Glossary · NIS2
NIS2 Directive
The EU's Directive (EU) 2022/2555, the updated cybersecurity law covering critical sectors across the Union.
Explained in depth: NIS2 overview
The NIS2 Directive replaces the original NIS Directive of 2016 and significantly expands its scope: from a handful of sectors to 18 across Annex I and Annex II, with an estimated tens of thousands of newly covered organisations across the EU. It harmonises the size threshold (the size-cap rule), sets out ten mandatory risk-management measures in Article 21, introduces a strict three-stage incident reporting timeline in Article 23, and makes management bodies personally accountable under Article 20. NIS2 entered into force on 16 January 2023, with member states required to transpose it into national law by 17 October 2024. It interacts with sector-specific legislation: where an EU act such as DORA imposes at least equivalent requirements, that act applies instead (lex specialis).
Why it matters
NIS2 is the baseline cybersecurity law for critical sectors in the EU. If your organisation is in scope, it defines your minimum security posture, your reporting duties, and your board's accountability.
