THREAT BRIEFING · 10.09.2026 DEENFRES

Strategy & Governance

NIS2: All Details and Background Information on the New EU Cybersecurity Directive

By Tobias Massow · August 2, 2023 · 5 min read

EU Agrees on New Cybersecurity Directive: What NIS2 Means for Companies

There is a new EU directive that deals with the harmonization of EU-wide standards in the field of cybersecurity and contains far-reaching provisions for companies. There is little time left until the regulation comes into force in all member states next year.

By 17 October 2024, the member states of the European Union must transpose the new EU directive NIS2 – for the regulation of Network and Information Security – into national law. Companies therefore have just over a year to prepare for the changes and align their processes and systems with the new requirements. The goal of the new directive is to “deepen and substantively expand the requirements for cybersecurity to improve protection in the sense of strengthening, modernizing, and expanding central provisions.”

Many More Companies Affected

In plain language, the EU aims to further harmonize cybersecurity standards across Europe, extend them to more industries and companies, and strengthen overall resilience against threats from cyberspace. NIS2 now also includes companies with 50 employees and a turnover of 10 million euros. Additionally, the new directive contains clear provisions regarding the “essential” and “important” sectors, for which special rules apply.

In the predecessor version NIS from 2016, each member state could define these sectors itself. In NIS2, the EU has clearly defined which industries fall under the respective categories. These include, for the “essential sectors,” the areas of energy, health, transport, banking and insurance, water and wastewater, network providers, as well as ICT service providers, aerospace, and public administration. The “important sectors” include postal and courier services, waste management, chemicals, food, industry, digital services, and research.

Far-Reaching Provisions for Cybersecurity

NIS2 contains strict provisions for the protection of the EU’s digital infrastructure and goes beyond the German IT Security Act 2.0. The central element of the directive is the obligation to integrate an IT security strategy into global corporate governance. This includes precise rules regarding risk management and the awareness-raising and training of employees, provisions for reporting incidents, and regulations for emergency plans in case of an emergency.

Additionally, NIS2 contains provisions on data protection and security, data access management, vulnerability management, and encryption, all of which are summarized under the term “cyber hygiene.” To implement these, companies must review all existing processes and measures, align their own requirements with the directive’s provisions, and keep in mind the rapidly changing IT world with new technologies and challenges from cybercriminals.

Time is running out: By 17 October 2024, EU member states must transpose NIS2 into national law. Companies have until then to adapt to the requirements and adjust their systems and processes.
Be warned: violations could trigger fines of up to 10 million euros!

TL;DR

Key Facts

Scope: Companies with 50 employees and 10 million euros in annual turnover

Implementation Deadline: 17 October 2024 for national implementation in all EU member states

Fines: Up to 10 million euros in case of violations

Essential Sectors: Energy, health, transport, banking, water, IT service providers, aerospace, public administration

Fact: According to the BKA (Federal Criminal Police Office), German companies suffered damages of over 206 billion euros due to cybercrime in 2024.

Fact: According to Mandiant, the average dwell time of an attacker in a network is 10 days.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What is NIS2 and who does the directive affect?

NIS2 is the revised EU directive for the regulation of network and information security. It affects companies with 50 employees and 10 million euros in turnover in defined essential and important sectors – significantly more companies than the predecessor version NIS from 2016.

What are the core requirements of NIS2?

NIS2 requires the integration of an IT security strategy into corporate governance, risk management processes, incident reporting obligations, emergency plans, employee training, and measures for data protection, encryption, and vulnerability management.

What penalties are threatened in case of non-compliance?

In case of violations against the NIS2 provisions, fines of up to 10 million euros are threatened. The amount depends on the severity of the violation and the size of the company.

What distinguishes NIS2 from the original NIS directive?

NIS2 defines the affected sectors uniformly across the EU for the first time, extends the scope to more industries and smaller companies, and tightens the requirements for risk management and incident reporting.

How should companies prepare for NIS2?

Companies must align existing processes and measures with the NIS2 provisions, integrate an IT security strategy into management, and train their employees. A gap assessment is the recommended first step.

Further Reading in the Network

Cloud Compliance and Regulation on cloudmagazin.com

EU Regulation and Its Business Impacts on mybusinessfuture.com

NIS2 as a C-Level Priority on digital-chiefs.de

Related Articles

Header Image Source: Pexels

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH