← All terms

NIS2 Directive

The NIS2 Directive (EU 2022/2555) is the EU cybersecurity law for 18 critical sectors, mandating risk management, training and 24-hour incident reporting.

The NIS2 Directive (Directive (EU) 2022/2555) is the European Union's cybersecurity law for critical and important infrastructure. It replaced the original 2016 NIS Directive, dramatically widening its reach: essential and important entities across 18 sectors — energy, transport, health, digital infrastructure, ICT service management, public administration, manufacturing of critical products and more — must implement a defined set of cybersecurity risk-management measures and report significant incidents on strict deadlines. Member states were required to transpose the directive into national law by 17 October 2024; in July 2026 the European Commission referred the last four holdouts to the Court of Justice for missing that deadline.

How it works

NIS2 operates through national law rather than directly, which is why transposition matters. Once in force, three mechanisms carry most of its weight. Article 21 lists ten minimum measures every in-scope entity must implement, ranging from incident handling and supply-chain security to "basic cyber hygiene practices and cybersecurity training." Article 20 makes the management body accountable: directors must approve the risk-management measures, oversee their implementation, follow cybersecurity training themselves, and can be held personally liable for infringements. Article 23 sets the reporting clock — an early warning to the authority within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. Non-compliance carries fines of up to €10 million or 2% of worldwide turnover for essential entities (€7 million or 1.4% for important ones).

How to defend and comply

The human-layer obligations are the ones security teams most often underestimate. A defensible NIS2 posture needs documented training for the management body, a regular training cadence for the workforce, and an incident-reporting reflex fast enough to beat the 24-hour early-warning window — which in practice means employees who recognize social engineering and report it in minutes, not days. Continuous phishing simulation and a measurable human risk score turn those duties into evidence a supervisor can audit. Our guide to NIS2's human-risk requirements walks through Articles 20, 21 and 23 in detail.

Full guide
Read the deep dive on this attack →

Related terms

Digital Operational Resilience Act (DORA)DORA (EU 2022/2554) is the EU regulation making financial entities manage ICT risk — with compulsory security awareness training for all staff and management.Cyber HygieneCyber hygiene is the set of routine practices — updates, strong authentication, least privilege, awareness — that keeps users and systems resistant to attack.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo