Glossary · NIS2
NIS1 (The Original NIS Directive)
Directive (EU) 2016/1148, the EU's first cybersecurity law, replaced by NIS2 in 2023.
Explained in depth: NIS2 overview
The original NIS Directive (2016/1148) was the EU's first horizontal cybersecurity legislation. It covered operators of essential services in seven sectors and certain digital service providers, but left much of the scoping to member states, which led to large differences between countries: the same company could be in scope in one member state and out of scope in its neighbour. NIS2 was created to fix those weaknesses. It expands coverage from roughly 7 to 18 sectors, replaces national scoping discretion with the uniform size-cap rule, replaces the OES/DSP categories with essential and important entities, adds concrete minimum security measures, introduces the strict three-stage reporting timeline, and adds management liability and meaningful penalty ceilings.
Why it matters
Organisations that were compliant under NIS1 cannot assume they are compliant under NIS2: the scope is wider, the measures more prescriptive, and the accountability personal. "NIS vs NIS2" remains a high-volume search, which makes this entry a useful traffic page.
