NIS2
Directive (EU) 2022/2555.
- What is NIS2NIS2 is Directive (EU) 2022/2555. It requires essential and important entities to manage cybersecurity risks and to report significant incidents.
- Who NIS2 applies toArticle 2 applies the directive to public or private entities of a type in Annex I or Annex II that are medium-sized, or larger, under Recommendation 2003/361/EC, and that provide services or carry out activities in the Union.
- NIS2 Article 21Article 21 requires essential and important entities to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems they use, and to prevent or minimise the impact of incidents.
- NIS2 Article 23Article 23 is the incident report. An early warning goes out within 24 hours of becoming aware of a significant incident. An incident notification follows within 72 hours. A final report is due not later than one month after that notification.