Reference
NIS2 & EU Regulation Glossary
A working dictionary of the terms that appear in EU compliance documentation. Each entry gives a one-line definition you can quote, a short explanation, and links to the pages where the term matters in practice.
A
- Annex I·Which sectors NIS2 covers
The list of 11 sectors under NIS2 considered most critical, whose in-scope organisations are classified as essential entities.
- Annex II·Which sectors NIS2 covers
The list of 7 sectors under NIS2 considered important but generally lower-risk than Annex I.
- Article 20·NIS2 penalties and management liability
The NIS2 provision requiring management bodies to approve, oversee, and be trained on cybersecurity risk measures.
- Article 21·The 10 NIS2 security requirements
The section of the NIS2 Directive that sets out the 10 mandatory cybersecurity risk-management measures.
- Article 23·NIS2 incident reporting timeline
The NIS2 provision setting the mandatory incident reporting timeline.
C
- Competent Authority·Who NIS2 applies to
The national body in an EU member state responsible for supervising NIS2 compliance.
- CSIRT·NIS2 incident reporting timeline
Computer Security Incident Response Team — the national body organisations report significant incidents to under NIS2.
E
- Essential Entity·Who NIS2 applies to
An organisation classified under NIS2 Annex I sectors that faces the strictest supervisory regime and highest penalty ceiling.
I
- Important Entity·Who NIS2 applies to
An organisation under NIS2 Annex I or II sectors that meets the medium-enterprise threshold without reaching essential-entity status.
M
- Management Body·NIS2 penalties and management liability
The board of directors, executive committee, or equivalent governing body of an organisation.
- Multi-Factor Authentication (MFA)·The 10 NIS2 security requirements
A login security method requiring more than one form of verification, required under NIS2 Article 21(j).
N
- National Transposition·Who NIS2 applies to
The process by which an EU member state converts the NIS2 Directive into its own national law.
- NIS2 Directive·NIS2 overview
The EU's Directive (EU) 2022/2555, the updated cybersecurity law covering critical sectors across the Union.
S
- Significant Incident·NIS2 incident reporting timeline
An incident that has caused, or could cause, severe operational disruption, financial loss, or considerable damage to others.
- Supply Chain Security·The 10 NIS2 security requirements
One of the 10 Article 21 measures, requiring entities to assess and manage cybersecurity risk from suppliers and service providers.