The Network and Information Security Directive (EU) 2022/2555 (NIS2 Directive) significantly expands the group of affected companies and significantly tightens the cybersecurity requirements – the keyword is: managing director responsibility. Detailed information on the requirements under the NIS2 Directive can be found here. For an efficient implementation of the NIS2 Directive, companies are in need of a holistic concept for cybersecurity compliance.
The NIS2 Directive applies to all companies providing services or operating in the EU, provided they employ at least 50 people or have an annual turnover and annual balance sheet total of more than 10 million EUR and belong to one of the critical sectors. Check now if you are affected with our free Quick-Check!
In addition to governance and cybersecurity awareness, the NIS2 Directive obliges companies to establish a risk management and a procedure for handling security incidents. Companies must determine which measures are specifically required by means of a gap analysis.
According to the NIS2 Directive, management bodies must ensure that the necessary technical, organisational and legal measures are taken and they must monitor their implementation. In case of non-compliance, managing directors can be held personally liable for breaches.
Both the legal situation and internal company processes are subject to change, which can be accompanied by new requirements. Companies must therefore continuously monitor both the legal situation and internal structures and react to changes.
In Europe, it is estimated that more than 100,000 organisations will be affected by the NIS2 Directive in the future. However, a large number of companies are not yet aware that they are affected. Use our free Quick check to find out whether your company is affected.
The European Union’s NIS‑2 Directive establishes a common baseline for cybersecurity requirements across the EU. However, unlike a directly applicable regulation, NIS‑2 must be transposed into national law by each Member State. As a result, businesses operating in Europe face not one single cybersecurity law, but up to 27 different national implementation regimes.
To support organisations navigating this complex regulatory landscape, we have prepared a comprehensive guide covering all EU Member States. The guide includes information on the current status of NIS‑2 implementation, competent supervisory authorities, registration requirements, incident reporting obligations and reporting portals, and key obligations under the respective national NIS‑2 laws.
The guide covers the following Member States: Belgium, Bulgaria, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, Netherlands, Austria, Poland, Portugal, Romania, Slovakia, Slovenia, Spain and Sweden.
100% expertise. 0% nonsense. We have extensive experience in cybersecurity compliance management and combine consulting practice and research in cybersecurity law. Our advice is: Smart. Efficient. Spot-on.