The NIS2 Directive significantly expands the scope and rigor of European cybersecurity regulation compared to its 2016 predecessor. It establishes a higher baseline of security measures and reporting obligations across a vast range of critical sectors.
Expanded Sectoral Scope
NIS2 moves away from the complex identification process of NIS1, applying automatically to medium and large enterprises in defined sectors:
- Highly Critical Sectors: Energy, Transport, Banking, Financial Market Infrastructures, Health, Drinking Water, Waste Water, Digital Infrastructure (Cloud, DNS, Data Centers), ICT Service Management, Public Administration, Space.
- Other Critical Sectors: Postal/Courier services, Waste management, Chemicals, Food (production/processing), Manufacturing (medical devices, computer/electronic, machinery, motor vehicles), Digital Providers (Marketplaces, Search Engines).
Minimum Security Measures
Entities must adopt a risk-management approach, implementing basic cyber hygiene practices as a legal requirement, including:
- Risk analysis and information system security policies.
- Incident handling.
- Business continuity (backup management, disaster recovery).
- Supply chain security (assessing vulnerabilities specific to each direct supplier).
- Cryptography and encryption use.
- Multi-factor authentication (MFA) and secured communications.
Strict Reporting Deadlines
NIS2 imposes a tiered reporting structure for significant incidents:
- Early Warning: Within 24 hours of becoming aware of the incident, indicating whether it involves unlawful acts or cross-border impact.
- Incident Notification: Within 72 hours, providing an initial assessment of severity and indicators of compromise.
- Final Report: Within one month after the incident notification, detailing the root cause, mitigation applied, and cross-border impact.
Personal Liability for Management
A crucial shift in NIS2 is holding C-level executives personally accountable. Management bodies must approve cybersecurity measures and oversee their implementation. Member States are required to ensure that management can be held personally liable for non-compliance and can be temporarily suspended from managerial duties following severe breaches.
Fines and Penalties
Fines align closely with GDPR standards:
- Essential Entities: Up to €10 million or 2% of total worldwide annual turnover.
- Important Entities: Up to €7 million or 1.4% of total worldwide annual turnover.