The NIS2 Directive represents a significant evolution compared to the NIS1 Directive, aiming to overcome its limitations and adapt to the ever-evolving cybersecurity landscape. If you want to understand whether your organization falls within the scope and what to do concretely, the starting point is to verify the obligations provided by the NIS2 Directive compliance path.
Here is a detailed analysis of the main differences:
Expanded Scope and Size-Based Thresholds
- NIS1: Focused on seven critical sectors: energy, transport, banking, financial market infrastructures, drinking water, health, and digital infrastructure. Only entities designated as “operators of essential services” (OES) within these sectors fell under the scope of the directive.
- NIS2: Significantly expands the scope by including additional sectors crucial for the economy and society, based on their level of digitalization and interconnection. These include:
- Sectors of high criticality: energy (expanded to include district heating and cooling, oil, gas, and hydrogen), transport (covering air, rail, water, and road), banking, financial market infrastructures, health (including pharmaceutical production, including vaccines), drinking water, wastewater, digital infrastructure (expanded to include internet exchange points, DNS service providers, TLD name registries, cloud computing providers, data center providers, content delivery networks, trust service providers, providers of public electronic communications networks, and publicly available electronic communications services), ICT service management (including managed service providers and managed security service providers), public administration, and space.
- Other critical sectors: postal and courier services, waste management, chemicals, food, manufacturing of medical devices, computers, electronics, machinery, motor vehicles, trailers and other transport equipment, digital providers (including online marketplaces, online search engines, and social networking platforms), and research organizations.
- Size-Based Thresholds: NIS2 introduces a size-based rule, automatically including all medium and large companies in the selected sectors. It also grants Member States the flexibility to designate smaller entities with high-risk profiles that should fall under the directive’s obligations. This represents a departure from the more targeted approach of NIS1, which relied on Member States to identify specific entities.
Classification of Entities: From OES and DSP to Essential and Important
- NIS1: Distinguished between “operators of essential services” (OES) and “digital service providers” (DSP), applying different regulatory requirements to each category.
- NIS2: Eliminates this distinction, instead classifying entities as “essential” or “important” based on their importance. This simplified classification aims to provide greater clarity and consistency across sectors.
Enhanced and Streamlined Security Requirements
- NIS1: Required OES to perform cybersecurity risk assessments and implement appropriate security measures, but provided less specific guidance on their implementation.
- NIS2: Strengthens and streamlines security requirements by imposing a more explicit approach to risk management. It introduces a list of ten key security elements that all covered entities must address in their cybersecurity risk management policies. These include requirements for:
- Risk Analysis and Security Policies: Conducting regular risk assessments, developing and updating security policies, and aligning them with recognized standards and best practices.
- Incident Management: Establishing clear procedures for reporting, communication, escalation, and incident response, ensuring a rapid and coordinated approach to minimize damage and downtime.
- Business Continuity and Crisis Management: Implementing measures to ensure operational resilience, such as backup and disaster recovery processes, and developing plans for crisis management, including communication strategies.
- Supply Chain Security: Assessing and mitigating risks associated with suppliers and service providers, taking into account their security practices and overall cybersecurity posture.
- Security in Network and Information System Acquisition, Development, and Maintenance: Integrating security considerations into the entire lifecycle of ICT systems, from procurement and development to deployment, maintenance, and decommissioning.
- Policies and Procedures to Assess the Effectiveness of Cybersecurity Risk Management Measures: Establishing mechanisms to regularly assess the effectiveness of implemented security controls through audits, penetration testing, and other forms of security assessment.
- Policies on the Use of Cryptography and Encryption: Protecting sensitive data both in transit and at rest by implementing appropriate cryptographic controls, including encryption, secure communication protocols, and digital signatures.
- Human Resources Security: Implementing security measures related to human resources, including background checks for employees in critical roles, security awareness training, and access control measures.
- Use of Multi-Factor Authentication or Continuous Authentication: Enhancing access security by implementing robust authentication mechanisms that go beyond simple passwords, such as multi-factor authentication or continuous authentication methods.
- Policies and Procedures to Ensure the Physical Security of Network and Information Systems: Addressing physical security risks to critical infrastructure and systems, including measures to control access to server rooms, data centers, and other sensitive locations.
More Detailed Incident Reporting Procedures
- NIS1: Required the reporting of “serious incidents” but with less detailed guidance on the timing and content of the report.
- NIS2: Introduces a more precise incident reporting process with clear timelines and specific content requirements. This includes a multi-stage approach:
- Early Warning: Within 24 hours of becoming aware of a significant incident, entities must send an early warning to their CSIRT or competent national authority, allowing for early intervention and potential mitigation.
- Incident Notification: This initial notification must be followed by a more comprehensive notification within 72 hours, providing further details on the impact of the incident and the response actions taken.
