The NIS2 Directive was developed to strengthen cybersecurity in the European Union, addressing several gaps identified in the original NIS Directive.
Here are the key elements of NIS2 and how they address those shortcomings:
- Expansion of Scope:
- Broader Coverage of Sectors and Entities: NIS2 extends its reach by including more sectors deemed crucial for the economy and society. While NIS1 focused on seven critical sectors, NIS2 includes additional sectors to address the “insufficient level of cyber resilience of businesses operating in the EU” observed previously.
- Size-Based Threshold: The directive introduces a size-threshold rule, requiring all medium and large companies in the selected sectors to comply with its requirements. This ensures that entities with a significant digital footprint and potential impact are held accountable for their cybersecurity posture.
- Elimination of the Distinction between OES and DSP: NIS2 removes the distinction between Operators of Essential Services (OES) and Digital Service Providers (DSP), instead classifying entities as “essential” or “important,” with varying levels of supervision. This simplifies categorization and promotes a more consistent approach to oversight.
- Strengthened Security Requirements:
- Risk Management Approach: NIS2 introduces a risk-management-based approach and mandates a minimum list of fundamental security elements that all covered companies must address.
- Standardization of Security Measures: This includes incident handling, supply chain security, vulnerability management and disclosure, and the use of cryptography. By establishing a common baseline of cybersecurity measures, NIS2 aims to correct inconsistencies in the implementation of security requirements under NIS1.
- Improved Incident Reporting:
- Multi-Stage Reporting Approach:
- Early Warning: Companies have 24 hours to submit an initial report to the competent authorities after becoming aware of an incident. This early warning system allows for faster response times.
- Incident Notification: Within 72 hours, a more detailed incident notification must be submitted.
- Final Report: A comprehensive final report is required within one month of the incident.
- Balancing Speed and Completeness: This structured approach aims to balance the need for rapid information sharing with the importance of in-depth analysis and learning from incidents.
- Stricter Supervision and Enforcement:
- Enhanced Supervisory Measures: NIS2 provides a minimum list of supervisory tools for national authorities, including audits, on-site inspections, requests for information, and access to documentation.
- Differentiated Supervision: It implements different levels of supervision for “essential” and “important” entities, ensuring a more targeted and proportionate approach.
- Harmonized Sanctions: It establishes a framework for consistent sanctions across the EU for violations of the directive, including a minimum list of administrative sanctions that take into account the size of the entity and the severity of the infringement.
- Enhanced Cooperation:
- Strengthened Role of the NIS Cooperation Group: NIS2 strengthens the role of the NIS Cooperation Group in facilitating strategic decision-making, information exchange, and coordination among Member States regarding cybersecurity.
- Improvement of the CSIRT Network: It aims to improve operational cooperation within the CSIRT network, promoting rapid information exchange and coordinated responses to cybersecurity incidents, especially those with cross-border implications. To learn more about the specific obligations related to CSIRT, it is also useful to read the obligation to designate a CSIRT contact person for NIS entities.
- Establishment of EU-CyCLONe: The creation of EU-CyCLONe, a European cyber crisis liaison organization network, is a significant addition in NIS2, specifically designed to improve the EU’s preparedness and response to large-scale cybersecurity incidents and crises.
The NIS2 Directive represents a significant step forward in the EU’s cybersecurity strategy. By addressing the shortcomings of NIS1 and adapting to the evolving threat landscape, NIS2 aims to create a more secure and resilient digital environment for businesses and citizens across the European Union. If your organization falls within the scope of the directive, assessing your level of compliance is the first concrete step: the ISGroup NIS2 compliance path guides companies from gap analysis to the implementation of the required measures. To understand where your organization stands regarding ACN deadlines, you can also consult the list of NIS2 entities and ACN guidance on March 31st.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
