What is NIS2?
NIS2 is the EU Network and Information Security Directive 2, which member states had to transpose by 17 October 2024 and apply from 18 October 2024. It expands cybersecurity obligations to approximately 160,000 entities across essential and important sectors: energy, transport, banking, healthcare, water, digital infrastructure. NIS2 requires risk-management measures (Article 21), incident notification within 24 hours (Article 23), and management-body accountability.
The longer answer.
NIS2 is Directive (EU) 2022/2555. It sorts organizations into essential and important entities across 11 essential and 7 important sectors, and penalties for essential entities reach 10 million euros or 2% of global turnover. National authorities such as BSI in Germany and ANSSI in France supervise it.
Article 21 lists the required risk-management measures, including risk analysis and information security policies, incident handling, business continuity, supply chain security, security in system acquisition and maintenance, cyber hygiene, and the use of cryptography. Secure configuration, continuous monitoring and drift detection give technical evidence for several of these.
More questions on Frameworks?
Our compliance engineers can show you exactly how CISGuard handles Frameworks in a briefing scoped to your environment.