Skip to content
CyberNIS2

NIS 2 Glossary

Clear definitions of technical terms related to the NIS 2 directive and cybersecurity.

hreflang
An HTML and sitemap signal that tells search engines which URL serves which language/region — Google's primary mechanism for ranking the right page per audience.
Canonical URL
The URL Google should treat as the master version of a page, declared via `<link rel="canonical">` and (ideally) consistent across HTTP headers, sitemap, and hreflang annotations.
ANSSI
The French National Cybersecurity Agency is France's national authority for cybersecurity, in charge of implementing NIS 2 in France.
Cloud Computing (SaaS, PaaS, IaaS)
An on-demand network access model for shared computing resources. NIS 2 covers all cloud players — IaaS, PaaS and SaaS — within its regulatory scope.
CSIRT / CERT
Computer Security Incident Response Team: a specialised team that responds to cybersecurity incidents. ANSSI is the national CSIRT designated by France under NIS 2.
NIS 2 Directive
European legislation aimed at harmonising and strengthening the overall level of cybersecurity of critical infrastructure across the European Union, replacing the 2016 NIS 1 directive.
DNS
Domain Name System — a foundational internet infrastructure that translates domain names into IP addresses, classified as critical infrastructure under NIS 2.
DORA
A European digital operational resilience regulation specifically designed for the financial sector, which takes precedence over NIS 2 under the Lex Specialis principle.
Essential Entity
A category of entities subject to NIS 2's strictest obligations, operating in highly critical sectors and exceeding certain size thresholds.
Important Entity
A category of entities subject to NIS 2 with obligations comparable to essential entities, but ex-post supervision and lower penalties.
Critical Provider to the State
A private contractor or subcontractor whose services are essential to the continuity of the State's sovereign functions, brought into NIS 2's scope to secure the supply chain.
Domain Name Registration Service Provider
An official intermediary (registrar) that allocates and manages internet domain names, subject to strict NIS 2 obligations.
Security Incident
An event with an actual impact on the availability, authenticity, integrity or confidentiality of data or services. NIS 2 imposes strict notification deadlines for significant incidents.
ISO 27001
The leading international standard for setting up an Information Security Management System (ISMS), often used as a compliance framework for NIS 2.
IXP
Internet Exchange Point — physical infrastructure that lets different networks exchange internet traffic locally, classified as critical infrastructure under NIS 2.
MSP / MSSP
Managed service providers (IT outsourcing) or managed security service providers (remote SOC), subject to NIS 2 from their very first employee due to their privileged access to client infrastructure.
Incident Notification
A legal obligation under NIS 2 to report any significant cyberattack to ANSSI on a strict timeline: early warning within 24h, full notification within 72h, final report within one month.
OES
Operator of Essential Services — a legal status created by NIS 1 to designate organisations essential to the functioning of the nation, replaced by the EE and IE categories under NIS 2.
Management Accountability
A major shift under NIS 2: cyber compliance now personally engages the legal and financial liability of executives, not just that of the legal entity.
CISO
Chief Information Security Officer: the professional in charge of defining and steering an organisation's cybersecurity policy, a central player in NIS 2 compliance.
ISMS
Information Security Management System: an organisational framework and set of processes for managing information security systematically, often certified to ISO 27001.