DirectiveEuropean Union

NIS2

Directive (EU) 2022/2555 (the NIS 2 Directive) lays down measures for a high common level of cybersecurity across the Union. It repeals and replaces Directive (EU) 2016/1148, extends the scope of sectors covered, and establishes cybersecurity risk-management measures and incident reporting obligations for essential and important entities, along with a coordinated regulatory and supervisory framework among Member States.

Who it applies to

Essential entities and important entities operating in the sectors and providing the services covered by the Directive's annexes (including energy, transport, digital infrastructure, drinking water and waste water, health, and certain public administration and space-related activities), determined by a size-cap rule covering medium-sized and larger enterprises, plus certain small enterprises and microenterprises that fulfil specific criteria indicating a key role for society, the economy or particular sectors or types of service.

Read the official text