EU Resilience & Security Acts

NIS2

Network and Information Security Directive 2

Law / regulation EU European Union Since 2022

Cybersecurity risk management and incident reporting duties for essential and important entities across energy, transport, health, digital infrastructure, public administration and more, with management bodies personally accountable for compliance.

Being a directive, what binds you is the national transposition, not the text itself, so the detail varies by member state. ISO/IEC 27001 and IT-Grundschutz are the usual routes to demonstrating the required measures.

At a glance

Category
EU Resilience & Security Acts
Jurisdiction
EU
Governance
European Union
Status
Directive (EU) 2022/2555; national transposition was due October 2024, and several member states ran late
First released
2022

Links

Related regulation

Other entries under EU Resilience & Security Acts.

See NIS2 in context

Open the interactive Data Landscape for Regulation to compare NIS2 against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.