NIS2

Last updated:

05 December 2025

3 min read

DEFINITION

NIS2 is the EU cybersecurity directive for essential and important entities; it expands the scope of application, harmonises security requirements and reporting obligations, and strengthens supervision and sanctions.

DeclarationNIS2

NIS2 mandates technical and organisational measures (including risk management, vulnerability and patch processes, business continuity, and supply chain security), strict incident-reporting deadlines, and management accountability. National transposition legislation specifies the details and supervisory mechanisms.

Implementation: Establish a controls mapping to ISO 27001/IEC 62443, define reporting playbooks, implement supply chain audits, and formalise board reporting. Review sector-specific transposition laws and thresholds for classification as an essential or important entity.

Key Points

- Risk management, reporting obligations, governance.

- Affected sectors defined in the annex to the directive.

- Overlaps with ISO 27001 and DORA.

Related Terms

Further Resources

On this page

→ Definition

→ Statement

→ Key points

→ Related terms

→ Sources

How turnus.ai provides support

turnus.ai automates the answering of compliance questionnaires and customer inquiries with just a single click.