Skip to main content
Category: Regulatory & Legal Obligations

NIS2 Directive

Also known as: NIS2, Network and Information Security Directive 2, Directive (EU) 2022/2555, NIS 2 Directive
Simply put

The NIS2 Directive is a European Union cybersecurity law that sets baseline security and incident reporting requirements for organizations operating in critical sectors across the EU. It is the second, updated version of the earlier NIS Directive and is designed to raise the overall level of cybersecurity throughout the Union. It works by setting a common legal framework that individual EU Member States must translate into their own national laws.

Formal definition

The NIS2 Directive, formally Directive (EU) 2022/2555, is EU legislation that replaces the original NIS Directive (Directive (EU) 2016/1148) and establishes a unified legal framework for cybersecurity across critical sectors within the European Union. As a directive rather than a regulation, it obligates Member States to transpose its provisions into national law, meaning specific implementation details, enforcement, and supervisory arrangements may vary by jurisdiction. It expands the scope of covered entities and imposes obligations in areas such as cybersecurity risk management and incident reporting; the evidence provided here does not specify the full set of covered sectors, penalties, deadlines, or technical control requirements, and those should be confirmed against the directive text and applicable national transposition. Note that a virtual or fractional CISO engagement may support readiness for NIS2 obligations, but legal accountability for compliance typically remains with the client organization and its officers, and the applicability of NIS2 to a given entity should be assessed against the relevant national law.

Why it matters

NIS2 represents a significant shift in how the European Union approaches cybersecurity across its critical sectors. As the second iteration of the Network and Information Security Directive, it replaces the original NIS Directive and aims to establish a higher and more consistent baseline of cybersecurity across the Union. According to the European Commission, it establishes a unified legal framework covering 18 critical sectors, which broadens the population of organizations that must take cybersecurity risk management and incident reporting seriously. For organizations operating in or serving these sectors, the practical effect is that cybersecurity moves from being a discretionary technical concern to a legal obligation tied to how a business governs itself.

The directive matters to security leaders because it reframes cybersecurity as a governance and business risk issue rather than a purely technical one. NIS2 introduces stricter requirements for risk management and incident reporting, which means executives and boards, not just IT teams, may bear responsibility for how an organization prepares for and responds to cyber incidents. Because NIS2 is a directive rather than a regulation, each EU Member State must transpose it into national law, so the specific enforcement mechanisms, deadlines, and supervisory arrangements can differ by jurisdiction. This creates real complexity for organizations operating across multiple Member States, since the version of NIS2 that applies to them is ultimately the national law that implements it.

A common and consequential mistake is assuming that engaging external security leadership transfers accountability for NIS2 compliance. It does not. A virtual or fractional CISO can support readiness for NIS2 obligations, but legal accountability for compliance typically remains with the client organization and its officers. Organizations should therefore treat NIS2 readiness as an ongoing governance responsibility rather than a one-time project that can be fully outsourced.

Who it's relevant to

Organizations in EU critical sectors
Entities operating in the critical sectors covered by NIS2 are directly affected, since the directive imposes cybersecurity risk management and incident reporting obligations. Because scope is defined through national transposition laws, these organizations should confirm whether and how NIS2 applies to them against the applicable national law rather than assuming coverage or exemption.
Executives, boards, and officers
NIS2 reframes cybersecurity as a governance and business risk matter, which places responsibility beyond the IT function. Legal accountability for compliance typically rests with the organization and its officers, so leadership cannot treat NIS2 as a purely technical concern to be delegated entirely to a security team or an external advisor.
Virtual and fractional CISOs
A virtual or fractional CISO can support NIS2 readiness by helping assess applicability, aligning risk management and incident reporting practices with the directive's expectations, and advising on governance. However, this is a strategy and advisory role; the value of such an engagement depends on organizational maturity, client cooperation, and access to stakeholders, and accountability for compliance remains with the client.
Organizations operating across multiple Member States
Because NIS2 is transposed into national law by each Member State, implementation details, enforcement, and supervisory arrangements may vary by jurisdiction. Multinational organizations should account for these differences and confirm obligations against each relevant national transposition rather than assuming a single uniform standard across the EU.

Inside NIS2

Expanded Scope of Covered Entities
The NIS2 Directive broadens the range of organizations subject to cybersecurity obligations compared with the original NIS Directive, typically distinguishing between 'essential' and 'important' entities across sectors such as energy, transport, health, digital infrastructure, and certain digital service providers. The precise classification and applicability depend on national transposition and entity-specific criteria, so organizations should confirm their status against the implementing law in each relevant EU member state.
Risk Management Measures
NIS2 requires in-scope entities to adopt appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. These commonly include areas such as risk analysis, incident handling, business continuity, supply chain security, and access control. The directive frames these as governance and risk obligations rather than prescribing specific tools, meaning implementation detail is left to the organization within the bounds of national law.
Incident Reporting Obligations
The directive establishes reporting duties for significant incidents, typically involving notification to designated national authorities or CSIRTs within defined timeframes. Reporting requirements and thresholds may vary by member state transposition, so organizations should verify the applicable deadlines and formats in their jurisdiction rather than assuming a single uniform standard.
Management Body Accountability
NIS2 places explicit emphasis on the responsibility of an entity's management or governing body for approving and overseeing cybersecurity risk management measures. This reflects the treatment of security as a governance and business risk function. Note that this accountability generally rests with the client organization's officers and leadership, not with any external advisor engaged to support the effort.
Supervision and Enforcement
The directive provides for supervisory mechanisms and the possibility of enforcement actions and penalties for non-compliance, with specifics determined through national transposition. The nature, scale, and application of any penalties depend on the implementing legislation and the relevant supervisory authority.
Supply Chain and Third-Party Security
NIS2 highlights the importance of addressing risks arising from supply chains and relationships with suppliers and service providers. In-scope entities are typically expected to consider third-party security as part of their overall risk management posture.

