IAPP Training, Module 9 - BoK II.B
Module 9, The NIS and NIS2 Directives
The original NIS Directive was the first EU-wide cybersecurity law. The NIS2 Directive entered into force on 16 January 2023. Member States had to transpose it by 17 October 2024, and it replaced the original regime from 18 October 2024. Subject to defined exceptions, it covers medium and large entities, separates them into essential entities and important entities, expands sectors and provides for a European Vulnerability Database maintained by ENISA.
| Focus | What it does |
|---|---|
| National capabilities | Compel Member State cybersecurity strategies/structures |
| Cross-border collaboration | Enhance cooperation between Member States |
| National supervision of critical sectors | Improve security of essential services and digital service providers |
- The NIS2 Directive entered into force on 16 January 2023 and Member States had to transpose it by 17 October 2024.
- New classifications - essential entities (energy, banking, health, drinking water) and important entities (waste management, food, medical devices, electronics).
- Expands covered sectors; modifies breach notification; adds voluntary coordinated vulnerability disclosure.
- Provides the European Vulnerability Database (EUVD), maintained by ENISA.
Key terms - quick answers
What is “NIS Directive”?
The first EU-wide cybersecurity law, in force May 2018; aligns with and bolsters GDPR security but is not specifically about personal data.
What is “NIS2 Directive”?
Directive (EU) 2022/2555, in force from 16 January 2023 with a 17 October 2024 transposition deadline.
What is “Essential entities”?
NIS2 category covering energy, banking, health and drinking water.
What is “Important entities”?
NIS2 category covering waste management, food, medical devices and electronics.
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.