- Full name
- Network and Information Security Directive 2
- Region
- European Union
- Applies to
- Essential and important entities across 18 sectors: energy, transport, banking, healthcare, digital infrastructure, public administration, manufacturing, postal, waste, food, chemicals, research, ICT service management, providers of digital services.
NIS2 (Directive (EU) 2022/2555) replaces the original NIS Directive and significantly expands the scope of EU cybersecurity rules. Member states had to transpose by 17 October 2024. The directive shifts cybersecurity from a technical compliance exercise to a board-level accountability with personal liability for management, harmonised incident reporting, and explicit minimum risk-management measures.