What is NIS2? Scope and readiness explained

NIS2 is the EU directive designed to raise the common level of cybersecurity across critical sectors. It expands sector coverage and introduces cybersecurity risk-management, governance, supervision and significant-incident reporting duties through national implementing laws.

Who this is for: For EU-focused teams that want preparation support before making public NIS2 statements.

What NIS2 covers

NIS2 creates a common EU framework for cybersecurity in critical sectors while Member States implement and enforce it through national law. Covered entities may face duties around governance, risk management, supply-chain security, vulnerability handling, business continuity and incident reporting.

  • Cybersecurity governance
  • Risk-management measures
  • Significant-incident reporting

Build the evidence base

Policies, asset and risk records, incident procedures, vendor reviews, continuity plans, training records and remediation tasks can support NIS2 readiness.

Confirm applicability

Applicability depends on sector, size, role, Member State implementation and possible designation. A qualified adviser should confirm whether the organisation is an essential or important entity and which national rules apply.

Make responsibility visible

Every policy, supplier review and remediation task should have an owner, status and review date.

Common questions

What is NIS2 in simple terms?

NIS2 is an EU cybersecurity directive that requires Member States to establish stronger cybersecurity risk-management, governance, supervision and incident-reporting rules for covered critical sectors.

Who does NIS2 apply to?

It generally concerns medium-sized and large entities in listed critical sectors, with additional inclusions and exceptions. Exact scope depends on the directive, national implementing law and possible designation.

Is NIS2 directly applicable in every country?

NIS2 is a directive, so Member States transpose it into national law. Organisations need to check the rules and competent authority in each relevant jurisdiction.

What evidence supports NIS2 readiness?

Useful records include governance decisions, cybersecurity risk assessments, incident procedures, continuity and recovery plans, supplier reviews, vulnerability handling, training, access controls and remediation tracking.

Does Trustega determine NIS2 applicability?

No. Trustega can organise readiness records and evidence. Legal applicability and interpretation should be confirmed with qualified advisers in the relevant Member State.

Primary sources

Related practical guides