NIS Directive and NIS 2
The original NIS Directive, adopted on 6 July 2016, was the first EU-wide cybersecurity law. The NIS2 Directive, Directive (EU) 2022/2555, replaced it from 18 October 2024. NIS2 widens sector coverage, separates covered organisations into essential and important entities, strengthens cyber-risk and incident-reporting duties, and harmonises maximum fine levels.
The NIS Directive is the first piece of EU-wide cybersecurity legislation, adopted 6 July 2016 and in force from August 2016. Member states had to transpose it by 9 May 2018 and identify operators of essential services by 9 November 2018.
- National capabilities: each state sets up a CSIRT and a competent national NIS authority
- EU cooperation: a cooperation group and a CSIRT network for sharing risk information
- Risk management & reporting: by OES (energy, transport, water, banking, financial market infrastructure, health, digital infrastructure) and DSPs (search engines, cloud, online marketplaces)
| Aspect | NIS Directive | NIS2 Directive |
|---|---|---|
| Status | 6 July 2016 | Adopted 14 December 2022 |
| Scope | OES + DSPs | Widened to more sectors |
| Security & reporting | Baseline rules | Strengthened |
| Fines | Set nationally | Increased maximum fines |
| Transposition | By 9 May 2018 | Member State transposition deadline 17 October 2024 |
The NIS Directive is the first EU-wide cybersecurity legislation. Each member state identifies the companies it covers and the exact form it takes - another source of national variation.
Key terms - quick answers
What is “NIS Directive”?
What is “CSIRT”?
What is “Operators of essential services”?
What is “Digital service providers”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.