IT Glossary

NIS2 Directive

The NIS2 Directive strengthens EU cybersecurity rules for essential and important entities. Learn its scope, requirements, and how to comply.

July 3, 2026

What is the NIS2 Directive?

The NIS2 Directive (Directive (EU) 2022/2555) is a European Union law that strengthens cybersecurity requirements for organizations operating essential and important services. It expands the scope of the original NIS Directive, mandates stronger risk management, incident reporting, and management accountability, and applies to a far wider range of sectors and mid-sized companies than its predecessor.

Key requirements of NIS2

  • Risk management measures: including access control, MFA, and supply-chain security.
  • Incident reporting: early notification of significant incidents within defined deadlines.
  • Management accountability: leadership can be held responsible for compliance.
  • Wider scope: many more sectors and medium-sized companies are now in scope.
  • Stronger enforcement: higher penalties for non-compliance.

NIS Directive vs NIS2

NIS2 significantly expands the original NIS Directive. Where the original NIS covered limited sectors, NIS2 is far broader and includes the mid-market. Accountability moves from light to direct management responsibility, and enforcement moves from weaker to stronger penalties.

Examples and use cases

A 300-person European software company that was out of scope under the old NIS now falls under NIS2. It must implement access controls, MFA, and audit-ready evidence of who can access what. Identity and access governance sits at the center of this, because access control and accountability are explicit NIS2 expectations. For the full breakdown, see the dedicated article below.

Related concepts

FAQ

Who must comply with NIS2?

Essential and important entities across a wide range of sectors, now including many medium-sized companies that were out of scope under the original NIS Directive.

What are the core NIS2 obligations?

Risk management measures (including access control and MFA), timely incident reporting, supply-chain security, and direct management accountability.

How does access governance help with NIS2?

NIS2 expects strong access control and provable accountability. Identity governance, access reviews, and audit trails supply that evidence.

Request a demo