2 expands EU cybersecurity duties across 18 critical sectors and makes resilience a management responsibility. This explains who should check the rules, what the core duties are and how incident reporting works.

Cybersecurity shield over a map of the European Union

NIS2 is the European Union's updated law for the cybersecurity of essential and important services. It covers more sectors than the earlier NIS Directive and expects organisations to manage cyber risk before an incident, not only explain it afterwards.

The directive entered into force in January 2023. EU countries had until 17 October 2024 to transpose it into national law, and NIS1 was repealed the following day. The practical rules for an organisation therefore depend on the national law that applies to it.

Who should check whether NIS2 applies

NIS2 covers 18 critical sectors. They include energy, transport, banking, health, drinking water, digital infrastructure, public administration, postal services, waste management, manufacturing and certain digital providers.

Do not decide from the company name alone: Scope can depend on sector, organisation size, the service provided and national rules. A supplier may also receive stronger security requirements through contracts even when it is not directly classified as a NIS2 entity.

Start with the official scope in the directive and the guidance from the relevant national authority. Legal and security teams should make the final determination together.

What organisations are expected to manage

NIS2 is broader than buying a security product. It asks for proportionate technical, operational and organisational measures.

  • Document risks to networks, systems and critical services.
  • Prepare incident handling, backup, recovery and crisis-management plans.
  • Manage security risks in suppliers and service providers.
  • Use appropriate access control, encryption and multifactor authentication.
  • Test whether controls work and train staff for their role.
  • Give management enough information to oversee and approve the programme.

Management bodies are expected to approve and oversee the risk measures. That changes NIS2 from a task left only to the security team into a governance responsibility.

Incident reporting has a timetable

When a significant incident occurs, waiting for a perfect investigation is not the plan. ENISA summarises the NIS2 sequence as an early warning within 24 hours and an incident notification within 72 hours. A final report normally follows later, with the exact process handled through the competent national authority or CSIRT.

Preserve evidence and contain the incident

Keep the service safe without destroying logs needed for the investigation.

Assess significance

Check disruption, affected users, duration, geography and possible wider impact.

Send the early warning

Notify the designated authority or CSIRT within the required initial window.

Update the notification

Add the known severity, indicators and impact as the investigation becomes clearer.

Complete the final report

Record the cause, mitigation and measures intended to prevent a repeat.

A sensible readiness plan

Begin with a service map: which systems keep the organisation running, who owns them, which suppliers they depend on and how long the business can tolerate an outage. Then compare the present controls with the national NIS2 requirements.

Good first evidenceAsset register, risk decisions, incident plan, supplier records, recovery tests and management approvals
Common weak pointA written policy that has never been tested
Useful exerciseA short tabletop incident with executives, operations, legal, communications and a critical supplier
Important reminderNational transposition and regulator guidance are authoritative for compliance

Why NIS2 matters beyond compliance

The useful result is not a folder prepared for an inspection. It is a service that can resist an attack, recover with less disruption and communicate clearly when customers or authorities need answers.

This article is general information, not legal advice. Confirm obligations with the competent authority and qualified advisers in the relevant country.

Found this useful?Share it with someone.
LinkedInXBluesky

Need more practical IT guides?

Explore step-by-step tutorials, expert insights, and actionable guidance to help you work smarter, stay secure, and solve real problems.

Browse More Articles