Skip to content
All terms
Glossary

NIS2

The EU cybersecurity directive that obliges considerably more companies to demonstrable security measures and incident reporting.

NIS2 widens the circle of affected companies considerably compared with its predecessor. It now covers not only classic critical infrastructure but also areas such as waste management, food production, postal and courier services, chemicals, and large parts of digital services - often from thresholds of 50 employees or 10 million euro turnover.

The obligations come down to two things: appropriate technical and organisational measures to manage risk, and reporting duties for significant security incidents. What is new is management-level responsibility - leadership must approve the measures, oversee their implementation, and can be held personally liable.

Architecturally, the reporting deadline changes the most. An initial report is expected within 24 hours. Anyone who has to find out during the incident which systems are affected, who processed which data and from when, will not manage it. That deadline is therefore not a documentation question but a requirement on logging and visibility that has to exist beforehand.

For most companies the pragmatic route is to dock the requirements onto an existing ISO 27001 approach rather than building a second system. The overlap is large - the difference lies mainly in how binding it is and in the deadlines.

The service behind it

Security & Infrastructure

Where it shows up