NIS2 Directive
NIS2 is a European Union law aimed at strengthening cybersecurity across the EU. It is the updated version of the earlier NIS Directive and applies to organizations operating in a range of critical sectors. It sets expectations for how these organizations protect their network and information systems.
NIS2 (Directive (EU) 2022/2555) is an EU directive that establishes a unified legal framework for cybersecurity across critical sectors within the European Union, replacing the original NIS Directive (Directive (EU) 2016/1148). As a directive, it sets obligations that EU Member States are required to transpose into their respective national laws, meaning specific implementation details, thresholds, and enforcement mechanisms can vary by Member State. According to the European Commission, its scope covers 18 critical sectors and it calls on Member States to take corresponding measures. This entry describes the instrument's purpose and scope at a high level; it does not cover sector-specific applicability determinations, national transposition specifics, or legal advice on individual compliance obligations, which depend on jurisdiction and organizational circumstances.
Why it matters
NIS2 represents a significant expansion of the European Union's approach to cybersecurity regulation. As the successor to the original NIS Directive (Directive (EU) 2016/1148), it establishes a unified legal framework intended to raise the level of cybersecurity across critical sectors within the EU. For organizations operating in the covered sectors, NIS2 signals that cybersecurity is treated not merely as an operational concern but as a matter of legal compliance subject to Member State enforcement.
Because NIS2 is a directive rather than a directly applicable regulation, its practical significance depends heavily on how each EU Member State transposes it into national law. Specific implementation details, thresholds, and enforcement mechanisms may vary across jurisdictions. This means that an organization operating in multiple Member States may face differing obligations depending on where it operates, making jurisdictional awareness an important part of any compliance assessment. Organizations should not assume that a single, uniform set of requirements applies EU-wide.
The European Commission describes NIS2's scope as covering 18 critical sectors, reflecting a broader reach than the earlier NIS Directive. Determining whether a particular organization falls within scope, and what obligations follow, requires a sector-specific and jurisdiction-specific analysis that is beyond the level of this entry. Compliance and legal teams typically treat scope determination as an early and consequential step, since it drives the subsequent assessment of applicable measures.
Who it's relevant to
Inside NIS2
Common questions
Answers to the questions practitioners most commonly ask about NIS2.
