Framework

NIS2 (Network and Information Security Directive)

The updated EU directive on cybersecurity that expands the scope of the original NIS Directive to cover more sectors and entities. NIS2 introduces stricter security requirements, incident reporting obligations, and enforcement measures with significant penalties for non-compliance.

The NIS2 Directive (Directive (EU) 2022/2555) is the EU's updated cybersecurity legislation that replaces the original NIS Directive from 2016. It significantly expands the scope to cover essential and important entities across 18 sectors, including energy, transport, banking, health, digital infrastructure, and public administration. Member states were required to transpose NIS2 into national law by October 17, 2024.

NIS2 introduces proportionate security requirements based on entity classification. Essential entities (large organizations in critical sectors) face stricter oversight and higher penalties (up to €10 million or 2% of global turnover), while important entities have somewhat lighter requirements but still face penalties up to €7 million or 1.4% of turnover. Key obligations include risk management measures, incident reporting within 24 hours (early warning) and 72 hours (full notification), supply chain security, and management body accountability.

For financial services organizations already subject to DORA, NIS2 generally defers to DORA as the sector-specific regulation (lex specialis). However, organizations in overlapping sectors should understand both frameworks to ensure comprehensive compliance coverage.

Learn More

Discover how Matproof can help you achieve NIS2 (Network and Information Security Directive) compliance.

View framework page

Automate compliance with Matproof

DORA, SOC 2, ISO 27001 — get audit-ready in weeks, not months.

Request a demo