NIS2
Also known as: NIS2 Directive
NIS2 is an EU directive on cybersecurity that sets technical and organizational baseline requirements for network and information systems.
NIS2 is a European Union directive on cybersecurity that member states transpose into national law. It sets out requirements for handling cyber risk in network and information systems, covering areas such as risk management, handling security incidents, and supply chain security.
In terms of content, NIS2 touches on technical topics such as network segmentation, access management, multi-factor authentication, backup and disaster recovery planning, and reporting security incidents to the relevant authorities. How it's actually transposed into national law differs by country, as does the precise scope of which organizations it covers.
Whether and to what extent a given business falls under NIS2 depends on criteria that vary by national implementation and that can change over time. That question is a legal one, not a technical one, and should be clarified with your own legal counsel – a glossary entry can't and shouldn't substitute for that.
What it means in practice
For a business, NIS2 is worth treating as a reason to review technical fundamentals such as network segmentation, access rights, backups, and incident detection, regardless of whether a legal obligation applies. Whether a specific business is covered and exactly what's required is a question for your own legal counsel. NDVDL implements the technical building blocks typically associated with NIS2 – the legal assessment is a separate matter.
Is this handled properly at your site?
We look at how it actually stands with you — and say honestly whether anything needs doing.
Related terms
All termsA term from your quote missing here?
Send us the passage you do not follow. We will explain it — with no obligation to order anything.