NIS2 Directive
EU Directive 2022/2555, which sets cybersecurity risk management and incident reporting obligations for mainly medium and large organisations in critical sectors, including energy, transport, health, digital infrastructure and manufacturing.
NIS2 replaced the original 2016 NIS Directive and greatly widened its scope. It classifies in-scope organisations as essential or important entities according to sector and size. Sectors of high criticality include energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration and space; other critical sectors include postal services, waste management, chemicals, food and the manufacture of products such as machinery, vehicles, electronics and medical devices. Member states had to transpose the directive into national law by 17 October 2024.
Entities must take appropriate and proportionate technical, operational and organisational measures, including risk analysis, incident handling, business continuity, supply-chain security, secure development and vulnerability handling, cryptography, access control, multi-factor authentication and staff training. Significant incidents must be reported in stages: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. Management bodies must approve the measures and can be held liable for failures.
Industrial organisations can be affected both directly, through their own classification, and indirectly, as suppliers to in-scope entities. Member states must provide maximum fines of at least 10 million euros or 2 per cent of worldwide annual turnover for essential entities. Because national transposition differs and some member states transposed late, organisations need to check the applicable national law, and standards such as ISO/IEC 27001 and IEC 62443 help structure the required measures.
Key points
- Directive (EU) 2022/2555, with a transposition deadline of 17 October 2024.
- Covers essential and important entities in many sectors, including manufacturing.
- Incident reports: 24-hour early warning, 72-hour notification, one-month final report.
- Management bodies approve security measures and can be held liable.
Where AiVibe comes in
AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.
Related terms
- Incident ResponseCybersecurity & Compliance
- ISO/IEC 27001Cybersecurity & Compliance
- IEC 62443 (ISA/IEC 62443)OT & Industrial Cybersecurity
- Cyber Resilience Act (CRA)Cybersecurity & Compliance
- General Data Protection Regulation (GDPR)Cybersecurity & Compliance
- Software Supply Chain AttackCybersecurity & Compliance