DEFINITION
NIS2 is the EU cybersecurity directive for essential and important entities; it expands the scope of application, harmonises security requirements and reporting obligations, and strengthens supervision and sanctions.
DeclarationNIS2
NIS2 mandates technical and organisational measures (including risk management, vulnerability and patch processes, business continuity, and supply chain security), strict incident-reporting deadlines, and management accountability. National transposition legislation specifies the details and supervisory mechanisms.
Implementation: Establish a controls mapping to ISO 27001/IEC 62443, define reporting playbooks, implement supply chain audits, and formalise board reporting. Review sector-specific transposition laws and thresholds for classification as an essential or important entity.
Key Points
- Risk management, reporting obligations, governance.
- Affected sectors defined in the annex to the directive.
- Overlaps with ISO 27001 and DORA.
Related Terms
On this page
→ Definition
→ Statement
→ Key points
→ Related terms
→ Sources
Relevant Blog Articles
How turnus.ai provides support
turnus.ai automates the answering of compliance questionnaires and customer inquiries with just a single click.



