From NIS to NIS 2

A major step forward in protecting networks and information systems.

Guillaume Alliel · 10 min read
Illustration: two glass rings, an old one and a larger new one
NIS · 2016
OESDSP
NIS 2 · 2022
EE IE + SECTORS
01

What is NIS 2?

NIS 2, or Network and Information Security 2, is the new version of the European directive aimed at strengthening the security of networks and information systems within the member states of the European Union, adopted on 10 November 2022.

A. What is a directive?

First of all, it is important to stress that NIS 2 is a directive and not a regulation. A regulation is meant to be uniform across countries and applies directly as soon as it has been adopted by the Council of the EU or the European Parliament and published in the Official Journal of the EU. The purpose of a directive, on the other hand, such as NIS 2 or Network and Information Security, version 2, is to promote the harmonisation of national laws by setting out general principles and objectives, while leaving member states a certain degree of freedom in how they apply the text. Each state is free to go beyond these principles. The directive must be transposed into national law through a vote in national parliaments, within the set deadlines. (1)

REGULATION Uniform, directly applicable once adopted and published in the OJ of the EU
EUROPEAN UNION Regulation Adoption, then publication in the OJ of the EU
MEMBER STATE 1 APPLICABLE
MEMBER STATE 2 APPLICABLE
MEMBER STATE 3 APPLICABLE
DIRECTIVE Mandatory transposition through a vote in national parliaments, within the set deadlines
EUROPEAN UNION Directive General principles and objectives
MEMBER STATE 1 TRANSPOSED
MEMBER STATE 2 TRANSPOSED
MEMBER STATE 3 GOES FURTHER

B. Background: the NIS Directive and its evolution into NIS 2

FROM NIS TO NIS 2 2016 → 2022
  1. July 2016 1st NIS adoption
  2. End of 2020 Impact assessment for the revision of NIS (the EU's obligation to assess the directive's impact)
  3. November 2022 Adoption of the NIS 2 Directive
Deadline: months

Transposition of the directive into domestic law at national level must be completed within 21 months of its entry into force.

C. Why protecting networks and information systems matters

The digital transformation of European societies and the interconnection of member states have exposed the European market to new cyber threats.

says Yves Verhoeven, Deputy Director for Strategy at ANSSI.

This increased interconnectivity means that attacks and security flaws spread faster and more widely, endangering critical infrastructure, sensitive data and information systems across the European Union.

Faced with this reality, it is imperative that member states work together to ensure:

  • adequate security conditions throughout the European Union;
  • the identification of common vulnerabilities;
  • the sharing of information on threats;
  • the implementation of effective prevention and response measures.
2 · MEMBER STATES WORK TOGETHER EUROPEAN UNION
Member State PROTECTED
Member State PROTECTED
Member State PROTECTED
Member State PROTECTED
Member State PROTECTED
COMMON OBJECTIVES
Adequate security across the EUCommon vulnerabilitiesThreat sharingPrevention and response

For example, in February 2022, the European Union suffered a cyberattack on the KA-SAT satellite network, and then accused Russia of being behind it. (2) The attack deprived businesses, public institutions and also civilians of internet access. “This unacceptable cyberattack is a further example of the irresponsible activities Russia is conducting in cyberspace, and an essential component of its illegal and unjustified invasion of Ukraine,” the EU declared. (3)

INCIDENT · FEBRUARY 2022 Cyberattack on the KA-SAT satellite network The EU accuses Russia of being behind it
  • Businesses NO INTERNET ACCESS
  • Public institutions NO INTERNET ACCESS
  • Civilians NO INTERNET ACCESS

To fully understand the stakes and objectives of NIS 2, it is necessary to go back to the origins of this directive and understand why NIS (Network and Information Security) was introduced in 2016.

02

What is the NIS Directive?

A. Objectives of NIS 1

The main objective of NIS 1, introduced in 2016, was to raise the overall level of cybersecurity and cyber resilience within the European Union (4). To achieve this, the aim was to:

  • create consistency in cybersecurity across member states, making sure they are properly protected against cyber threats and can benefit from other countries' best practices;
  • optimise communication and information sharing while raising their awareness, in order to strengthen the collective capacity to counter attacks;
  • enable some more advanced countries to promote a culture of cybersecurity, by leading by example and highlighting the importance of taking this dimension into account.

NIS 1 was therefore a strategy of collaboration and cooperation between EU member states. Some more advanced countries played a role in promoting a culture of cybersecurity, by leading by example and highlighting the importance of taking this dimension into account.

B. Overview of the main elements of the NIS 1 Directive

When the NIS Directive was introduced, two specific sectors were covered: operators of essential services (hereinafter “OES”) and digital service providers (hereinafter “DSP”).

OES (5) are entities operating in essential sectors such as energy, transport, health, banking, financial services and critical digital infrastructure. These operators are subject to stricter security obligations because of the importance of their services to the proper functioning of society and the economy.

