The NIS2 Directive significantly expands the scope and rigor of European cybersecurity regulation compared to its 2016 predecessor. It establishes a higher baseline of security measures and reporting obligations across a vast range of critical sectors.

Expanded Sectoral Scope

NIS2 moves away from the complex identification process of NIS1, applying automatically to medium and large enterprises in defined sectors:

  • Highly Critical Sectors: Energy, Transport, Banking, Financial Market Infrastructures, Health, Drinking Water, Waste Water, Digital Infrastructure (Cloud, DNS, Data Centers), ICT Service Management, Public Administration, Space.
  • Other Critical Sectors: Postal/Courier services, Waste management, Chemicals, Food (production/processing), Manufacturing (medical devices, computer/electronic, machinery, motor vehicles), Digital Providers (Marketplaces, Search Engines).

Minimum Security Measures

Entities must adopt a risk-management approach, implementing basic cyber hygiene practices as a legal requirement, including:

  • Risk analysis and information system security policies.
  • Incident handling.
  • Business continuity (backup management, disaster recovery).
  • Supply chain security (assessing vulnerabilities specific to each direct supplier).
  • Cryptography and encryption use.
  • Multi-factor authentication (MFA) and secured communications.

Strict Reporting Deadlines

NIS2 imposes a tiered reporting structure for significant incidents:

  1. Early Warning: Within 24 hours of becoming aware of the incident, indicating whether it involves unlawful acts or cross-border impact.
  2. Incident Notification: Within 72 hours, providing an initial assessment of severity and indicators of compromise.
  3. Final Report: Within one month after the incident notification, detailing the root cause, mitigation applied, and cross-border impact.

Personal Liability for Management

A crucial shift in NIS2 is holding C-level executives personally accountable. Management bodies must approve cybersecurity measures and oversee their implementation. Member States are required to ensure that management can be held personally liable for non-compliance and can be temporarily suspended from managerial duties following severe breaches.

Fines and Penalties

Fines align closely with GDPR standards:

  • Essential Entities: Up to €10 million or 2% of total worldwide annual turnover.
  • Important Entities: Up to €7 million or 1.4% of total worldwide annual turnover.