Compliance · EU
EU Directive 2022/2555Essential & important entities

NIS2

Plain-English definition

NIS2 is the EU's updated Network and Information Security Directive, significantly expanding on the original NIS Directive's scope. It covers 'essential' entities (energy, transport, banking, financial market infrastructure, health, water, digital infrastructure, public administration, space) and 'important' entities (including manufacturing, food, postal and courier services, and waste management above certain size thresholds), each with defined risk-management and incident-reporting obligations.

Transposition into national law varies by EU member state and applicability depends on both sector and organization size, so scope should be confirmed against your specific jurisdiction.

Who needs it

Organizations operating in the expanded list of essential and important sectors within the EU, including many mid-sized companies that were out of scope under the original NIS Directive but now meet NIS2's broader size and sector thresholds.

Key requirements

Risk-management measures covering incident handling, business continuity, supply-chain security, and access control; incident reporting on a strict timeline (early warning within 24 hours, incident notification within 72 hours, final report within one month); and direct management-body accountability for cybersecurity risk oversight.

Cyber/privacy implications

Supply-chain security is an explicit requirement, not an implied best practice, meaning your vendor risk management program needs to be documented and defensible, not informal.

Assessment methodology

Entity classification (essential vs. important, and applicability confirmation), gap assessment against the risk-management measures, incident-reporting process design against the tight statutory timelines, and supply-chain security review.

Implementation phases

01
Classify

Confirm essential/important entity status and jurisdiction-specific obligations.

02
Remediate

Close gaps in risk-management measures and supply-chain security controls.

03
Report

Stand up incident classification and reporting processes matched to statutory deadlines.

Evidence & documentation requirements

Risk-management measure documentation, supply-chain security assessments of critical vendors, incident classification and reporting records, and management-body cybersecurity oversight records.

Common mistakes

Assuming NIS Directive compliance under the original directive automatically satisfies NIS2's expanded requirements; missing the 24-hour early-warning reporting deadline because incident detection and internal escalation aren't fast enough to meet it.

Related standards

Expert review

Nitzan Levi
Nitzan Levi
Co-Founder, Cybecs · Co-Founder, RedRok · Executive Director, Privacy & GRC · CISM, CISSP, CDPSE, CCSK, CSA

FAQ

How do I know if we're 'essential' or 'important'?
Determined by your sector and organization size against thresholds set in the directive and your member state's transposition law; we confirm classification as the first step.
What's the penalty for non-compliance?
Varies by member state transposition, but NIS2 sets a framework for significant fines and includes personal liability provisions for management bodies in cases of gross negligence.
We're a supplier to an essential entity, does this affect us?
Indirectly yes: essential and important entities are required to manage supply-chain risk, so your customers may push NIS2-aligned security requirements down to you contractually even if you're not directly in scope.

Request a Gap Assessment

Confirm your NIS2 classification and see where your controls stand.

Request a Gap Assessment →