---
title: "NIS 2 Directive (Directive (EU) 2022/2555)"
canonical: "https://kb.cynergy.app/space/WC/1209892876/NIS%202%20Directive%20(Directive%20(EU)%202022%2F2555)"
format: markdown
---
The **NIS2 Directive** (Network and Information Security 2) is an updated cybersecurity directive by the European Union, enhancing and expanding the 2016 NIS Directive. It aims to strengthen cybersecurity resilience and incident response across critical infrastructure sectors, applying a broader set of requirements to more organizations. It was adopted in 2022, and EU member states are expected to enforce it by October 2024.

Here's a closer look at what NIS2 involves and how organizations can prepare for compliance.

### Key Aspects of the NIS2 Directive

1. **Expanded Scope**: NIS2 covers a wider range of sectors beyond essential services, now including entities in **energy, transport, banking, health**, and **digital infrastructure**, as well as public administration and space. This broader scope means that more organizations will need to comply with the directive’s security standards.
2. **Harmonized Security Standards**: Member states are required to establish similar standards for incident handling and risk management to ensure a unified cybersecurity posture across the EU.
3. **Enhanced Incident Reporting**: Organizations must notify the authorities of cyber incidents within **24 hours** of detection, followed by a more comprehensive report within **72 hours**. This will allow for quicker response and collaboration across the EU.
4. **Increased Accountability**: Organizations are now required to appoint responsible individuals or teams to ensure NIS2 compliance. Boards and executive management are held accountable for non-compliance, meaning the leadership team must prioritize cybersecurity measures.
5. **Supply Chain Security**: There’s an increased focus on managing third-party risk, ensuring that the entire supply chain meets NIS2 standards, particularly for critical infrastructure.
6. **Penalties and Fines**: Non-compliance with NIS2 can lead to significant fines, up to **2% of an organization’s annual global turnover**. Additionally, reputational damage and operational disruptions can result.

### Steps for Organizations to Prepare for NIS2 Compliance

1. **Assess Organizational Exposure and Scope**:
  - Determine if your organization falls under NIS2’s scope.
  - Identify all critical functions and services covered by the directive and map any dependencies on third-party services or suppliers.
2. **Conduct a Risk Assessment**:
  - Evaluate current cybersecurity policies and procedures to identify gaps.
  - Focus on critical systems and services, as well as the impact of any potential threats to your operations.
3. **Implement or Enhance Security Measures**:
  - **Access Control and Authentication**: Enforce strict access controls, multi-factor authentication (MFA), and least privilege policies.
  - **Network Security**: Use firewalls, intrusion detection, and network segmentation to protect critical assets.
  - **Incident Detection and Response**: Strengthen your incident response program, ensuring monitoring and alerting for potential threats.
4. **Establish Incident Reporting Procedures**:
  - Set up a clear protocol for incident detection, logging, and escalation to meet the 24-hour and 72-hour reporting requirements.
  - Train teams to understand their responsibilities in reporting incidents to the appropriate regulatory bodies.
5. **Enhance Cyber Resilience and Business Continuity**:
  - Develop a robust business continuity and disaster recovery plan that covers both physical and cyber incidents.
  - Regularly conduct cyber exercises and penetration testing to validate your resilience and response strategies.
6. **Third-Party Risk Management**:
  - Ensure that suppliers and third-party vendors are aware of their responsibilities under NIS2.
  - Request cybersecurity compliance documentation and assess their adherence to the directive’s standards.
7. **Executive Oversight and Accountability**:
  - Establish a governance framework where top-level management is responsible for overseeing cybersecurity compliance.
  - Appoint a NIS2 compliance officer or similar role to ensure ongoing adherence to the directive.
8. **Document and Maintain Compliance Evidence**:
  - Keep detailed records of security measures, risk assessments, and incident response activities.
  - Prepare for potential audits by regulatory bodies.

### NIS2 and Beyond: Continuous Improvement

Compliance is not a one-time effort. Regularly assess and update cybersecurity policies and procedures to keep pace with evolving threats and regulatory changes. Organizations that embrace a proactive, security-focused culture will be better positioned to meet the requirements of NIS2 while minimizing the risk of incidents and penalties.