By contrast, DSPs (6) cover a broader range of digital services, such as online services, cloud computing services, electronic payment services, search engines, online marketplaces, etc.

DSPs are subject to security requirements proportionate to the nature and importance of the digital services they provide.

NIS 1 · OESESSENTIAL SECTORS
Operators of essential services
  • Energy
  • Transport
  • Health
  • Banking services
  • Financial services
  • Critical digital infrastructure
Level of requirementsStricter obligations
NIS 1 · DSPDIGITAL SERVICES
Digital service providers
  • Online services
  • Cloud computing
  • Electronic payment
  • Search engines
  • Online marketplaces
  • etc.
Level of requirementsProportionate to the service

The introduction of NIS (the directive on the security of network and information systems) improved and consolidated the overall level of cybersecurity across Europe by helping to:

  • reduce the risk of cyberattacks;
  • better protect essential infrastructure and sensitive data;
  • raise awareness of the importance of cybercrime issues;
  • develop greater digital sovereignty.

The consultancy Wavestone carried out a study covering the 27 countries of the European Union plus Switzerland and the United Kingdom; 79% of these states had put in place a state supervision process. In addition, the directive established common security requirements, which makes cooperation and coordination between EU member states easier and makes these standards consistent. (7)

of the states studied had put in place a state supervision process WAVESTONE STUDY · 27 EU COUNTRIES + SWITZERLAND + UNITED KINGDOM

The directive provided for the creation of three entities:

  1. 01 STRATEGIC
    NIS Cooperation Group Coordination between member states and stronger strategic cooperation
  2. 02 OPERATIONAL
    CSIRT network The national teams that manage and coordinate the response to cybersecurity incidents
  3. 03 CRISIS MANAGEMENT
    EU-CyCLONe Cooperation between national cybersecurity crisis management authorities 2020 · FORMALISED IN JAN. 2023
COMMON OBJECTIVE CooperationCoordinationInformation sharing between EU member states

1.NIS Cooperation Group (Network and Information Security Cooperation Group)

It enables coordination between the member states of the European Union on cybersecurity. Its main objective is to strengthen strategic cooperation between member states, in order to optimise information sharing and thereby raise the overall level of cybersecurity maturity. (8)

2.CSIRT network (Computer Security Incident Response Team)

It refers to a network of the Computer Security Incident Response Teams of EU member states. These teams are responsible for managing and coordinating the response to cybersecurity incidents at national level. The CSIRT network aims to “contribute to building trust between member states and [to] promote swift and effective operational cooperation”. (9)

3.EU-CyCLONe

It is a cooperation network between the national authorities responsible for cybersecurity crisis management in EU member states, launched in 2020 and formalised in January 2023 with NIS 2. It aims to foster information sharing and situational awareness, in collaboration with the European Union Agency for Cybersecurity. (10)

The objective of these three entities is to promote cooperation, coordination and information sharing on cybersecurity between EU member states.

03

The fundamental reasons behind the introduction of the NIS 2 Directive

On 17 June 2022, the Council of the European Union and the European Parliament jointly published the draft revision of NIS, prompted by its limitations, which included:

  • a scope that was too narrow regarding the sectors required to comply with the directive;
  • countries had too much freedom in implementing the directive at national level, which led to inconsistent application across Europe.

To address these problems, NIS 2 was developed with significant improvements and a broader scope, including:

LIMITATIONS OF NIS 1
01 Scope too narrow
02 Too much national freedom, inconsistent application
Draft revision published17 JUNE 2022
NIS 2 · IMPROVEMENTS
  • Inclusion of new sectors and entities
  • Consideration of supply chain security
  • Implementation of a security policy
  • Carrying out risk analyses
  • Introduction of monitoring measures
  • Incident and risk management
  • Harmonised and stronger penalties in all member states

These measures aim to ensure better coordination, a more effective response to cybersecurity incidents and stronger protection against cyber threats. NIS 2 seeks to establish more consistent cybersecurity standards across the European Union, thereby encouraging a collaborative approach and robust protection of networks and information systems.

The NIS 2 Directive also sets out two types of penalties (11) to ensure that cybersecurity obligations are met:

TYPE 1 · ADMINISTRATIVE FINES
Essential entitiesor 2% of total worldwide annual turnover
Important entitiesor 1.4% of total worldwide annual turnover
TYPE 2 · MANAGEMENT LIABILITY
Executives LIABLE
Senior managers LIABLE
Held liable for cybersecurity breaches

1.Heavy administrative fines with set amounts

Entities that fail to meet the security obligations laid down by the directive may face substantial administrative fines. These fines are set at a significant level, reaching up to €10 million or 2% of total worldwide annual turnover for essential entities, in order to deter negligent or non-compliant behaviour, and €7 million or 1.4% of total worldwide annual turnover for important entities.

2.Management liability

This means that executives and senior managers can be held liable for cybersecurity breaches, which encourages them to pay particular attention to implementing security measures and protecting networks and information systems.

04

Who does the NIS 2 Directive apply to?

