NIS2 Directive
The NIS2 Directive (Directive (EU) 2022/2555) is the European Union's updated cybersecurity directive, expanding the scope of covered entities and strengthening cybersecurity risk management, incident reporting, and supervisory obligations across essential and important sectors.
What NIS2 Requires
NIS2 imposes cybersecurity risk management obligations across covered entities, including governance and accountability at management level, technical and organizational measures for security, incident handling and business continuity, supply chain security, and vulnerability disclosure.
The directive introduced strengthened incident reporting requirements, with initial notifications typically due within 24 hours of awareness for significant incidents, followed by more detailed reports at defined intervals.
Who NIS2 Applies To
NIS2 significantly expanded the covered-entity scope compared to its predecessor. Essential entities include sectors like energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. Important entities include additional sectors like postal services, waste management, chemicals, food, manufacturing, digital providers, and research.
Size thresholds apply. Medium-sized and large entities in covered sectors fall in scope, with smaller entities included when they are critical for specific reasons.
Why NIS2 Matters
NIS2 substantially raised the bar for cybersecurity obligations across the EU, with real teeth: substantial fines, personal accountability for management, and expanded supervisory powers. It also aligns thematically with DORA for financial entities, though the two regimes have distinct scopes.
Related Terms
Turn Cyber Risk Into Financial Exposure the Board Can Act On
Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.


