Back to Frameworks
Frameworks

NIS2 Directive

Framework Name

NIS2 Directive

Type

Mandatory

Region / Jurisdiction

European Union (national implementation and exact requirements vary by member state)

Enforcing Body / Certifying Party

A designated National Competent Authority in each EU member state, since NIS2 requires each country to pass its own national law to implement it, rather than applying directly and uniformly the way a Regulation does

Penalty / Consequence of Non-Compliance

Up to €10 million or 2% of global annual turnover for "essential" entities, with lower caps for "important" entities, though exact amounts, and how strictly they're applied, depend on each country's own transposing law. Management bodies can also face personal liability, and in some countries, temporary bans from holding a management position

What It Is & Why It Matters

NIS2 sets baseline cybersecurity requirements across roughly 160,000 organizations spanning 18 sectors, energy, healthcare, transport, telecommunications, digital infrastructure, public administration, and more. It splits organizations into "essential" entities, which face proactive supervision including regular audits and inspections, and "important" entities, which are supervised reactively, mainly triggered by an incident or a complaint. This is a meaningfully different legal instrument than most others on your list: NIS2 is a Directive, not a Regulation, which means the EU set the requirements, but each member state had to write and pass its own national law to actually put it into effect, and those national laws don't all read identically.

It matters both for its own scope and for what it doesn't cover: NIS2 is the general cybersecurity baseline across many industries, while frameworks like DORA carve out their own sector, DORA takes precedence over NIS2 for financial entities specifically, applying its own more detailed rules instead. For any organization not in a sector with its own specialized law, NIS2 is the relevant EU cybersecurity baseline, and its personal liability provisions have pushed cybersecurity conversations into boardrooms in a way earlier EU cyber rules didn't.

Who Needs It

  • You operate in one of NIS2's 18 in-scope sectors within the EU, including as a medium or large company
  • You provide digital infrastructure, cloud, or managed IT services into the EU, sectors NIS2 explicitly targets
  • You are a non-EU company providing in-scope services into the EU and may soon need to designate an EU representative, under an amendment currently being discussed
  • Your board or executive team needs to understand personal liability exposure for cybersecurity failures under EU law
Book A Demo