In short: The NIS2 Directive strengthens cybersecurity requirements for essential and important entities across the EU. Member states were required to transpose it into national law by 17 October 2024.
Who is covered by NIS2?
Medium and large organizations in sectors such as energy, transport, health, digital infrastructure, manufacturing and public administration.
What does NIS2 require?
- Cybersecurity risk management measures
- Incident reporting within tight timelines
- Supply chain security
- Management accountability and training
How do ISO standards help?
ISO/IEC 27001 provides a recognised framework for many NIS2 risk management expectations.
Key takeaways
- NIS2 expands EU cybersecurity obligations.
- Management bodies are accountable.
- ISO/IEC 27001 supports compliance.
Frequently asked questions
What is the difference between essential and important entities?
Classification depends on sector and size; essential entities face stricter supervision.
Does NIS2 cover suppliers?
Supply chain security is a required risk management measure.
Is ISO/IEC 27001 certification mandatory?
No, but it can help demonstrate appropriate measures.