EU directive strengthening cybersecurity requirements for essential and important entities across Europe.
NIS2 (Network and Information Security Directive 2) is an EU directive expanding cybersecurity requirements across essential and important sectors—energy, transport, health, digital infrastructure, and more. NIS2 requires risk management measures, incident reporting (within 24 hours for significant incidents), supply chain security, and management accountability. Member states must transpose NIS2 into national law. Penalties for non-compliance can reach €10 million or 2% of global turnover.
Why It Matters
The DSC Perspective:
NIS2 significantly expands who must comply with EU cybersecurity regulations. If you operate in the EU or provide services to EU entities in covered sectors, assess your NIS2 obligations. The directive emphasises supply chain security, affecting suppliers too.
