NIS 2: what you need to know about the new european cybersecurity directive
Articles by the same author:
1
2
4
This new version expands the scope of the 2016 NIS Directive, which was previously limited to operators of essential services (OSE) and digital service providers (DSP). Now, more than 10,000 organizations across 18 sectors will be affected, ranging from digital infrastructures to healthcare services, as well as energy and transport.
These entities will be required to meet three main obligations:
These obligations aim to standardize and strengthen resilience against growing cyber threats.
Penalties for non-compliance can reach up to 2% of revenue for entities deemed essential and 1.4% for important entities. However, a three-year grace period is granted to allow businesses to gradually adapt to these new requirements, with full compliance expected by 2027.
To support organizations during this transition, ANSSI offers various tools, including the MonEspaceNIS2 website, which allows businesses to check their compliance and stay informed of updates related to the directive.