Glossary
NIS 2 Directive
European legislation aimed at harmonising and strengthening the overall level of cybersecurity of critical infrastructure across the European Union, replacing the 2016 NIS 1 directive.
The NIS 2 Directive (Network and Information Security, version 2) is European legislation that harmonises, strengthens and raises the overall level of cybersecurity of critical infrastructure and key businesses across the European Union. It replaces the original 2016 directive, massively widening the list of sectors in scope and toughening penalties.
Key changes from NIS 1
- Wider scope: from 7 sectors covered under NIS 1 to 18 sectors, bringing several thousand additional entities into scope.
- Two categories of entities: a distinction between Essential Entities (EE) and Important Entities (IE), with different supervision regimes.
- Management accountability: governing bodies are personally accountable for compliance with cybersecurity obligations.
- Stronger penalties: up to €10M or 2% of worldwide turnover for EEs, €7M or 1.4% for IEs.
- Strict notification deadlines: early warning within 24h, initial notification within 72h, final report within one month.
Timeline
Published on 27 December 2022 and entering into force on 16 January 2023, the directive had to be transposed into the national law of each member state by 17 October 2024.