コンテンツに移動
NIS2 Compliance - Banner background Image

Everything you need to prepare for the NIS 2 Directive

Navigate your NIS 2 Compliance Journey with Sophos

The NIS2 directive became effective in January 2023. EU Member States had been given a deadline of October 17, 2024,
to integrate NIS2 security requirements into their national legislation. By this date, all companies falling under the scope of
NIS2 must ensure compliance with the updated requirements.

What’s new with NIS 2?

NIS 2 replaces the original NIS Directive introduced in 2016, which was the first piece of EU-wide legislation on cybersecurity. NIS 2 widens the scope of the initial framework to include more industries, introduces stringent supervisory measures for national authorities, places greater focus on supply chains, creates stricter enforcement and stricter penalties for non-compliance.

NIS vs NIS2 - comparison

Who does NIS 2 apply to?

The original NIS Directive primarily applied to critical infrastructure organizations, pulling into the Directive’s requirements only 7 industry sectors as Operators of Essential Services and 3 industry sectors as Digital Services. NIS 2 significantly expands the scope to include 11 industry sectors as Essential Entities and 7 industry sectors as Important Entities.

Essential Entities are subject to a more intensive supervision regime in which both ex-ante and ex-post compliance are monitored (meaning that entities will be required to meet supervisory requirements as of the introduction of NIS 2.) Important Entities are subject to a lighter form of supervision, only ex-post (meaning that action is only taken if and when authorities receive evidence of non-compliance).

An organisation is covered by the NIS 2 Directive if:

  • The organization provides services or carries out activities in any of the EU member states
  • With exceptions, the organization has at least 50 employees or an annual turnover or balance sheet of over €10 million
  • The organization operates in one of the 18 sectors specified by NIS 2 under Annex I and Annex II

NIS 2 identifies organizations operating in the following 18 sectors as essential entities and important entities depending on the total annual revenue and size of the organization:

*Essential Entities:

These are typically medium and large organizations seen as critical to the economy and operating in a sector listed in the left column above.

**Important Entities:

These are typically medium and large organizations seen as important to the economy but not critical and operating in a sector listed in the right column above.

Exceptions: Companies that are the sole provider of a particular service within an EU member state or disruption of their service could have a significant impact may be classified as an essential entity or important entity regardless of size.

Typical criteria for an organization to be considered large:

  • 250 employees or more; or
  • An annual turnover of €50 million or more and a balance sheet total of €43 million or more

Criteria for an organization to be considered medium:

  • 50 employees or more; or
  • An annual turnover and balance sheet total of €10 million or more

Small or micro-organizations are not excluded from the scope of NIS 2. Member States can extend NIS 2 requirements if an entity fulfils specific criteria as a key player in society, the economy, or sectors or types of service.

 

nis2-industries_0.png.webp