IT Glossary
The NIS2 Directive strengthens EU cybersecurity rules for essential and important entities. Learn its scope, requirements, and how to comply.
July 3, 2026
The NIS2 Directive (Directive (EU) 2022/2555) is a European Union law that strengthens cybersecurity requirements for organizations operating essential and important services. It expands the scope of the original NIS Directive, mandates stronger risk management, incident reporting, and management accountability, and applies to a far wider range of sectors and mid-sized companies than its predecessor.
NIS2 significantly expands the original NIS Directive. Where the original NIS covered limited sectors, NIS2 is far broader and includes the mid-market. Accountability moves from light to direct management responsibility, and enforcement moves from weaker to stronger penalties.
A 300-person European software company that was out of scope under the old NIS now falls under NIS2. It must implement access controls, MFA, and audit-ready evidence of who can access what. Identity and access governance sits at the center of this, because access control and accountability are explicit NIS2 expectations. For the full breakdown, see the dedicated article below.
Essential and important entities across a wide range of sectors, now including many medium-sized companies that were out of scope under the original NIS Directive.
Risk management measures (including access control and MFA), timely incident reporting, supply-chain security, and direct management accountability.
NIS2 expects strong access control and provable accountability. Identity governance, access reviews, and audit trails supply that evidence.