Skip to main content
Hero background

NIS2 Directive

What Is the NIS2 Directive?

The NIS2 Directive (Directive (EU) 2022/2555) is the European Union's cybersecurity legislation that establishes stronger cybersecurity and resilience requirements for organizations providing essential and important services. The directive expands the scope of the original Network and Information Systems (NIS) Directive and introduces enhanced requirements for cyber risk management, incident reporting, supply chain security, business continuity, and executive accountability. 

Built on a risk-based framework, the NIS2 Directive focuses on preventing cyber incidents, detecting threats early, responding effectively, and recovering quickly to maintain essential operations. The directive reflects the growing importance of cybersecurity in protecting essential services, economic stability, and national resilience. 

NIS2 Scope and Coverage 

The NIS2 Directive significantly expands the range of organizations subject to cybersecurity obligations. It applies to public and private entities operating in sectors that support critical services and societal functions, including: 

  • Energy 

  • Transportation 

    Banking 

  • Financial market infrastructures 

  • Healthcare 

  • Drinking water 

  • Wastewater management 

  • Digital infrastructure 

  • Public administration 

  • Space services 

  • Postal and courier services 

  • Waste management 

  • Food production and distribution 

  • Chemicals 

  • Manufacturers of critical products 

  • Digital service providers, including online marketplaces and search engines 

NIS2 applies primarily to medium-sized and large organizations, while smaller entities may also fall within scope when they provide critical services or present elevated risk. Since entering into force on January 16, 2023, the directive has moved from policy to implementation, with EU Member States required to transpose it into national law by October 17, 2024. Organizations must now consider the requirements set by their national legislation and align their cybersecurity programs with evolving regulatory and supervisory expectations. 

Why NIS2 Matters

The NIS2 Directive strengthens cybersecurity across services and infrastructure that citizens, businesses, and governments depend upon every day. Its purpose extends beyond regulatory compliance to support operational resilience, public trust, and continuity of mission-critical functions under the NIS2 Directive. 

A single cybersecurity incident can disrupt essential services, expose sensitive information, and create impacts that extend far beyond the initial breach. The NIS2 Directive helps organizations strengthen their resilience against these risks, enabling them to respond more effectively to cyber threats and maintain critical operations when disruptions occur. 

Key benefits include: 

  • Improved resilience across critical services and digital infrastructure 

  • More consistent cybersecurity standards across EU Member States 

  • Faster and more coordinated incident reporting and response 

  • Stronger oversight of third-party suppliers and service providers 

  • Clear accountability for executive leadership and governing bodies 

  • Better alignment with established cybersecurity frameworks and resilience practices 

For multinational organizations, the NIS2 Directive helps reduce regulatory fragmentation while supporting a more consistent approach to cyber risk management across European operations. 

NIS2 Requirements

Risk Management and Incident Response 

The NIS2 Directive requires organizations to implement documented cybersecurity programs capable of preventing, detecting, responding to, and recovering cyber incidents. 

Core program elements include: 

  • Formal cybersecurity governance structures 

  • Incident response procedures and escalation paths 

  • Business continuity and disaster recovery planning 

  • Vulnerability management programs 

  • Security monitoring and threat detection capabilities 

  • Supply chain risk management processes 

  • Regular testing and continuous improvement activities 

Incident reporting is a central requirement. Organizations must establish processes for identifying, assessing, documenting, and reporting significant incidents to designated authorities within timelines defined by national legislation. Depending on national requirements, reporting may include early warnings, incident notifications, and final reports covering impact, root cause, and remediation. 

A strong response also depends on effective coordination throughout an incident. Security teams need to communicate with operational leaders and relevant external parties as events unfold. Secure communications can help teams share critical information and make timely decisions while maintaining the response. 

Security Controls and Resilience Measures 

The NIS2 Directive requires security measures that are proportionate to organizational risk while supporting operational continuity and resilience. 

Common control areas include: 

  • Identity and access management 

  • Multi-factor authentication 

  • Encryption for data in transit and at rest 

  • Network segmentation 

  • Endpoint security 

  • Continuous monitoring and threat detection 

  • Centralized logging and audit trails 

  • Backup and recovery capabilities 

  • Vulnerability management 

  • Secure communications for incident coordination and crisis response 

Together, these controls help organizations strengthen resilience while reducing the operational impact of cyber incidents. 

Supply Chain Security 

Supply chain risk management is a major focus of the NIS2 Directive. Organizations are expected to evaluate and monitor the cybersecurity posture of suppliers, contractors, managed service providers, cloud providers, and other third parties that support critical operations. 

Key practices include: 

  • Third-party security assessments 

  • Supplier due diligence processes 

  • Contractual cybersecurity requirements 

  • Ongoing supplier monitoring 

  • Verification of security controls 

  • Review of software and technology risks 

These measures help reduce the likelihood of supply chain-related disruptions and strengthen overall organizational resilience. 

Documentation and Accountability 

The NIS2 Directive requires organizations to maintain evidence demonstrating the effectiveness of cybersecurity controls and governance activities. 

Examples include: 

  • Risk assessments 

  • Security policies and procedures 

  • Incident records 

  • Audit findings 

  • Corrective action plans 

  • Business continuity documentation 

  • Training records 

  • Third-party assessment results 

Maintaining accurate and accessible records supports regulatory reviews and demonstrates ongoing commitment to cybersecurity governance and operational resilience. Many organizations align NIS2 initiatives with established frameworks such as ISO/IEC 27001, ISO 22301, and the NIST Cybersecurity Framework to strengthen governance, support risk management activities, and streamline compliance efforts. 

Implementing the NIS2 Directive

Effective NIS2 implementation requires more than meeting individual security requirements. Organizations need a structured approach that connects cybersecurity governance, risk management, operational resilience, and incident response across the organization 

Organizations preparing for or maintaining alignment with the NIS2 Directive commonly focus on the following priorities: 

  • Identifying in-scope entities, systems, and services 

  • Establishing executive ownership and governance structures 

  • Conducting cybersecurity risk assessments 

  • Developing incident response and reporting procedures 

  • Implementing continuous monitoring capabilities 

  • Strengthening identity and access management controls 

  • Establishing secure communication channels for incident management and crisis coordination 

  • Improving supply chain risk management practices 

  • Validating backup and recovery processes 

  • Maintaining audit-ready documentation 

  • Performing regular exercises and resilience testing 

A structured approach helps strengthen cyber resilience, improve operational readiness, and support ongoing alignment with NIS2 Directive requirements and national implementing legislation. 

BlackBerry for Secure Communications

For Environments Where Failure Isn’t an Option

BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.

Explore BlackBerry Secure Communications solutions