NIS2 (NIS 2 Directive)

NIS2 is the EU directive on measures for a high common level of cybersecurity across the Union (Directive (EU) 2022/2555). It replaces the first NIS Directive and significantly expands obligations and scope.

It affects essential and important entities from 18 sectors – from energy, health and transport to digital infrastructure and manufacturing – generally from medium-sized organizations upward, in some cases regardless of size. Core obligations include risk management measures (including access control, encryption, backup and crisis management, supply chain security), staggered reporting obligations for significant incidents (early warning within 24 hours, follow-up report within 72 hours) and the personal responsibility of management for implementation.

Transposition into national law takes place in each member state – in Germany via the NIS 2 Implementation Act. Organizationally, the requirements are usually met via an ISMS that structures risk management, measures and evidence; in professional terms, NIS2 is thus a central driver of investment in IT Security.