Overview of the NIS 2 Directive

Direttiva NIS2 Frequently Asked Questions

The NIS 2 Directive establishes measures for a high common level of cybersecurity across the European Union. This directive aims to improve the functioning of the internal market by raising cybersecurity standards. If you want to understand what the main objective of the NIS2 Directive is, you can find an in-depth analysis in our knowledge base.

🔴 NIS2 compliance: identify hidden risks and strengthen your security with a focused assessment by ISGroup specialists.

Scope of the Directive

The NIS 2 Directive applies to a wide range of entities, categorized as essential or important. These include, but are not limited to:

  • Essential Entities: Specified in Annex I, they operate in sectors crucial for the economy and society. They exceed the threshold for medium-sized enterprises. Examples include:
  • Electricity suppliers
  • Water suppliers
  • Hospitals
  • Digital service providers such as online marketplaces and search engines.
  • Important Entities: Outlined in Annexes I and II, they operate in sectors considered less critical than essential entities. It is important to note that this category includes entities identified as critical under Directive (EU) 2022/2557. Examples include:
  • Postal and courier services
  • Food processing and distribution companies
  • Research organizations

The scope of the directive extends to entities that provide domain name registration services, regardless of their size. Furthermore, Member States have the discretion to apply the NIS 2 Directive to:

  • Public administration entities at the local level
  • Educational institutions, particularly those engaged in critical research activities.

Main Provisions of the NIS 2 Directive

  • National Cybersecurity Strategies: Member States are required to develop national cybersecurity strategies. These strategies outline the priorities and objectives for improving cybersecurity within the Member State and the governance framework to achieve those objectives.
  • Incident Reporting: Both essential and important entities are obligated to report significant cybersecurity incidents to their designated CSIRT (Computer Security Incident Response Team) or competent authority. The directive details a multi-stage approach for incident reporting:
  • Early Warning: Entities must provide an early warning, typically within 24 hours of becoming aware of a significant incident.
  • Incident Notification: A more detailed incident notification, including an initial assessment, is required typically within 72 hours.
  • Final Report: A final report including a detailed analysis and mitigation measures must be submitted within one month of the incident notification.
  • Risk Management Measures: Essential and important entities are obligated to implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. For organizations that need to structure or verify their compliance path, ISGroup’s NIS2 compliance support accompanies the gap analysis and the implementation of the required measures. These measures include, but are not limited to:
  • Risk analysis and information system security policies
  • Incident management
  • Business continuity and crisis management
  • Supply chain security
  • Human resources security
  • Supervisory Measures: The NIS 2 Directive grants competent authorities the power to supervise essential and important entities to ensure compliance. For essential entities, these supervisory measures include:
  • On-site inspections
  • Security audits
  • Issuance of binding instructions
  • Enforcement Measures: In case of non-compliance, the NIS 2 Directive provides for a range of enforcement measures, including:
  • Administrative fines
  • Public reprimands
  • Temporary suspension of activities or withdrawal of rights

Relationship with Sector-Specific Laws

The NIS 2 Directive recognizes that specific EU sector-specific laws may impose cybersecurity obligations. If these obligations have an effect at least equivalent to those provided for by the NIS 2 Directive, the corresponding provisions of the directive, including those related to supervision and enforcement, do not apply to those entities.

For example:

The NIS 2 Directive does not apply to financial entities under the scope of Regulation (EU) 2022/2554. This is because that regulation has equivalent, if not more comprehensive, provisions for digital operational resilience in the financial sector. However, Member States are still required to include financial entities when considering large-scale cybersecurity incidents and developing national response plans.

For organizations that fall within the NIS2 perimeter and still need to verify their position regarding the list of NIS2 subjects managed by ACN, it is useful to also consult the operational guidelines on the designation of the CSIRT contact person, one of the requirements mandated by the directive.

Protect your organisation with NIS2 compliance.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert

In