NIS2 - IT Management
NIS2 is the European Union's directive for a high common level of cyber security across the EU. It significantly widens the scope and obligations of the original NIS Directive — directly affecting more than 100,000 organizations — and makes strong cyber-security risk management a legal duty for essential and important entities.

What is NIS2?
NIS2 (the Network and Information Security Directive, Directive (EU) 2022/2555) was adopted in 2022 to strengthen cyber security and resilience across Europe. It replaces and expands the original NIS Directive, widening the range of sectors in scope and tightening security and reporting requirements. Because it is an EU directive, NIS2 is implemented through national legislation in each member state — so the precise obligations depend on where your organization operates. With 46 articles, over 140 recitals and many references to other European and national laws, understanding what NIS2 means for your organization takes a structured approach.
What NIS2 requires
NIS2 requires organizations in scope to manage cyber-security risk and prove they are doing so. Core obligations include a duty of care with appropriate technical and organizational risk-management measures, incident reporting within set timeframes, supply-chain security and business continuity. Crucially, management bodies are directly accountable: they must approve and oversee the measures, and can be held liable. A structured approach to cyber security and risk management — such as an ISMS aligned with ISO/IEC 27001 — helps organizations meet these requirements.
Why NIS2 matters
Who is NIS2 for?
NIS2 is primarily aimed at members of management bodies who are responsible for cyber security in their role, and at information security officers. More broadly, it is relevant to anyone in an essential or important entity — and to their suppliers — who needs to understand and act on the directive.
Becoming NIS2 compliant
Becoming compliant means understanding whether your organization falls in scope, then putting governance, risk management, incident handling and reporting processes in place — and keeping management involved. NIS2 covers many sectors deemed essential or important to society and the economy, from energy, transport, banking and health to digital infrastructure and public administration. Because obligations flow from national law, check the transposition in each country where you operate.


