INDEPENDENT NIS2 RESOURCEGovernance · Resilience · ImplementationEU framework / national application
HomeOverview
The directive

What is NIS2?

Directive (EU) 2022/2555 establishes a common EU framework for cybersecurity across critical sectors. Member States implement it through national law, so the practical answer for an organisation requires both levels.

What the framework addresses

NIS2 widens the scope of the earlier NIS framework and addresses cybersecurity risk management, reporting of significant incidents, governance, supervision and cooperation. The Commission describes coverage across 18 sectors.

Start here: identify the legal entity and services, test whether an annex category applies, then verify the relevant national law and authority guidance.

Essential and important entities

The Directive distinguishes essential and important entities. Classification is connected to sector, type of entity, size and specific rules or exceptions. The label affects the supervisory approach, but it should not be assigned based on a sector name alone.

How to read this site

Official sources and context

Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.