Why is NIS 2 coming?

Introducing NIS

NIS: EU’s First Cybersecurity Law

Enacted in 2016, the Network and Information Systems Directive (NIS) marked the European Union’s inaugural cybersecurity legislation. Its foremost aim was to bolster the cyber resilience of EU Member States by designating essential service operators and mandating cybersecurity protocols, notably emphasizing incident reporting as a pivotal obligation.

Why second version is now coming?

Why NIS Was Revised?

Shortly after its inception, it became evident that the Directive’s implementation varied significantly across Member States, resulting in a fragmented system. Certain companies and organizations were deemed essential in some nations but not in others.

To address this, the European Commission opted to revise the NIS Directive, aiming to precisely delineate the covered organizations and their respective requirements. This initiative materialized in 2021 with the introduction of the Network and Information Security Directive (NIS 2).

Get the detailed checklist to become NIS 2 compliant

Get Minumum Cybersecurity measures for NIS 2 Compliance

The new, more comprehensive version

NIS 2: A Better Version of NIS

The NIS 2 directive significantly broadens the scope of the original NIS Directive, extending coverage to a much wider array of organizations, increasing the number of entities affected tenfold.

While NIS initially targeted sectors like water supply, energy, digital infrastructure, banking, financial market infrastructure, health, and transport, NIS 2 now encompasses additional sectors such as public administration, digital providers, space, research, postal services, waste management, food, manufacturing, and chemical products.

Moreover, NIS 2 enhances cybersecurity enforcement requirements by introducing early mandatory incident reporting, expanding risk management provisions, and establishing a clear designation of C-level cybersecurity responsibility.