Dr. Marcus Kessler
Chief Security Officer
The Network and Information Security Directive 2 (NIS2, Directive (EU) 2022/2555) is the EU's updated cybersecurity law, replacing the original 2016 NIS Directive. It substantially broadens the sectors in scope, raises the baseline of required security measures, and introduces personal liability for management.
⚠NIS2 entered force in October 2024 and was to be transposed into national law by 17 October 2024. Many member states are now actively enforcing. Non-compliance can bring fines up to €10 million or 2% of global turnover for essential entities.
NIS2 covers two tiers. "Essential" entities include energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, and public administration. "Important" entities include postal, waste, manufacturing, chemicals, food, and digital providers. The scope is far wider than the original directive.
Article 21 requires in-scope organizations to implement appropriate and proportionate technical, operational, and organizational measures. The directive lists ten minimum elements that must be addressed.
NIS2 introduces a faster reporting cadence than GDPR. An in-scope entity must report a significant incident to its CSIRT within 24 hours of detection (early warning), an updated report within 72 hours, and a final report within one month. Management boards must approve and sign off on security measures.
“NIS2 makes senior management personally accountable: directors can be held liable and temporarily prohibited from management duties for failures.”
NIS2 and GDPR are complementary. A personal data breach often triggers both: GDPR Article 33 (72-hour authority notification) and NIS2 incident reporting (24-hour early warning). The technical measures required — encryption, MFA, vulnerability management — satisfy both Article 32 (GDPR) and Article 21 (NIS2). A unified security program addresses both at once.
Our audit framework maps your controls against both NIS2 Article 21 and GDPR Article 32 in a single assessment, so you produce evidence once for both regimes. Contact us to scope a NIS2 readiness review.
The OWASP Top 10 is the baseline for web application security. We walk through each risk category for 2026, what it look...
HTTP security headers are your first line of defense against XSS, clickjacking, and content injection attacks. Here is t...