Security, Resilience & Assurance · European Union
NIS2 Directive — Network and Information Security
The EU's updated cybersecurity directive, widening the scope of the original NIS Directive to cover more sectors and imposing direct supply chain risk management duties on “essential” and “important” entities across the Union.
REGULATORENISA & national competent authorities
REGIONEuropean Union
EFFECTIVEEntered into force January 2023; transposed into national law from October 2024
Who it applies to
- Essential and important entities across energy, transport, health, digital infrastructure and more
- Medium and large organisations in the newly expanded sector list
- Supply chain partners of in-scope organisations, indirectly
Key requirements
- Board-level accountability for cybersecurity risk management
- Supply chain risk management covering suppliers and service providers
- 24-hour early warning and 72-hour incident notification to authorities
- Business continuity and crisis management planning
- Regular security testing and vulnerability management
Maximum penaltyUp to €10 million or 2% of global annual turnover for essential entities, whichever is higher
Go to the source
Official resources
Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.
Start your compliance journey
See how Praeferre automates NIS2 compliance
Continuous monitoring, evidence and reporting for NIS2 — alongside every other framework you need to satisfy.