- Final Report: A final report is required no later than one month after the initial notification, offering a detailed analysis of the incident, its root cause, and lessons learned to prevent similar incidents in the future.
Stronger Harmonized Supervision, Enforcement, and Sanctions
- NIS1: Relied heavily on Member States for supervision and enforcement, leading to inconsistent application of sanctions across the EU.
- NIS2: Strengthens supervisory measures, imposes stricter enforcement, and seeks to harmonize sanctioning regimes across all Member States.
- Enhanced Supervisory Powers: Provides national authorities with a minimum list of supervisory tools, including regular and targeted audits, on-site inspections, requests for information, and access to documentation.
- Differentiated Supervisory Regimes: Establishes distinct supervisory approaches for “essential” and “important” entities, tailoring supervision to their risk profiles and potential impact.
- Harmonized Sanctioning Framework: Introduces a minimum list of administrative sanctions for violations of the directive’s requirements, including binding instructions, mandatory security audits, and administrative fines.
- Significant Administrative Fines: For “essential” entities, NIS2 provides for administrative fines of up to 10 million euros or 2% of the total global annual turnover, whichever is higher. For “important” entities, the maximum fine is at least 7 million euros or 1.4% of the total global annual turnover.
- Senior Management Responsibility: Introduces provisions to hold individuals in senior management positions liable for violations of the directive, promoting a culture of accountability at the highest levels of organizations.
Improved Cyber Crisis Management and EU-Level Cooperation
- NIS1: Lacked specific provisions for coordinated cyber crisis management at the EU level.
- NIS2: Strengthens cooperation at the EU level and introduces mechanisms to improve the prevention, management, and response to cyber crises:
- National Cyber Crisis Management Authorities: Obliges each Member State to designate a national authority responsible for cyber crisis management, ensuring clear lines of responsibility and coordination.
- National Cyber Crisis Response Plans: Requires Member States to develop comprehensive national plans to respond to large-scale cybersecurity incidents and crises, outlining roles, responsibilities, communication protocols, and escalation procedures.
- EU-CyCLONe: Establishes the European Cyber Crises Liaison Organisation Network (EU-CyCLONe) to provide operational support for the coordinated management of large-scale cybersecurity incidents and crises among Member States.
Addressing Cybersecurity in Supply Chains
- NIS1: Did not specifically address cybersecurity risks in supply chains.
- NIS2: Includes requirements for entities to address cybersecurity risks within their supply chains and supplier relationships. This includes conducting risk assessments of critical suppliers, implementing security controls in procurement processes, and promoting information sharing and cooperation on cybersecurity issues throughout the supply chain.
Enhanced Role of the Cooperation Group and Information Sharing
- NIS1: Established the Cooperation Group to facilitate strategic cooperation and information exchange among Member States.
- NIS2: Strengthens the role of the Cooperation Group in shaping strategic cybersecurity policy decisions and promotes more systematic information sharing and cooperation among Member State authorities. This includes sharing information on threats, vulnerabilities, incidents, best practices, and regulatory approaches.
Coordinated Vulnerability Disclosure and EU Vulnerability Database
- NIS1: Did not include provisions for coordinated vulnerability disclosure.
- NIS2: Establishes a framework for coordinated vulnerability disclosure, outlining procedures for reporting vulnerabilities to vendors and coordinating responsible disclosure practices. It also mandates the creation of an EU vulnerability database, maintained by ENISA, to track publicly known vulnerabilities in ICT products and services.
In summary, the NIS2 Directive builds on the foundations laid by NIS1, expanding its scope, strengthening its requirements, and introducing new cooperation and enforcement mechanisms to address the evolving cybersecurity challenges facing the EU. To delve deeper into the full regulatory framework, you can consult the official document of the NIS2 Directive, or read what the main objective of the NIS2 Directive is. If your organization is already registered in the ACN list, you can also find operational guidance on what NIS2 compliance entails within the ACN deadlines.
Frequently Asked Questions about the NIS2 Directive
- Does my company fall within the NIS2 scope even if it was not subject to NIS1?
- It is possible. NIS2 significantly expands the scope compared to NIS1, including new sectors and applying automatic size-based thresholds: all medium and large enterprises in the covered sectors fall under the obligations, regardless of an explicit designation as happened with NIS1. It is therefore necessary to verify your sector and company size.
- What are the penalties for those who do not comply with NIS2?
- For entities classified as “essential,” administrative fines can reach up to 10 million euros or 2% of the total global annual turnover (the higher value applies). For “important” entities, the maximum is 7 million euros or 1.4% of the global turnover. NIS2 also introduces personal liability for senior management.
- By when must organizations comply with NIS2 in Italy?
- The Italian transposition of the NIS2 Directive took place with Legislative Decree 138/2024. The operational deadlines for registration and compliance are managed by ACN (National Cybersecurity Agency), which has defined the time windows for registration in the list of NIS subjects and the subsequent compliance obligations.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
