We are still developing our website

Skip to content
Transposition Deadline: October 2024

NIS2 Directive: What You Need to Know

The NIS2 Directive establishes new rigorous cybersecurity requirements for essential and important entities in the European Union. Discover if your organization is covered and how to ensure compliance.

What is the NIS2 Directive?

NIS2 (Network and Information Security Directive 2) is the update to the original NIS directive, establishing more rigorous cybersecurity requirements across the European Union.

Expanded Scope

NIS2 significantly expands the scope of the original directive, covering 18 critical and important sectors, including energy, transport, health, digital infrastructures, public administration, and more.

  • More than 160,000 entities covered in the EU
  • Clearer size criteria
  • Includes digital service providers
More Rigorous Requirements

NIS2 introduces more detailed and specific security requirements, including risk management, supply chain security, incident notification, and management accountability.

  • 10 mandatory security measures
  • 24-hour incident notification
  • Personal liability of managers
Significant Penalties

NIS2 establishes substantial administrative penalties for non-compliance, with fines that can reach millions of euros, depending on the entity classification.

  • Essential Entities: up to €10M or 2% of global annual turnover
  • Important Entities: up to €7M or 1.4% of global annual turnover
  • Personal liability of management members
Critical Deadlines

Member States must transpose the directive into national legislation by October 2024, with immediate application after transposition.

  • October 2024: Transposition deadline
  • Immediate: Application after national transposition
  • Now: Ideal time to start preparation

Sectors Covered by NIS2

NIS2 covers 18 critical and important sectors, divided into two categories: Essential Entities and Important Entities.

⚡Energy

Electricity, oil, gas, hydrogen

🚂Transport

Air, rail, maritime, road

🏦Banking

Credit institutions

🌐Digital Infrastructure

IXP, DNS, TLD, cloud, data centers

🏥Health

Healthcare providers, laboratories

💧Drinking Water

Supply and distribution

♻️Wastewater

Collection and treatment

🏛️Public Administration

Central and regional public services

🛰️Space

Ground infrastructure operators

Size Criteria

In covered sectors, NIS2 applies to medium and large entities. Under the EU SME definition, a company is medium-sized from 50 employees, or when it exceeds €10M annual turnover and €10M balance sheet, so many medium-sized SMEs are in scope. Micro and small companies generally are not, with exceptions: for example, if they are the sole provider of an essential service or if an incident would have significant impact.

10 Mandatory Security Measures

NIS2 establishes 10 cybersecurity risk management measures that all covered entities must implement.

1. Risk Analysis and Security Policies

Implement cybersecurity risk analysis and information systems security policies, including regular vulnerability assessments and penetration testing.

2. Incident Handling

Establish policies and procedures to prevent, detect, respond to, and recover from cybersecurity incidents, including business continuity and disaster recovery plans.

3. Business Continuity and Crisis Management

Implement business continuity, disaster recovery, and crisis management plans, including backup systems and restoration procedures.

4. Supply Chain Security

Assess and manage cybersecurity risks related to suppliers and service providers, including security requirements in contracts.

5. Security in Acquisition and Development

Implement security policies and procedures for the acquisition, development, and maintenance of information systems, including vulnerability management.

6. Assessment of Measure Effectiveness

Establish policies and procedures to assess the effectiveness of cybersecurity risk management measures, including regular audits.

7. Training and Awareness

Implement cyber hygiene practices and cybersecurity training programs for all employees, including threat awareness.

8. Encryption and Access Control

Use encryption and access control policies, including multi-factor authentication and identity and privileged access management.

9. Human Resources Security

Implement human resources security policies, including background checks, confidentiality agreements, and termination procedures.

10. Multi-Factor Authentication and Secure Communications

Use multi-factor authentication or continuous authentication solutions, secure voice, video, and text communications, and secure emergency communication systems.

Incident Notification

NIS2 establishes rigorous requirements and tight deadlines for notifying cybersecurity incidents to competent authorities.

24 Hours
Initial Alert

Initial notification of significant incidents within 24 hours after becoming aware of the incident.

72 Hours
Incident Notification

Detailed notification of the incident, including initial severity and impact assessment, within 72 hours.

1 Month
Final Report

Final report with detailed analysis of the incident, impact, mitigation measures, and lessons learned.

Significant Incidents

Incidents that cause or may cause serious operational disruptions or significant financial losses, or that affect other entities or users, must be notified.

  • Interruption of essential services
  • Compromise of personal or sensitive data
  • Impact on other entities or users
  • Significant financial losses

How We Can Help

Pentesting.pt offers specialized services to help your organization prepare and comply with the NIS2 Directive requirements.

NIS2 Readiness Assessment

Comprehensive assessment of your organization's current cybersecurity state against NIS2 requirements, with gap identification and action plan.

Request Assessment
Penetration Testing

Regular penetration testing to identify vulnerabilities and validate the effectiveness of implemented security measures.

View Service
Policies and Procedures

Development of policies, procedures, and security documentation aligned with NIS2 requirements.

View Service
Incident Management

Implementation of detection, response, and notification processes for incidents in accordance with NIS2 requirements.

View Training
Training and Awareness

Cybersecurity training programs for employees and management, including threat awareness.

View Training
Compliance Audit

Regular audits to verify ongoing compliance with NIS2 requirements and identify areas for improvement.

View Service

Prepare Your Organization for NIS2

Don't wait until the last moment. Start now preparing your organization for NIS2 Directive compliance and protect yourself against penalties and cybersecurity risks.

Security testing for SMEs

A penetration test shows which technical measures are in place and where they fail, with evidence you can present for NIS2. Our packages are scoped to the size of your business.