The NIS2 Directive represents a significant evolution compared to the NIS1 Directive. If you want to understand what the main objective of the NIS2 Directive is, it is useful to start with the structural differences compared to the previous framework.
Here is an analysis of the main differences:
Expanded scope and size thresholds
- The NIS2 Directive significantly expands the number of sectors and entities subject to its cybersecurity regulations. While NIS1 focused on seven critical sectors, NIS2 extends coverage to eleven sectors considered “highly critical” and adds another seven “critical sectors”. This expansion reflects the increasing digitalization and interconnection of various sectors and their impact on the EU economy and society.
- Furthermore, NIS2 introduces a size threshold, mandating that all medium and large companies in the designated sectors must comply with its regulations. This change ensures a more comprehensive approach to cybersecurity, recognizing that threats can emerge from entities of any size. However, Member States retain the flexibility to identify and include smaller entities with potentially high-risk profiles as well.
Classification of entities and supervisory regimes
- NIS2 abandons the previous distinction between “operators of essential services” and “digital service providers.” Instead, it implements a more streamlined classification system based on the importance of the entity: “essential entities” and “important entities.” This categorization allows for more targeted and appropriate supervisory regimes, aligning regulatory oversight with the potential impact of cybersecurity incidents.
Strengthened and simplified security and reporting requirements
- NIS2 promotes greater consistency and rigor in security measures and incident reporting across Member States, addressing a significant limitation of the NIS1 Directive. The Directive imposes a risk management approach that defines a minimum baseline of fundamental security elements that all companies must adopt. These include incident handling, supply chain security, vulnerability management and disclosure, and the use of cryptography (and encryption, where applicable). For organizations needing to structure or verify their compliance journey, NIS2 compliance support can help identify gaps regarding minimum requirements and plan necessary interventions.
- The Directive introduces a multi-stage approach to incident reporting, striking a balance between timely reporting and in-depth analysis. Companies now have 24 hours to submit an initial “early warning” to the CSIRT (Computer Security Incident Response Team) or the competent national authority once an incident is detected. A detailed notification must follow within 72 hours, culminating in a final report submitted within one month of the incident.
Strengthening enforcement and the sanctioning regime
- Recognizing the inconsistent application of sanctions under NIS1, NIS2 establishes a more robust and harmonized framework for sanctions across all Member States. It introduces a minimum list of administrative sanctions for non-compliance with risk management and reporting obligations, including:
- Binding instructions
- Mandatory implementation of security audit recommendations
- Orders to bring security measures into compliance with NIS2 requirements
- Administrative fines
Strengthening cooperation and information sharing
- NIS2 strengthens strategic and operational cooperation between Member States, recognizing the increased interconnection of cyber threats and the need for a coordinated response. It expands the role of the Cooperation Group, facilitating more robust strategic policy decisions and information exchange between national cybersecurity authorities.
- It strengthens the CSIRT network, improving operational cooperation between national CSIRTs to ensure rapid and effective responses to cross-border incidents. Furthermore, NIS2 establishes EU-CyCLONe (European Cyber Crisis Liaison Organisation Network), which plays a crucial role in coordinating the management of large-scale cybersecurity incidents and crises across the EU.
Focus on supply chain security
- NIS2 addresses a crucial aspect of cybersecurity often overlooked in previous regulations: supply chain security. It mandates that individual companies address cyber risks within their supply chains and supplier relationships. Furthermore, it allows Member States, in collaboration with the Commission and ENISA, to conduct coordinated security risk assessments of critical supply chains at the EU level, based on the model used for 5G network cybersecurity.
Coordinated vulnerability disclosure and EU vulnerability database
- To promote a more proactive approach to cybersecurity, NIS2 establishes a framework for coordinated vulnerability disclosure, involving key stakeholders across the EU. This framework allows for the responsible reporting and management of newly discovered vulnerabilities in ICT products and services. Additionally, NIS2 provides for the creation of an EU vulnerability database managed by ENISA, centralizing information on publicly known vulnerabilities to improve overall cybersecurity awareness and preparedness.
Frequently Asked Questions
- How do I know if my company falls under the NIS2 scope?
- The scope depends on the sector of activity and the size of the organization. NIS2 generally applies to medium and large enterprises in the “highly critical” and “critical” sectors listed by the Directive. In Italy, the ACN manages the registration and notification process: you can consult the ACN guidelines on the NIS2 list and compliance deadlines to verify the criteria applicable to your organization.
- What is the practical difference between an “essential entity” and an “important entity”?
- The distinction is not just a label: essential entities are subject to stricter ex-ante oversight, while important entities are primarily monitored ex-post. The maximum applicable sanctions differ between the two categories. The full text of the Directive can be found in the official NIS2 Directive document.
- What happens if a company does not report an incident within the required timeframes?
- Failure to report within the established deadlines (early warning within 24 hours, detailed notification within 72 hours) exposes the organization to the administrative sanctions provided for by NIS2, which include binding instructions, compliance orders, and, in the most serious cases, significant financial penalties. Adherence to reporting timelines is one of the obligations verified by competent authorities.
Protect your organisation with NIS2 compliance.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
