NIS2

European and national legislation on the cyber security of organisations

The new European directive Network and Information Security Directive 2 (NIS2) became effective in European Union (EU) legislation on 17 October 2024. The new directive imposes significant requirements on levelling up the cybersecurity capabilities of organisations in various sectors that are characterised as essential or important.

NIS2 enhances EU network and information systems security by requiring critical infrastructure operators to implement a minimum set of cybersecurity standards and report on cyber incidents. It expands NIS's scope, covering more organisations and industries, and its objective is to improves supply chain security, streamline reporting, and enforce stricter measures and sanctions across Europe for a safer and more secure Europe.

These mandatory, risk-based cybersecurity standards can effectively contribute to a stronger cybersecurity security posture for organisations who adopt and adhere to the standards, many of which are likely part of an established cybersecurity policy. Failure to comply with these mandatory standards may result in significant fines.

BDO has developed an easy-to-use NIS2 assessment tool to simplify the process for you, and provide you with insight into your current state almost immediately. You can access this tool by clicking the button below. Please feel free to enter your information and speak with one of our cybersecurity NIS2 specialists who will be happy to help you on your journey. 


NIS2 image


NIS2 image


NIS2 image

How it works

As NIS2 is not equally applicable to everyone, we offer a brief overview of this European Directive on Network and Information Security. We explain the essence of NIS2 and who it is important for. Discover the requirements and best practices for compliance with NIS2.

What is it for?

The NIS2 imposes security requirements that are grouped under duty of care, reporting obligation, and supervision, and are already relatively concrete before they are formalised in national legislation. These include, among others, the concrete lists of measures from Article 21 and the significant fines from Article 34 (4). Read more in the directive: EUR-Lex – 32022L2555 (europa.eu). In addition, there are a number of other notable elements such as security in the supply chain, responsibility of management bodies, and training obligations.

Where do you stand?

To ensure that your organisation is ready for these legal cybersecurity requirements in time, it is important to start with the right preparations now. Although the requirements have not yet been formalised in national legislation, it is clear which direction it is heading, and the parallels with existing frameworks and good practices such as ISO 27001.

Run the NIS2 Analyzer now and get a first impression of where you are today.

For whom does it apply?

Organisations that will fall under the new European directive Network and Information Security Directive 2 (NIS2) include energy companies, airlines, water companies, digital service providers, government agencies, and their suppliers. To check if your organisation falls under this directive, it is recommended that you consult information from your local government. If you have any questions, please feel free to contact us for expert advice and support.

Which type of organisations does it impact?

The NIS2 directive is aimed at more types of companies and organisations than the first NIS directive. This means that there are now more public and private organisations that must comply with the rules.

The organisations now covered by the NIS2 directive include:

  • Energy
  • Transport
  • Banking
  • Infrastructure financial market
  • Healthcare
  • Drinking water
  • Digital infrastructure
  • ICT-service providers
  • Wastewater
  • Government services
  • Space
  • Digital service providers
  • Postal and courier services
  • Waste management
  • Food production
  • Chemicals
  • Research
  • Manufacturing

Essential entities 

These are large organisations that are active in a sector from Annex I of the NIS2 directive.

An organisation is considered large based on the following criteria:

  • at least 250 employees; 
  • an annual turnover of more than €50 million and a balance sheet total of more than €43 million.

Important entities 

These are medium-sized organisations that are active in a sector from Annex I and medium and large organisations that are active in a sector from Annex II.

An organisation is considered medium-sized based on the following criteria:

  • at least 50 employees; or 
  • an annual turnover and balance sheet total of more than €10 million.