Praeferre/Frameworks/NIS2
Security, Resilience & Assurance · European Union

NIS2 Directive — Network and Information Security

The EU's updated cybersecurity directive, widening the scope of the original NIS Directive to cover more sectors and imposing direct supply chain risk management duties on “essential” and “important” entities across the Union.

REGULATORENISA & national competent authorities REGIONEuropean Union EFFECTIVEEntered into force January 2023; transposed into national law from October 2024

Who it applies to

  • Essential and important entities across energy, transport, health, digital infrastructure and more
  • Medium and large organisations in the newly expanded sector list
  • Supply chain partners of in-scope organisations, indirectly

Key requirements

  • Board-level accountability for cybersecurity risk management
  • Supply chain risk management covering suppliers and service providers
  • 24-hour early warning and 72-hour incident notification to authorities
  • Business continuity and crisis management planning
  • Regular security testing and vulnerability management

Maximum penaltyUp to €10 million or 2% of global annual turnover for essential entities, whichever is higher

Go to the source

Official resources

Praeferre's summary is a starting point, not legal advice. For the authoritative text and current guidance, go directly to the governing body.

Start your compliance journey

See how Praeferre automates NIS2 compliance

Continuous monitoring, evidence and reporting for NIS2 — alongside every other framework you need to satisfy.