NIS2 Network and Information Security Directive 2
EU cybersecurity directive that expanded scope to thousands of "essential" and "important" entities. Required member-state transposition by 2024; non-compliance penalties up to €10M or 2% of revenue.
NIS2 replaced the original Network and Information Security Directive and widened its scope dramatically, from a small set of operators of essential services to entire sectors. It splits organizations into essential and important entities across areas including energy, transport, banking, health, water, digital infrastructure, public administration, postal services, waste, food, manufacturing and ICT service management. The practical effect is that many mid-sized companies that were out of scope before are now in it.
Reporting runs to a fixed clock. A significant incident requires an early warning to the national authority within 24 hours of becoming aware of it, a fuller incident notification within 72 hours, and a final report within one month. Meeting a 24-hour deadline is an operational capability rather than a policy one: it assumes somebody was watching, recognized the incident and could describe it, which is difficult without round-the-clock monitoring.
The directive also puts management bodies on the hook. Senior managers are expected to approve and oversee cybersecurity risk measures and can be held personally liable for failures, and they are required to undergo training. Penalties reach up to 10 million euro or 2 percent of total worldwide annual turnover, whichever is higher, for essential entities.
Common questions
Who does NIS2 apply to?
It applies to essential and important entities operating in the sectors named in the directive, generally at medium size and above, plus certain entities designated regardless of size, such as some digital infrastructure and public administration bodies. It also reaches organizations outside the EU that provide in-scope services within it.
What are the NIS2 reporting deadlines?
An early warning goes to the relevant national authority within 24 hours of becoming aware of a significant incident, a more detailed notification within 72 hours, and a final report within one month. The first deadline is the demanding one, because it starts from awareness and therefore depends on detecting the incident promptly in the first place.
What are the penalties under NIS2?
For essential entities, administrative fines reach up to 10 million euro or 2 percent of total worldwide annual turnover, whichever is higher. For important entities the ceiling is 7 million euro or 1.4 percent. Beyond fines, the directive provides for management liability, and senior managers can be held personally responsible for failing to oversee risk measures.
NIS2 is one signal.
We watch the rest.
Vijilan runs a 24/7 SOC across endpoint, identity, cloud, network, SaaS and mobile, and acts on what it finds rather than forwarding an alert.