Skip to content

NIS2

Directive (EU) 2022/2555. It extends mandatory cybersecurity to whole sectors that were previously outside it, and makes management accountable.

What NIS2 is

NIS2 is the European cybersecurity directive that replaces the original NIS. Being a directive rather than a regulation, it requires each member state to transpose it into national law, and that transposition can add requirements and set deadlines.

Its substantive change relative to the earlier NIS is one of scale: it widens the sectors covered, raises the requirements, hardens the sanctions regime, and holds management bodies directly accountable.

Who NIS2 applies to

The directive distinguishes essential from important entities, by sector and size. Its annexes cover sectors of high criticality such as energy, transport, banking, health, water and digital infrastructure, and other critical sectors including postal services, waste management, food and manufacturing.

Below certain size thresholds most entities fall outside, with exceptions where the service is critical regardless of size.

What NIS2 requires

Risk management measures (Art. 21). Risk analysis and security policy. Incident handling. Business continuity and crisis management. Supply chain security. Security in acquisition, development and maintenance. Assessment of the effectiveness of the measures. Cyber hygiene and training. Cryptography. Human resources security and access control. Multi-factor authentication and secure communications.

Incident reporting (Art. 23), in three stages. An early warning within 24 hours. Incident notification within 72 hours. A final report within one month.

Management accountability. Management bodies approve the measures, oversee their implementation, and can be held personally liable for failures. It is the change with the most practical consequences in the whole directive.

How NIS2 is demonstrated

There is no NIS2 certificate. Conformity is demonstrated to the competent national authority through documentation, implemented measures and incident records.

Many organisations build on a management system they already have, because the underlying work overlaps.

With Zerod

NIS2 requires management to answer for security. Zerod makes that possible.

Activate NIS2 and Zerod gives you the directive's control register, generates the risk management documentation, and connects incident handling to the reporting deadlines the directive imposes.

Frequently asked questions

Does NIS2 apply to me as a supplier to an essential entity?

The directive requires covered entities to manage the security of their supply chain. NIS2 may not apply to you directly and your customer may still pass requirements to you by contract.

Is there a NIS2 certificate?

No. It is a legal obligation supervised by national authorities, not a certification scheme.

NIS2 · Zerod