%3Aquality(100)&w=3840&q=75)
NIS2 Directive
What Is the NIS2 Directive?
The NIS2 Directive (Directive (EU) 2022/2555) is the European Union's cybersecurity legislation that establishes stronger cybersecurity and resilience requirements for organizations providing essential and important services. The directive expands the scope of the original Network and Information Systems (NIS) Directive and introduces enhanced requirements for cyber risk management, incident reporting, supply chain security, business continuity, and executive accountability.
Built on a risk-based framework, the NIS2 Directive focuses on preventing cyber incidents, detecting threats early, responding effectively, and recovering quickly to maintain essential operations. The directive reflects the growing importance of cybersecurity in protecting essential services, economic stability, and national resilience.
NIS2 Scope and Coverage
The NIS2 Directive significantly expands the range of organizations subject to cybersecurity obligations. It applies to public and private entities operating in sectors that support critical services and societal functions, including:
Energy
Transportation
Banking
Financial market infrastructures
Healthcare
Drinking water
Wastewater management
Digital infrastructure
Public administration
Space services
Postal and courier services
Waste management
Food production and distribution
Chemicals
Manufacturers of critical products
Digital service providers, including online marketplaces and search engines
NIS2 applies primarily to medium-sized and large organizations, while smaller entities may also fall within scope when they provide critical services or present elevated risk. Since entering into force on January 16, 2023, the directive has moved from policy to implementation, with EU Member States required to transpose it into national law by October 17, 2024. Organizations must now consider the requirements set by their national legislation and align their cybersecurity programs with evolving regulatory and supervisory expectations.
Why NIS2 Matters
The NIS2 Directive strengthens cybersecurity across services and infrastructure that citizens, businesses, and governments depend upon every day. Its purpose extends beyond regulatory compliance to support operational resilience, public trust, and continuity of mission-critical functions under the NIS2 Directive.
A single cybersecurity incident can disrupt essential services, expose sensitive information, and create impacts that extend far beyond the initial breach. The NIS2 Directive helps organizations strengthen their resilience against these risks, enabling them to respond more effectively to cyber threats and maintain critical operations when disruptions occur.
Key benefits include:
Improved resilience across critical services and digital infrastructure
More consistent cybersecurity standards across EU Member States
Faster and more coordinated incident reporting and response
Stronger oversight of third-party suppliers and service providers
Clear accountability for executive leadership and governing bodies
Better alignment with established cybersecurity frameworks and resilience practices
For multinational organizations, the NIS2 Directive helps reduce regulatory fragmentation while supporting a more consistent approach to cyber risk management across European operations.
NIS2 Requirements
Risk Management and Incident Response
The NIS2 Directive requires organizations to implement documented cybersecurity programs capable of preventing, detecting, responding to, and recovering cyber incidents.
Core program elements include:
Formal cybersecurity governance structures
Incident response procedures and escalation paths
Business continuity and disaster recovery planning
Vulnerability management programs
Security monitoring and threat detection capabilities
Supply chain risk management processes
Regular testing and continuous improvement activities
Incident reporting is a central requirement. Organizations must establish processes for identifying, assessing, documenting, and reporting significant incidents to designated authorities within timelines defined by national legislation. Depending on national requirements, reporting may include early warnings, incident notifications, and final reports covering impact, root cause, and remediation.
A strong response also depends on effective coordination throughout an incident. Security teams need to communicate with operational leaders and relevant external parties as events unfold. Secure communications can help teams share critical information and make timely decisions while maintaining the response.
Security Controls and Resilience Measures
The NIS2 Directive requires security measures that are proportionate to organizational risk while supporting operational continuity and resilience.
Common control areas include:
Identity and access management
Multi-factor authentication
Encryption for data in transit and at rest
Network segmentation
Endpoint security
Continuous monitoring and threat detection
Centralized logging and audit trails
Backup and recovery capabilities
Vulnerability management
Secure communications for incident coordination and crisis response
Together, these controls help organizations strengthen resilience while reducing the operational impact of cyber incidents.
Supply Chain Security
Supply chain risk management is a major focus of the NIS2 Directive. Organizations are expected to evaluate and monitor the cybersecurity posture of suppliers, contractors, managed service providers, cloud providers, and other third parties that support critical operations.
Key practices include:
Third-party security assessments
Supplier due diligence processes
Contractual cybersecurity requirements
Ongoing supplier monitoring
Verification of security controls
Review of software and technology risks
These measures help reduce the likelihood of supply chain-related disruptions and strengthen overall organizational resilience.
Documentation and Accountability
The NIS2 Directive requires organizations to maintain evidence demonstrating the effectiveness of cybersecurity controls and governance activities.
Examples include:
Risk assessments
Security policies and procedures
Incident records
Audit findings
Corrective action plans
Business continuity documentation
Training records
Third-party assessment results
Maintaining accurate and accessible records supports regulatory reviews and demonstrates ongoing commitment to cybersecurity governance and operational resilience. Many organizations align NIS2 initiatives with established frameworks such as ISO/IEC 27001, ISO 22301, and the NIST Cybersecurity Framework to strengthen governance, support risk management activities, and streamline compliance efforts.
Implementing the NIS2 Directive
Effective NIS2 implementation requires more than meeting individual security requirements. Organizations need a structured approach that connects cybersecurity governance, risk management, operational resilience, and incident response across the organization
Organizations preparing for or maintaining alignment with the NIS2 Directive commonly focus on the following priorities:
Identifying in-scope entities, systems, and services
Establishing executive ownership and governance structures
Conducting cybersecurity risk assessments
Developing incident response and reporting procedures
Implementing continuous monitoring capabilities
Strengthening identity and access management controls
Establishing secure communication channels for incident management and crisis coordination
Improving supply chain risk management practices
Validating backup and recovery processes
Maintaining audit-ready documentation
Performing regular exercises and resilience testing
A structured approach helps strengthen cyber resilience, improve operational readiness, and support ongoing alignment with NIS2 Directive requirements and national implementing legislation.
%3Aquality(100)&w=3840&q=75)
BlackBerry for Secure Communications
For Environments Where Failure Isn’t an Option
BlackBerry Secure Communications is the leading solution that delivers unmatched expertise to protect the world’s most critical communications.
Explore BlackBerry Secure Communications solutions