NIS 2 introduces new players and criteria in order to optimise this directive and strengthen European cybersecurity. The previous definitions of operators of essential services (“OES”) (12) and digital service providers (“DSP”) are replaced respectively by the terms “essential entity” (hereinafter “EE”) and “important entity” (hereinafter “IE”), in order to adapt obligations to each entity.

The sectors covered by NIS 2
EEs cover: EE · FORMER OES
  • Energy
  • Transport
  • Banking
  • Financial market infrastructure
  • Health
  • Drinking water and waste water
  • Digital infrastructure (cloud computing service providers, data centres, DNS, etc.)
  • ICT service management (business-to-business)
  • Public administration
IEs include: IE · FORMER DSP
  • Postal services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacture of medical devices and in vitro diagnostic medical devices
  • Manufacture of computer, electronic and optical products
NIS 2 · SECTORS 15 sectors split between two types of entity
Essential entities9
Important entities6
ESSENTIAL ENTITIES 9 sectors · EE They replace the operators of essential services (OES) under NIS 1.
IMPORTANT ENTITIES 6 sectors · IE They replace the digital service providers (DSP) under NIS 1.
Choose an entity type to isolate its sectors.

To fall within the scope of the NIS 2 Directive, you must be a public or private entity, provide services or operate within the European Union, and your business sector must be included in the list of EEs or IEs. In addition, you must have at least 50 employees and annual turnover of €10 million or more. (13)

CONDITIONS TO MEET
  • Public or private entity
  • Activity within the European Union
  • Sector included in the EE or IE list
  • At least 50 employees
  • Annual turnover ≥ €10 million
Entity covered by NIS 2
05

The NIS 2 Directive timeline

A. Implementation timeline of the NIS 2 Directive

The NIS 2 Directive was published in the Official Journal of the European Union on 27 December 2022, and member states have 21 months from that date to transpose the directive into their national law. The transposition deadline is therefore set for October 2024.

However, it is important to stress that this deadline concerns transposition into national law by member states, not the compliance date for the entities subject to the NIS 2 Directive. These entities will very probably be given additional time to comply with the directive once it applies in their respective countries. (14)

27 Dec. 2022PUBLICATION IN THE OJ OF THE EU October 2024
MEMBER STATES Transposition into national law
Deadline: months
Transposition deadline
ENTITIES Compliance
Additional time likely, once the directive applies in each country

The deadline concerns member states, not the compliance of entities.

B. Adaptation and transposition into national legislation

The NIS 2 project is part of the European Union's legislative efforts to regulate the growing importance of digital and IT tools. The NIS 2 Directive is designed in coordination with several other texts (15), namely:

NIS 2 Directive + 3 TEXTS
  • DIRECTIVE DRAFT

    The draft directive on the resilience of critical entities, which imposes obligations to ensure the continuity of essential services and their security against physical threats;

  • REGULATION DRAFT

    The draft DORA regulation (Digital Operational Resilience Act), which sets out specific cybersecurity obligations for financial sector players. This regulation also provides that the players concerned in this sector will be able to take part in the discussions of the NIS Cooperation Group and exchange with the CSIRTs (Computer Security Incident Response Teams);

  • REGULATION BEING DRAFTED

    The regulation currently being drafted, commonly known as “cyber resilience”. This regulation will build on the definitions of “incident” and “vulnerability” established by the NIS 2 Directive. In addition, certain categories of products will be defined as critical according to their use by entities qualifying as essential under the directive's criteria.

These various pieces of legislation are designed to strengthen the security and resilience of critical infrastructure, essential services and financial sector players against cyber threats, for a safer digital environment.

Summary

NIS 2 is the second version of the NIS project, which aims at improving and consolidating the overall level of cybersecurity across Europe, and widens the sectors concerned:

  • Digital providers
  • Waste management and waste water networks
  • Public administration
  • Postal and courier services
  • Food
  • Manufacture of chemicals and pharmaceuticals
  • Space

It applies to entities that meet the following criteria:

  1. Operating within the European Union;
  2. Whose business sector is included in the list of EEs or IEs;
  3. With at least 50 employees or annual turnover of €10 million or more.

Compared with NIS 1, this new directive aims to strengthen incident response by introducing more appropriate security requirements for critical infrastructure, and also for their subcontractors.

In addition, companies that fail to comply with its cybersecurity provisions for their activities will be liable to financial penalties. For essential entities: up to €10 million or 2% of total worldwide annual turnover. For important entities: up to €7 million or 1.4% of total worldwide annual turnover.

The directive thus encourages member states to work together to promote cooperation, coordination and information sharing, and then to ensure:

  1. Adequate security conditions throughout the European Union;
  2. The identification of common vulnerabilities;
  3. The sharing of information on threats;
  4. The implementation of effective prevention and response measures.
17 OCTOBER 2024

This directive will be transposed from 17 October 2024 and will then involve more specific measures that the entities concerned will have to put in place in order to comply with the requirements.

Written by Guillaume Alliel Phinasoft

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.