NIS 2 Glossary
Clear definitions of technical terms related to the NIS 2 directive and cybersecurity.
- hreflang
- An HTML and sitemap signal that tells search engines which URL serves which language/region — Google's primary mechanism for ranking the right page per audience.
- Canonical URL
- The URL Google should treat as the master version of a page, declared via `<link rel="canonical">` and (ideally) consistent across HTTP headers, sitemap, and hreflang annotations.
- ANSSI
- The French National Cybersecurity Agency is France's national authority for cybersecurity, in charge of implementing NIS 2 in France.
- Cloud Computing (SaaS, PaaS, IaaS)
- An on-demand network access model for shared computing resources. NIS 2 covers all cloud players — IaaS, PaaS and SaaS — within its regulatory scope.
- CSIRT / CERT
- Computer Security Incident Response Team: a specialised team that responds to cybersecurity incidents. ANSSI is the national CSIRT designated by France under NIS 2.
- NIS 2 Directive
- European legislation aimed at harmonising and strengthening the overall level of cybersecurity of critical infrastructure across the European Union, replacing the 2016 NIS 1 directive.
- DNS
- Domain Name System — a foundational internet infrastructure that translates domain names into IP addresses, classified as critical infrastructure under NIS 2.
- DORA
- A European digital operational resilience regulation specifically designed for the financial sector, which takes precedence over NIS 2 under the Lex Specialis principle.
- Essential Entity
- A category of entities subject to NIS 2's strictest obligations, operating in highly critical sectors and exceeding certain size thresholds.
- Important Entity
- A category of entities subject to NIS 2 with obligations comparable to essential entities, but ex-post supervision and lower penalties.
- Critical Provider to the State
- A private contractor or subcontractor whose services are essential to the continuity of the State's sovereign functions, brought into NIS 2's scope to secure the supply chain.
- Domain Name Registration Service Provider
- An official intermediary (registrar) that allocates and manages internet domain names, subject to strict NIS 2 obligations.
- Security Incident
- An event with an actual impact on the availability, authenticity, integrity or confidentiality of data or services. NIS 2 imposes strict notification deadlines for significant incidents.
- ISO 27001
- The leading international standard for setting up an Information Security Management System (ISMS), often used as a compliance framework for NIS 2.
- IXP
- Internet Exchange Point — physical infrastructure that lets different networks exchange internet traffic locally, classified as critical infrastructure under NIS 2.
- MSP / MSSP
- Managed service providers (IT outsourcing) or managed security service providers (remote SOC), subject to NIS 2 from their very first employee due to their privileged access to client infrastructure.
- Incident Notification
- A legal obligation under NIS 2 to report any significant cyberattack to ANSSI on a strict timeline: early warning within 24h, full notification within 72h, final report within one month.
- OES
- Operator of Essential Services — a legal status created by NIS 1 to designate organisations essential to the functioning of the nation, replaced by the EE and IE categories under NIS 2.
- Management Accountability
- A major shift under NIS 2: cyber compliance now personally engages the legal and financial liability of executives, not just that of the legal entity.
- CISO
- Chief Information Security Officer: the professional in charge of defining and steering an organisation's cybersecurity policy, a central player in NIS 2 compliance.
- ISMS
- Information Security Management System: an organisational framework and set of processes for managing information security systematically, often certified to ISO 27001.