Ch 10.6 - NIS Directive

The NIS Directive (and NIS 2)

The original NIS Directive advanced EU cybersecurity and complemented the GDPR. NIS2, Directive (EU) 2022/2555, replaced that regime from 18 October 2024. It widens sector coverage, divides covered organisations into essential and important entities, strengthens cybersecurity risk-management and incident-reporting duties, and harmonises maximum fines. Essential entities can face at least €10 million or 2% of worldwide annual turnover, whichever is higher.

The NIS Directive advances the EU's cybersecurity agenda first legislated in 2009. It is not concerned with personal data security as such, but it complements the GDPR and indirectly bolsters the security of personal data held by regulated organisations.

  1. Compel national cybersecurity strategies and structures - establishing national CSIRTs, appointing cybersecurity regulators, and identifying operators of essential services
  2. Improve security of operators of essential services and digital service providers via member-state laws setting security and incident-notification requirements
  3. Enhance cooperation between member states via the NIS Cooperation Group coordinating the CSIRTs and developing best practice
Essential services vs digital service providers
CategoryExamples / sectorsEnforcement model
Operators of essential services (Annex II)Energy, water, transport, health, banking, digital infrastructureRegulators can step in ex ante (before being alerted) as well as ex post
Digital service providers (Annex III)Online marketplaces, search engines, cloud computing (e.g. eBay, Google, Amazon)Regulators can step in only ex post (after being alerted to a breach)

NIS2 requires appropriate and proportionate technical, operational and organisational measures, incident reporting and management accountability. It covers more sectors than the original regime. Article 34 requires maximum fines for essential entities of at least €10 million or 2% of worldwide annual turnover, whichever is higher, and at least €7 million or 1.4% for important entities.

Ex ante vs ex post

Regulators may act ex ante (before being alerted) for operators of essential services, but only ex post (after being alerted) for digital service providers. A neat distinction to remember.

Key terms - quick answers

What is “NIS Directive”?
The Directive on security of network and information systems (also 'Cybersecurity Directive'); advances EU cybersecurity and complements the GDPR.
What is “CSIRT”?
Computer Security Incident Response Team - national teams established under the NIS Directive to handle cyber incidents.
What is “Operators of essential services”?
Entities (Annex II) in energy, water, transport, health, banking and digital infrastructure whose disruption would significantly affect critical activities.
What is “Digital service providers”?
Online marketplaces, online search engines and cloud computing services (Annex III) - e.g. eBay, Google, Amazon.

Sources and study method

This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.