Guide to NIS2 – New cybersecurity rules
The European Union has raised the bar for cybersecurity with the NIS2 Directive (Directive (EU) 2022/2555). Replacing the original 2016 NIS Directive, this regulation introduces stricter obligations for companies operating within the EU or serving European partners. Its goal: stronger protection of networks, data, and digital services across an increasingly complex threat landscape.
What is the NIS2 Directive?
NIS2 aims to achieve a high common level of cybersecurity across the Union by significantly broadening the range of sectors and entities required to implement cybersecurity measures and report incidents to national authorities. The Directive no longer covers only traditional critical infrastructure — it also applies to companies providing digital services and organisations whose operations are important to the functioning of the economy and society.
Compared to the original NIS Directive, which applied to a limited number of designated operators, NIS2 covers a much wider range of sectors, including energy, transport, banking and financial market infrastructure, healthcare, digital infrastructure, public administration, and manufacturing. As a result, far more organisations across the EU now need to be prepared to respond to cyber threats.
Core Obligations Under NIS2
Organisations that fall within the scope of NIS2 are required to:
- Implement technical and organisational measures to protect network and information systems
- Establish clear risk-management procedures based on an all-hazards approach
- Report significant security incidents to the relevant national authority — with an initial early warning within 24 hours and a fuller notification within 72 hours
- Address supply chain security, including the risks arising from relationships with direct suppliers and service providers
- Provide training for staff, and in particular for management bodies
A key feature of the Directive is the emphasis on management accountability. Company leadership must approve and oversee cybersecurity risk-management measures, and can be held liable for failing to ensure adequate implementation. Beyond technical capability, NIS2 places real weight on organisational culture — treating cybersecurity as a shared responsibility rather than a purely technical function.
Why NIS2 Matters Even Beyond the Companies Directly in Scope
NIS2 doesn’t only affect the essential and important entities named directly in the Directive. Its influence extends through supply chains: if your business supplies services or products to a company that falls under NIS2, you may be asked to demonstrate equivalent cybersecurity practices as part of that customer’s own supplier-risk assessment. Being able to show a structured, certifiable approach to information security has therefore become a competitive advantage — and increasingly, a condition for doing business — well beyond the entities formally designated as essential or important.
How Companies Can Prepare for NIS2
- Assess applicability – determine whether your organisation, or your role in a client’s supply chain, brings you within scope.
- Strengthen risk management – review and reinforce your cybersecurity risk-management strategy in line with the all-hazards approach required by the Directive.
- Align processes – implement internal policies, procedures, and tools covering incident handling, business continuity, access control, and cryptography.
- Train your people – involve employees, and especially management, in regular cybersecurity training.
Verifying Compliance Through Certification
One of the most effective ways to demonstrate NIS2 readiness is through independent, internationally recognised certification of your information security management system. Many of the risk-management, incident-handling, and supply-chain security practices required under NIS2 overlap closely with established ISMS standards, making certification a practical way to document and prove compliance to regulators, partners, and customers alike.
INTERCERT, working with TÜV AUSTRIA, supports companies across Europe with independent assessment and certification of their information security management systems.
👉 Learn more about ISO/IEC 27001 certification, requirements, and pricing in Europe
Conclusion
NIS2 should not be viewed merely as a regulatory burden, but as an opportunity to strengthen digital resilience. Preparing early not only reduces risk but also builds trust with partners and customers in a digital environment that keeps evolving. Investing in cybersecurity today means stability, competitiveness, and long-term business continuity.
For more background on the NIS2 Directive, its scope, and its implementation across EU Member States, see nis-2-directive.com