NIS2 in 60 Seconds
NIS2 (Network and Information Security Directive 2) is the EU's updated cybersecurity law. It replaces the original NIS Directive (2016) with significantly broader scope, stricter requirements, and harsher penalties. EU member states had until 17 October 2024 to transpose it into national law.
In simple terms: NIS2 requires essential and important entities across 18 sectors to implement cybersecurity risk management measures and report significant incidents.
Who Does NIS2 Apply To?
18 Sectors, 2 Categories
Essential entities (11 sectors):
- Energy (electricity, oil, gas, hydrogen, district heating)
- Transport (air, rail, water, road)
- Banking
- Financial market infrastructures
- Health (hospitals, reference labs, medical device manufacturers)
- Drinking water
- Waste water
- Digital infrastructure (DNS, TLDs, cloud, data centres, CDNs, trust services)
- ICT service management (B2B, managed services, managed security)
- Public administration
- Space
Important entities (7 sectors):
- Postal and courier services
- Waste management
- Chemicals
- Food production and distribution
- Manufacturing (medical devices, electronics, machinery, motor vehicles)
- Digital providers (online marketplaces, search engines, social networks)
- Research organisations
Size threshold: Generally applies to medium-sized enterprises and above (50+ employees or €10M+ turnover).
The 10 Minimum Security Measures
Article 21(2) requires at minimum:
- Policies on risk analysis and information system security
- Incident handling
- Business continuity and crisis management
- Supply chain security
- Security in network and information systems acquisition, development, and maintenance
- Policies and procedures for assessing cybersecurity risk-management measures
- Basic cyber hygiene practices and cybersecurity training
- Policies and procedures for the use of cryptography and encryption
- Human resources security, access control policies, and asset management
- Use of multi-factor authentication, secured communications, and secured emergency communications
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →NIS2 vs DORA — What's the Difference?
| Aspect | NIS2 | DORA |
|---|---|---|
| Legal form | Directive (transposed nationally) | Regulation (directly applicable) |
| Scope | 18 sectors, cross-economy | Financial sector only |
| Focus | Cybersecurity broadly | Digital operational resilience (ICT risk) |
| Overlap | Financial entities subject to DORA are exempt from NIS2 (lex specialis) | DORA takes precedence for financial entities |
Penalties
- Essential entities: Up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher
- Important entities: Up to €7,000,000 or 1.4% of total worldwide annual turnover, whichever is higher
- Management liability: NIS2 explicitly holds management bodies personally accountable. They must approve and oversee cybersecurity risk management measures.
Learn Ansible Automation in 250+ Examples
Comprehensive Ansible training with real-world use cases.
Start on Educative →NIS2 and AI Systems
AI systems that support essential or important services fall under NIS2 requirements. This means AI-powered network monitoring, predictive maintenance in energy, AI-driven diagnostics in healthcare, and similar applications need cybersecurity risk management, incident handling, and supply chain security measures.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 3-4 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
