The NIS2 Directive (Directive (EU) 2022/2555) is the European Union’s updated cybersecurity framework, aiming to strengthen the resilience of critical infrastructure and essential services against cyber threats. It expands the scope of its predecessor, NIS1, by introducing stricter security requirements, incident reporting obligations, and governance measures.
Following the implementation deadline of 17 October 2024, the European Commission published the NIS2 Implementing Regulation and Annex. The Implementing Regulation and Annex sets out further details on Article 21 – Cybersecurity risk management measures, and when an incident is ‘significant’ according to Article 23(3).
Here at WLC, we have drafted a Briefing Paper, which may assist your organisation in understanding not only the obligations upon important and essential entities but also provide some guidance as to how your organisation could maintain compliance with the new NIS2 Directive.
This Briefing Paper summarises the key requirements of the NIS2 Directive, providing a checklist for organisations, and an in-depth review of the key requirements contained within Articles 20 – 23. Specifically, this briefing document provides a breakdown of the requirements which are applicable to NIS2 organisations.