European Union
NIS2
The NIS2 Directive strengthens cybersecurity across essential and important entities in the EU. It raises risk-management, governance, and incident-reporting requirements and holds management bodies accountable for compliance.
5 articles
Governance
Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and follow specific cybersecurity training.
Cybersecurity risk-management measures
Entities must take appropriate and proportionate technical, operational and organisational measures to manage risks, based on an all-hazards approach.
Reporting obligations
Entities must notify significant incidents to the CSIRT or competent authority via a phased timeline: early warning within 24 hours, incident notification within 72 hours, and a final report within one month.
Use of European cybersecurity certification schemes
Member States may require entities to use particular ICT products, services and processes certified under European cybersecurity certification schemes.
Supervisory and enforcement measures in relation to essential entities
Competent authorities may conduct audits and inspections and impose enforcement measures, including administrative fines, for infringements.
Turn NIS2 into tracked tasks
eurocompliant maps these obligations to checklists and evidence, so you can prove compliance instead of re-reading the text.
Start free trial