Common questions

Answers to the questions practitioners most commonly ask about NIS2.

Does hiring a virtual CISO make my organization compliant with NIS2?
No. A virtual CISO can support NIS2 readiness by advising on governance, risk management measures, and reporting obligations, but engaging a vCISO does not by itself make an organization compliant. Compliance depends on the organization actually implementing required measures, and legal accountability for meeting NIS2 obligations typically remains with the organization and its management body rather than transferring to the vCISO.
Is a virtual CISO the same as a managed security service provider for NIS2 purposes?
No. These are commonly conflated, but they serve different functions. A managed security service provider generally delivers operational services such as monitoring or tool administration. A virtual CISO provides strategy, governance, and executive-level guidance, including advising on how NIS2 obligations map to your risk management and reporting processes. A vCISO typically does not perform the hands-on operational tasks an MSSP would, unless explicitly contracted, so the two roles may be complementary rather than interchangeable.
How can a virtual CISO help my organization prepare for NIS2 obligations?
In many engagements, a virtual CISO helps assess where current practices stand against the directive's expectations for risk management and governance, advises on prioritizing gaps, and supports the development of policies and reporting processes. The value delivered often depends on organizational maturity, access to relevant stakeholders, and a clearly defined scope of engagement.
Can a virtual CISO fulfill the management accountability that NIS2 places on leadership?
Generally no. A virtual CISO can advise the management body and help leaders understand their obligations, but the directive typically directs accountability toward the organization's management. A vCISO advises and directs within the agreed scope; the underlying accountability usually stays with the client organization and its officers unless a specific contractual arrangement states otherwise.
What is typically out of scope when a virtual CISO supports NIS2 readiness?
A virtual CISO engagement focused on NIS2 typically centers on strategy, governance, and risk management guidance. Hands-on operational tasks such as SOC monitoring, security tool administration, or executing incident response are generally out of scope unless explicitly contracted. Clarifying these boundaries in the engagement agreement helps set realistic expectations.
What determines how effectively a virtual CISO can support NIS2 efforts?
Effectiveness often varies by provider and engagement model. Outcomes commonly depend on the clarity of scope, the organization's existing security maturity, the level of client cooperation, and the vCISO's access to decision-makers and relevant documentation. Engagement structure may also differ across vCISO, fractional, and interim arrangements, which can affect availability and depth of involvement.

Common misconceptions

Engaging a virtual CISO makes an organization compliant with NIS2, or transfers NIS2 accountability to the advisor.
A virtual CISO can support readiness, help interpret obligations, and guide the development of risk management and governance measures, but accountability under NIS2 typically remains with the entity's management body and officers. An advisory engagement does not guarantee compliance and does not shift legal or regulatory accountability unless a contract specifies otherwise.
NIS2 applies uniformly across the EU with identical rules everywhere.
NIS2 is a directive that requires transposition into national law, so specific thresholds, reporting timeframes, penalties, and entity classifications may vary by member state. Organizations should verify the applicable requirements in each jurisdiction where they operate rather than assuming a single harmonized standard.
A virtual CISO supporting NIS2 will operationally handle incident detection, monitoring, and response.
A virtual CISO typically provides strategy, governance, and program-level guidance around risk management and reporting obligations. Hands-on operational tasks such as SOC monitoring or executing incident response are generally out of scope unless explicitly contracted, and are often delivered by other providers or internal teams.

Best practices

Confirm your organization's status under the applicable national transposition of NIS2 before assuming scope, since classification as an essential or important entity depends on jurisdiction-specific criteria.
Engage the management or governing body early, because NIS2 places accountability at the leadership level and treats cybersecurity as a governance and business risk matter rather than a purely technical one.
Map existing risk management measures against the areas emphasized by NIS2, such as incident handling, business continuity, and supply chain security, to identify gaps within the bounds of the relevant national law.
Establish and document incident reporting processes aligned to the notification thresholds and timeframes defined in your applicable jurisdiction, and verify these details rather than relying on a single assumed standard.
Clarify engagement scope when using a virtual CISO for NIS2 support, distinguishing advisory and program-development work from operational tasks, and confirm that accountability remains with the organization's officers unless contractually agreed otherwise.
Address third-party and supplier risk explicitly as part of the overall security program, since NIS2 highlights supply chain security as a component of risk management.