NIS2 Directive: What You Need to Know
The NIS2 Directive establishes new rigorous cybersecurity requirements for essential and important entities in the European Union. Discover if your organization is covered and how to ensure compliance.
What is the NIS2 Directive?
NIS2 (Network and Information Security Directive 2) is the update to the original NIS directive, establishing more rigorous cybersecurity requirements across the European Union.
NIS2 significantly expands the scope of the original directive, covering 18 critical and important sectors, including energy, transport, health, digital infrastructures, public administration, and more.
- More than 160,000 entities covered in the EU
- Clearer size criteria
- Includes digital service providers
NIS2 introduces more detailed and specific security requirements, including risk management, supply chain security, incident notification, and management accountability.
- 10 mandatory security measures
- 24-hour incident notification
- Personal liability of managers
NIS2 establishes substantial administrative penalties for non-compliance, with fines that can reach millions of euros, depending on the entity classification.
- Essential Entities: up to €10M or 2% of global annual turnover
- Important Entities: up to €7M or 1.4% of global annual turnover
- Personal liability of management members
Member States must transpose the directive into national legislation by October 2024, with immediate application after transposition.
- October 2024: Transposition deadline
- Immediate: Application after national transposition
- Now: Ideal time to start preparation
Sectors Covered by NIS2
NIS2 covers 18 critical and important sectors, divided into two categories: Essential Entities and Important Entities.
Electricity, oil, gas, hydrogen
Air, rail, maritime, road
Credit institutions
IXP, DNS, TLD, cloud, data centers
Healthcare providers, laboratories
Supply and distribution
Collection and treatment
Central and regional public services
Ground infrastructure operators
Size Criteria
In covered sectors, NIS2 applies to medium and large entities. Under the EU SME definition, a company is medium-sized from 50 employees, or when it exceeds €10M annual turnover and €10M balance sheet, so many medium-sized SMEs are in scope. Micro and small companies generally are not, with exceptions: for example, if they are the sole provider of an essential service or if an incident would have significant impact.
10 Mandatory Security Measures
NIS2 establishes 10 cybersecurity risk management measures that all covered entities must implement.
Implement cybersecurity risk analysis and information systems security policies, including regular vulnerability assessments and penetration testing.
Establish policies and procedures to prevent, detect, respond to, and recover from cybersecurity incidents, including business continuity and disaster recovery plans.
Implement business continuity, disaster recovery, and crisis management plans, including backup systems and restoration procedures.
Assess and manage cybersecurity risks related to suppliers and service providers, including security requirements in contracts.
Implement security policies and procedures for the acquisition, development, and maintenance of information systems, including vulnerability management.
Establish policies and procedures to assess the effectiveness of cybersecurity risk management measures, including regular audits.
Implement cyber hygiene practices and cybersecurity training programs for all employees, including threat awareness.
Use encryption and access control policies, including multi-factor authentication and identity and privileged access management.
Implement human resources security policies, including background checks, confidentiality agreements, and termination procedures.
Use multi-factor authentication or continuous authentication solutions, secure voice, video, and text communications, and secure emergency communication systems.
Incident Notification
NIS2 establishes rigorous requirements and tight deadlines for notifying cybersecurity incidents to competent authorities.
Initial notification of significant incidents within 24 hours after becoming aware of the incident.
Detailed notification of the incident, including initial severity and impact assessment, within 72 hours.
Final report with detailed analysis of the incident, impact, mitigation measures, and lessons learned.
Significant Incidents
Incidents that cause or may cause serious operational disruptions or significant financial losses, or that affect other entities or users, must be notified.
- Interruption of essential services
- Compromise of personal or sensitive data
- Impact on other entities or users
- Significant financial losses
How We Can Help
Pentesting.pt offers specialized services to help your organization prepare and comply with the NIS2 Directive requirements.
Comprehensive assessment of your organization's current cybersecurity state against NIS2 requirements, with gap identification and action plan.
Request AssessmentRegular penetration testing to identify vulnerabilities and validate the effectiveness of implemented security measures.
View ServiceDevelopment of policies, procedures, and security documentation aligned with NIS2 requirements.
View ServiceImplementation of detection, response, and notification processes for incidents in accordance with NIS2 requirements.
View TrainingCybersecurity training programs for employees and management, including threat awareness.
View TrainingRegular audits to verify ongoing compliance with NIS2 requirements and identify areas for improvement.
View ServicePrepare Your Organization for NIS2
Don't wait until the last moment. Start now preparing your organization for NIS2 Directive compliance and protect yourself against penalties and cybersecurity risks.
Security testing for SMEs
A penetration test shows which technical measures are in place and where they fail, with evidence you can present for NIS2. Our packages are scoped to the size of your business.