What Is NIS2?
NIS2 is the European Union's updated Network and Information Security Directive, designed to strengthen cybersecurity and resilience across critical and important sectors within member states. It expands on the original NIS Directive by widening the range of organizations it covers and raising expectations for governance, incident reporting, and risk management.
NIS2 applies to a much broader set of organizations than its predecessor, including many medium and large companies across sectors such as energy, transport, healthcare, digital infrastructure, and manufacturing. Organizations in scope are expected to implement risk management measures, report significant incidents within strict timeframes, and demonstrate that leadership is actively engaged in cybersecurity oversight.
One of the more notable aspects of NIS2 is its emphasis on staff awareness and training as part of an organization's risk management obligations. Technical controls alone are not considered sufficient; organizations need to show that employees understand their role in maintaining security, particularly around recognizing and reporting threats like phishing.
Non-compliance with NIS2 can result in significant penalties, similar in structure to GDPR enforcement. For organizations in scope, NIS2 represents a meaningful shift from cybersecurity as a technical function toward cybersecurity as an organization-wide governance responsibility.