
We previously released some guidance around the new Network and Information Security Directive (NIS2), which you can read here. NIS2 has many different areas to dive into, so we thought we'd make this guide to keep you up to date with the new directive ahead of the changes.
Introduction To make the EU digitally safer, the EU published a new version of the Network and Information Security directive ( NIS2 ) at the end of 2022. After the translation of NIS2 into national legislation by the Member States, is expected to become effective at the end of 2024.
NIS2 will be applicable to more sectors and entities than the current directive, with more explicitly described security measures and fines, stricter incident reporting obligations, and will empower national supervisory authorities.
What are the timelines? NIS2 was approved and published by the EU at the end of 2022 and the implementation period of 21 months began in January 2023, during which the directive must be incorporated into national legislation. National laws are expected to enter into force at the end of 2024. From then, organisations must fulfill their duty of care and reporting.
Which organisations are in scope? Entities in the sectors mentioned in the table below are in scope. NIS2 makes a clear distinction between essential sectors and important sectors .
Essential entities will be actively monitored by supervisory authorities, whereas passive supervision will be carried out on the important entities.
Essential sectors: Energy, Transport, Banks, Financial market infrastructure, Health, Drinking water, Waste water, Digital Infrastructure, ICT Service Management, Public Administration, Space
Important sectors: Postal and courier services, Waste management, Chemicals, Food, Manufacturing, Digital services, Research
NIS2 does not apply to entities employing fewer than 50 persons and whose annual turnover (or annual balance sheet total) does not exceed 10 million. Exceptions to this size criteria are, for example, providers of trust services and public electronic communication services.
Will there be central registers maintained with organizations in scope? By April 2025, Member States shall establish a list of essential and important entities, and entities providing domain name registration services. For the purpose of establishing the list, Member States shall require the entities to submit at least the following information to the competent authorities:
(a) the name of the entity;
(b) the address and up-to-date contact details, including email addresses, IP ranges and telephone numbers.
The entities shall notify any changes within two weeks of the date of the change.
ENISA, the European Union Agency for Cybersecurity, will be responsible for the creation and maintenance of a registry for entities providing cross-border services e.g, DNS service providers, TLD name registries, entities providing domain name registration services, cloud computing service providers, and data centre service providers. Entities in scope are obliged to provide the required information before 18th January 2025.
Is governance and liability addressed? Management bodies of essential and important entities must approve the cybersecurity risk-management measures taken by those entities and oversee its implementation and can be held liable for infringements.
What does the duty of care mean for organisations? Organisations must take appropriate measures for the security of network and information systems, including the physical environment. Appropriate means that they are tailored to the risks. The directive states that, among other things, there must be:
Information systems risk analysis and security policy
Incident Handling
Business continuity, such as backup management, contingency, and crisis management
Security of the supply chain and life cycle of network and information systems, including response to and disclosure of vulnerabilities
Policies and procedures for assessing the effectiveness of security measures
Basic cyber hygiene practices and cyber security training
The directive refers to European and international standards for the design of security measures and specifically mentions the ISO 27000 series. Guidelines for cyber security and hygiene are also available on websites of (semi) governmental websites e.g., the Centre for Cyber Security Belgium, the National Cyber Security Centre and the Rijksinspectie Digitale Infrastructuur (both in the Netherlands).
What does the duty to report mean for organisations? The entities in scope of NIS2 must issue a preliminary alert for any significant incident (without delay) or any event, within 24 hours, and submit an incident report to the Computer Security Incidents Response Team (CSIRT) or competent authority within 72 hours at the latest.
Furthermore, entities will have the obligation to report changes related to the lists, with entities maintained by the European Union Agency for Cybersecurity (ENISA), and Member States.
What is the supervisory regime? Member States will monitor compliance with NIS2-based legislation. The essential entities will be actively supervised. Important entities will be passively supervised, meaning supervising authorities will take action if there is reason to do so, e.g., in the event of an incident.
Supervising authorities will have the power to subject entities, at least, to on-site inspections, off-site supervision, regular and ad hoc audits, security scans, and requests for documentation and information.
What are the possible fines? Administrative fines can be imposed on essential entities up to a maximum amount of at least 10 million, or up to at least 2% of global annual turnover.
Administrative fines can be imposed on significant entities up to a maximum amount of at least 7 mill
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
01/04/2026
January 4 2026, 18:00 (PST) DOLBY AND DOUYIN EMPOWER THE NEXT GENERATON OF CREATORS WITH DOLBY VISION
Douyin Users Can Now Create And Share Videos With Stun...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
11/02/2026
Graduate Spotlight: Gabrielle Rodriguez The educator, who grew up in the Philippines, shares how shes bringing what she learned at Berklee back home.
