The NIS2 Directive is set to significantly influence the future of cybersecurity in the EU. Here is how it will address the main shortcomings of the previous NIS Directive, as well as introduce a series of new measures to strengthen cyber resilience. For a direct reference, the official document of the NIS2 Directive is also available.
The impact of the NIS2 Directive
- Broader scope and higher standards: The NIS2 Directive extends the scope of application of cybersecurity regulations, including a greater number of sectors and entities. Furthermore, it eliminates the distinction between operators of essential services and digital service providers. This means that more organizations will be subject to cybersecurity requirements, leading to a higher overall level of cybersecurity across the EU. The directive also introduces stricter security requirements, adopting a risk management approach with a minimum list of basic security elements that all affected entities must implement. This will help to harmonize cybersecurity practices in the EU and ensure that organizations adopt a more proactive approach to managing cyber risks.
- Harmonized incident reporting: The NIS2 Directive introduces a more detailed and harmonized incident reporting process, with clear timelines and requirements for the content of reports. This will help to improve the speed and effectiveness of incident response. National authorities will need to adopt a clearer view of the cyber threat landscape.
- Supply chain security: Recognizing the growing importance of supply chain security, the NIS2 Directive includes specific provisions to address cyber risks in supply chains and supplier relationships. This includes requirements for individual companies to manage cybersecurity risks in their supply chains and for Member States to conduct coordinated risk assessments of critical supply chains at the EU level. These measures will help to mitigate the risk of supply chain cyberattacks that could compromise critical services.
- Stricter supervision and enforcement: The NIS2 Directive introduces stricter supervisory measures for national authorities. These include a minimum list of supervisory tools and a differentiation between supervisory regimes for essential and important entities. This will ensure that national authorities have the necessary tools to oversee and effectively enforce the directive. The directive also establishes a minimum list of administrative sanctions for breaches of cybersecurity obligations. This includes fines that can reach up to 10 million euros or 2% of the total annual global turnover for essential entities. These stricter enforcement measures aim to deter organizations and encourage them to take cybersecurity seriously.
- Improved cooperation and information sharing: The NIS2 Directive places a strong emphasis on cooperation and information sharing between Member States and EU institutions. This includes mechanisms for sharing information on cyber threats, vulnerabilities, and incidents, as well as joint supervisory actions and peer reviews. The directive also establishes EU-CyCLONe, a network of national cyber crisis management liaison organizations that will support the coordinated management of large-scale cyber incidents and crises. These measures will help to improve the EU’s collective cybersecurity posture and make it more difficult for attackers to exploit vulnerabilities across borders.
The challenges of the Directive
Although the NIS2 Directive represents a significant step forward for cybersecurity in the EU, some challenges remain related to its implementation and enforcement. Previous sources and discussions highlight several critical issues, including:
- Determining equivalence between the NIS2 Directive and specific EU sectoral regulations.
- Identifying all entities that fall within the scope of the directive.
- Ensuring that entities have the resources and skills necessary to implement robust cybersecurity measures.
- Overcoming reluctance in applying sanctions for security breaches.
- Ensuring consistent application of the directive across Member States.
- Establishing effective mechanisms for cooperation and information sharing.
- Keeping pace with an ever-evolving threat landscape.
Addressing these challenges will be essential to ensure that the NIS2 Directive achieves its ambitious goals and helps create a safer and more resilient digital environment for EU citizens and businesses. For organizations that have yet to start or consolidate their compliance journey, structured NIS2 compliance support can make the difference between a fragmented process and a truly effective implementation plan. It is also useful to check who is included in the ACN list of NIS2 entities and the operational deadlines to understand if and when your organization is involved.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
