What are the key elements of the NIS2 Directive?

Direttiva NIS2 Frequently Asked Questions

The NIS2 Directive aims to strengthen the European Union’s cybersecurity posture by addressing the limitations of previous legislation and adapting to the evolving threat landscape. It expands the scope of cybersecurity regulations, imposes stricter security and reporting requirements, and strengthens supervision and enforcement mechanisms.

Here are some of the key elements of the NIS2 Directive:

1. Expanded Scope

The directive extends the range of sectors and entities subject to cybersecurity obligations. It introduces a size-based threshold, requiring all medium and large companies in selected sectors to comply with the directive’s provisions. This represents a significant shift from the previous NIS Directive, which focused on specific critical sectors and left it to Member States to identify “essential” entities.

  • The NIS2 Directive identifies two main categories of sectors: “sectors of high criticality” and “other critical sectors,” listed in Annexes I and II of the directive. The inclusion of new sectors, such as space, waste management, and food, reflects the growing interconnection and digitalization of essential services, as well as the expanded potential for cyberattacks to disrupt critical societal functions.
  • Member States retain some discretion in identifying smaller entities with high-risk profiles that should fall under the scope of the NIS2 Directive, allowing for tailored implementation based on national contexts and sector-specific risk assessments.
🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

2. Risk Management Approach

The directive promotes a risk management-based framework rather than a purely compliance-driven approach. Entities falling under the scope of the directive must implement measures that address various aspects of cybersecurity, including:

  • Incident management
  • Supply chain security
  • Vulnerability management and disclosure
  • Use of cryptography and encryption

To understand how these requirements translate into concrete technical controls, it is also useful to consult the cybersecurity standards referenced by the NIS2 Directive.

3. Standardized Security and Reporting Requirements

To ensure greater consistency in implementation and reduce the burden on companies operating in multiple EU Member States, the directive establishes more precise provisions regarding security requirements and incident reporting.

  • Minimum Cybersecurity Measures: The directive outlines a list of ten key elements that all covered entities must address in their cybersecurity risk management policies. This includes measures such as risk analysis, incident response planning, business continuity, and supply chain security.
  • Incident Reporting: Clearer guidance is provided on incident reporting processes, content, and timelines. The directive requires entities to submit an early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident, followed by a more detailed notification within 72 hours and a final report within one month.

4. Strengthened Supervision and Enforcement

The directive introduces stricter supervisory measures for national authorities and establishes tougher enforcement requirements. For organizations looking to assess their level of compliance and prepare for requirements, the NIS2 compliance path offers structured support from gap analysis to the implementation of required controls.

  • Supervisory Measures: Competent authorities have a wider range of tools to supervise both essential and important entities, including regular and targeted audits, on-site and off-site checks, requests for information, and access to relevant documentation.
  • Harmonized Sanctions: To address the previous reluctance among some Member States to impose sanctions for non-compliance, the directive harmonizes the sanctioning regime across the EU. It establishes a minimum list of administrative sanctions, including binding instructions, mandatory security audits, and fines. The directive differentiates between essential and important entities regarding the level of administrative fines for violations.
  • Liability: Accountability for cybersecurity measures is strengthened by introducing provisions on the liability of individuals in senior management roles within essential and important entities.

5. Enhanced Cooperation and Information Sharing

The directive aims to improve cooperation and information sharing between Member States, competent authorities, and entities.

  • Cooperation Group: The role of the existing Cooperation Group, composed of national cybersecurity authorities, is strengthened in shaping strategic policy decisions and coordinating responses to cybersecurity challenges at the EU level.
  • CSIRT Network: The directive improves operational cooperation within the existing CSIRT network, encouraging the rapid and efficient exchange of information and best practices between national CSIRTs to strengthen incident response capabilities.
  • EU-CyCLONe: The directive establishes a European Cyber Crises Liaison Organisation Network (EU-CyCLONe), tasked with supporting the coordinated management of large-scale cybersecurity incidents and crises, ensuring a rapid and unified response at the EU level.

6. Coordinated Vulnerability Disclosure and EU Database

A framework for coordinated vulnerability disclosure is introduced, aimed at creating a more structured and secure approach to managing newly discovered vulnerabilities in ICT products and services. This framework encourages the responsible reporting of vulnerabilities to vendors and promotes collaboration between security researchers, vendors, and authorities to effectively mitigate risks.

The directive also provides for the creation of an EU vulnerability database, maintained by ENISA, which will serve as a central repository for publicly known vulnerabilities in ICT products and services. This database will be a valuable resource for entities to stay informed about potential threats, apply necessary security updates, and improve their overall cybersecurity posture.

In summary, the NIS2 Directive introduces significant changes designed to strengthen the EU’s cybersecurity framework. By expanding its scope, tightening security and reporting requirements, and improving supervision and enforcement mechanisms, the directive aims to create a more cyber-resilient environment for essential services and critical infrastructure across the European Union. The official text of the NIS2 Directive remains the primary regulatory reference for those who need to verify the details of the provisions.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In