The NIS Directive (and NIS 2)
The original NIS Directive advanced EU cybersecurity and complemented the GDPR. , Directive (EU) 2022/2555, replaced that regime from 18 October 2024. It widens sector coverage, divides covered organisations into essential and important entities, strengthens cybersecurity risk-management and incident-reporting duties, and harmonises maximum fines. Essential entities can face at least €10 million or 2% of worldwide annual turnover, whichever is higher.
The NIS Directive advances the EU's cybersecurity agenda first legislated in 2009. It is not concerned with personal data security as such, but it complements the GDPR and indirectly bolsters the security of personal data held by regulated organisations.
- Compel national cybersecurity strategies and structures - establishing national , appointing cybersecurity regulators, and identifying operators of essential services
- Improve security of operators of essential services and digital service providers via member-state laws setting security and incident-notification requirements
- Enhance cooperation between member states via the NIS Cooperation Group coordinating the CSIRTs and developing best practice
| Category | Examples / sectors | Enforcement model |
|---|---|---|
| Operators of essential services (Annex II) | Energy, water, transport, health, banking, digital infrastructure | Regulators can step in ex ante (before being alerted) as well as ex post |
| Digital service providers (Annex III) | Online marketplaces, search engines, cloud computing (e.g. eBay, Google, Amazon) | Regulators can step in only ex post (after being alerted to a breach) |
requires appropriate and proportionate technical, operational and organisational measures, incident reporting and management accountability. It covers more sectors than the original regime. Article 34 requires maximum fines for essential entities of at least €10 million or 2% of worldwide annual turnover, whichever is higher, and at least €7 million or 1.4% for important entities.
Regulators may act ex ante (before being alerted) for operators of essential services, but only ex post (after being alerted) for digital service providers. A neat distinction to remember.
Key terms - quick answers
What is “NIS Directive”?
What is “CSIRT”?
What is “Operators of essential services”?
What is “Digital service providers”?
Sources and study method
This independent lesson uses active recall, spaced retrieval and scenario practice. Read the full study method.