The Network and Information Security Directive 2 strengthens cybersecurity requirements across the EU. Essential and important entities must comply by October 2024.
NIS2 significantly expands the scope of organizations that must comply with EU cybersecurity requirements.
Stricter requirements & supervision
Lighter-touch regulation
Size threshold: Generally applies to medium-sized enterprises (50+ employees, €10M+ turnover) and large enterprises, but some entities are covered regardless of size.
NIS2 mandates comprehensive cybersecurity risk management measures
Implement policies for risk analysis and information system security, including threat assessment and vulnerability management.
Establish procedures for preventing, detecting, and responding to cybersecurity incidents with defined escalation paths.
Ensure business continuity with backup management, disaster recovery, and crisis management procedures.
Manage security risks in relationships with suppliers and service providers, including contractual requirements.
Address security in network and information systems acquisition, development, and maintenance.
Regular testing and auditing of cybersecurity risk management measures and their effectiveness.
NIS2 introduces strict incident notification requirements with specific deadlines.
Initial notification to CSIRT/authority about significant incidents
Detailed assessment including severity, impact, and indicators of compromise
Complete report with root cause, mitigation measures, and cross-border impact
Higher tier penalties
or 2% of total annual worldwide turnover
Plus potential personal liability for management
Lower tier penalties
or 1.4% of total annual worldwide turnover
Whichever is higher applies
Our platform helps you assess your supply chain security and identify vendors that could expose you to NIS2 compliance risks.
Assess your cybersecurity posture and supply chain risks before the deadline.