NIS and NIS 2 — What is it?
Everything you need to know about the European directive on the security of network and information systems, and its evolution into NIS 2.
1The NIS directive (2016)
The NIS (Network and Information Security) directive, adopted in July 2016, was the first European legislation dedicated to cybersecurity. It aimed to achieve a common high level of security of network and information systems across the European Union.
It required Operators of Essential Services (OES) and Digital Service Providers (DSPs) to implement security measures and report major incidents.
2The NIS 2 directive (2022)
The NIS 2 directive (EU 2022/2555), published on 27 December 2022 and entering into force on 16 January 2023, repeals and replaces NIS 1. Member States had until 17 October 2024 to transpose it into national law.
NIS 2 marks a major qualitative leap: broader scope, stronger obligations, stricter penalties, and direct accountability for management bodies.
Broader scope
From a few hundred OES to several thousand entities covered across 18 sectors.
Stricter penalties
Up to €10 M or 2% of global turnover for essential entities; €7 M or 1.4% for important entities.
Strict deadlines
Incident notification: 24h (early warning), 72h (initial notification), 1 month (final report).
Who is affected?
NIS 2 distinguishes two categories of entities based on their size and sector. The main criterion is exceeding thresholds of 250 employees or €50 M turnover / €43 M balance sheet for essential entities, and 50 employees or €10 M for important entities.
- Energy (electricity, gas, oil, hydrogen)
- Transport (air, rail, maritime, road)
- Banking sector
- Financial market infrastructures
- Health (hospitals, laboratories, R&D)
- Drinking water
- Wastewater
- Digital infrastructure (DNS, IXP, cloud, datacentres…)
- ICT service management (B2B)
- Public administrations
- Space
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacturing (medical devices, machinery, vehicles…)
- Digital providers (online marketplaces, social networks, search engines…)
- Research
Exception: certain entities are covered regardless of their size (e.g.: providers of public electronic communications networks, public administrations, entities critical under other EU regulations).
Key obligations
NIS 2 imposes a minimum baseline of cybersecurity measures for all covered entities.
Cyber risk management
Implement proportionate technical and organisational measures to manage the risks to the security of networks and information systems.
Incident notification
Report any significant incident to the competent authority within strict deadlines: early warning within 24h, notification within 72h, final report within one month.
Supply chain security
Assess and manage risks related to suppliers and service providers who have access to your systems or data.
Management accountability
Governing bodies must approve cyber risk management measures and can be held personally liable for failures.
Business continuity
Maintain business continuity and recovery plans to keep essential services running in the event of a cyber crisis.
Training and awareness
Regularly train all members of the organisation, including management, on cybersecurity best practices.
NIS 1 vs NIS 2 — Key differences
| Criterion | NIS 1 | NIS 2 |
|---|---|---|
| Sectors covered | 7 sectors | 18 sectors |
| Entities targeted | A few hundred (OES) | Several thousand |
| Management liability | Not provided | Yes, mandatory engagement |
| Supply chain | Not provided | Obligation to secure |
| Notification deadline | "Without undue delay" | 24h / 72h / 1 month |
| Max. penalty | Varies by State | €10 M or 2% of global turnover |
| EU harmonisation | Weak | Strengthened |
Are you affected by NIS 2?
Answer a few questions to get a personalised diagnosis of your regulatory situation.