Februar...
11/02/2026
The intergalactic children's show starring Adam King will premiere on 14 February on RT 2, RT KIDSjr and RT Player
The Late Late Toy Show star Adam King...
10/02/2026
From San Fran to Santa Clara down to Los Angeles, ESPN celebrates the Big Game w...
10/02/2026
A team of broadcast engineers and experts dispersed across Northern Italy help broadcasters and still photographers keep shooting
OBS has put new imaging techn...
10/02/2026
If you can have the best pictures and the best sound quality for these global ev...
10/02/2026
Disney+ will add vertical video within its app this year after ESPN introduced V...
10/02/2026
GameChanger today unveiled the most comprehensive product update in its 15-year history, marking a major step forward in how families, athletes, coaches, fans, ...
10/02/2026
With a new film adaptation of Wuthering Heights arriving just in time for Valent...
10/02/2026
Today, we announced our fourth quarter 2025 earnings, marking a strong finish to the year with exceptional user growth and continued momentum across the busines...
10/02/2026
I dag redovisar vi v rt resultat f r fj rde kvartalet 2025, vilket markerar ett starkt avslut p ret med robust anv ndartillv xt och fortsatt momentum i hela v...
10/02/2026
World-first opt-out function now fully integrated on SBS On Demand
10 February, 2026
Media releases
SBS has announced a suite of audience-first enhancement...
10/02/2026
Jennifer Hanley, Vice President, International, L3Harris, signed a Memorandum of...
10/02/2026
eds3_5_jq(document).ready(function($) { $(#eds_sliderM519).chameleonSlider_2_1({ content_source:......
10/02/2026
NEW YORK February 10, 2026 Nielsen's Gracenote, the global leader in entertainment metadata, today announced the continuation of its partnership with Go...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Clear dialogue has long been one of the biggest pain points in post-production. From complex mixes to unpredictable playback environments, intelligibility somet...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
10/02/2026
10 Feb 2026
VEON's Kyivstar Expands Digital Healthcare Services in Ukraine ...
10/02/2026
The new TV campaign is set to air on Sky from 10th February - 6th April inviting...
10/02/2026
Red Seat Ventures Acquires Leading Podcast Subscription Platform Supercast Los Angeles, CA, February 10, 2026 - Red Seat Ventures, a division of Fox Corporati...
10/02/2026
Arvato Systems Celebrates a Decade of Innovation and Customer Success in the Dig...
09/02/2026
A look inside the tech, tools, and team that make the Super Bowl into true eye c...
09/02/2026
Software-defined IP backbone and centralized signal-control hub redefine champio...
09/02/2026
Broadcasters continue to raise the bar when it comes to producing an eye-catchin...
09/02/2026
Game coverage will feature nearly 100 cameras, a deep well of replay channels, a...
09/02/2026
Sony's imaging tech is the literal lens through which the spectacle and exc...
09/02/2026
The technologies, including AI, allow fans at home to see the athletes, feel' the speed, and sense the skill
With four years from one Winter Games to the ...
09/02/2026
Sportradar AG announces a multi-year agreement with NBC Sports Regional Sports N...
09/02/2026
New York Festivals Advertising Awards proudly unveils a dynamic new Sports Category Group, expanding its 2026 competition to recognize the powerful role sports ...
09/02/2026
Devlin Design Group, Filmwerks, LTN pitched in on the four-day effort
The site ...
09/02/2026
Despite the game taking place right in the middle of NBC Sports' busiest month ever, its production and operations teams pulled off a massive Super Bowl LX ...
09/02/2026
SBS Media Sustainability Challenge returns for 2026
9 February, 2026
Media releases
The challenge offers brands and agencies $500,000 in advertising invent...
09/02/2026
The National Film and Video Foundation (NFVF), an agency of the Department of Sport, Arts, and Culture and custodian of the SAFTAs, is calling on all South Afri...
09/02/2026
The National Film and Video Foundation (NFVF), an agency of the Department of Sp...
09/02/2026
The National Film and Video Foundation (NFVF) is pleased to announce that the call for training provider submissions is open. This funding aims to award grants ...
09/02/2026
Two multi-role L3Harris products - the Red Wolf launched effects vehicle and Sk...
09/02/2026
The L3Harris Key Management System is the first solution on the open market - and available to NATO customers today - that allows countries to create their own ...