Back to library
Cybersecurity · Issued by European Union

NIS2

NIS2 Directive (EU 2022/2555) — Network & Information Security

EUCyberRegulatoryDirective
Compare NIS2 with

EU cybersecurity directive expanding scope to thousands more essential and important entities. Mandatory from Oct 2024.

NIS2 imposes risk-management measures, 24/72-hour incident reporting and board-level accountability for cybersecurity. Aligns naturally with ISO 27001 and the NIST CSF. Fines up to €10M or 2% of global turnover.

At a glance

Complexity
High
Certification
Regulatory (mandatory)
Time to implement
6–18 months
Issued by
European Union

Fits

Industries
itbankinghealthcaregovernmentmanufacturingsupply chaininsurance
Risk types
cybercomplianceoperational
Frequently asked

Questions risk leaders ask

NIS2 is the EU's updated cybersecurity directive, expanding mandatory security and incident reporting requirements to thousands of essential and important entities across member states, effective October 2024.
India regulatory hub

India equivalent: CERT-In Directions 2022

Same scope (incident reporting, log retention, supply-chain), different timelines — and a 6-hour clock that's the world's fastest.

CERT-In deep dive
See if it fits you

Run the Finder to get a personalised match score for NIS2.

Made with Emergent