White Telekom Logo

Menu

Two consultants looking at a new tech screen

NIS 2 directive: new standards in cybersecurity

Summary
The NIS-2 Directive sets new EU cybersecurity standards, tightening rules for critical sectors and management accountability. Learn how organizations can prepare, ensure compliance, and protect essential services against cyber threats.

Not what you are searching for?

Expert authors
Page content
    A keyline for context

    NIS 2 directive: new standards in cybersecurity

    The NIS-2 Directive (“Network and Information Security Directive”) is a key initiative aimed at enhancing the security and integrity of networks and information systems across the European Union. NIS-2 was published in the Official Journal of the EU (L333) on December 27, 2022, and came into force on January 16, 2023. EU member states are required to transpose the directive into national law by October 2024. In Germany, a draft bill for implementation – NIS-2 Implementation and Cybersecurity Enhancement Act (NIS-2UmsuCG) – has been available since July 2023.

    Scope and requirements

    Building on the 2016 NIS Directive, NIS-2 sets new cybersecurity requirements for critical infrastructures (KRITIS) in the EU. The directive is a crucial component of the EU’s cybersecurity strategy, aiming to better protect critical infrastructures from cyber threats and ensure a high, EU-wide level of security. Numerous measures have been defined, including the establishment of national Computer Emergency Response Teams (CERTs), development of coordinated incident response plans, and improved cooperation between public and private entities.

    The directive imposes stricter requirements on public and private organizations in 18 critical sectors with more than 50 employees or annual revenues of at least €10 million. Among the 11 highly critical sectors are energy, transport, banking, financial market infrastructures, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, and space. The 7 other critical sectors include postal and courier services, waste management, chemical production and trade, food production and distribution, manufacturing, digital service providers, and research.

    Reporting and compliance obligations

    Affected organizations must address cybersecurity risk management, monitoring, incident handling, and business continuity. Significant security incidents must be reported to the Federal Office for Information Security (BSI) within defined deadlines:

    Compliance with NIS-2 is monitored through strict liability rules for management. Failure to comply may result in severe penalties. Management must oversee implementation, participate in training, and ensure employees are trained. Non-compliance can result in fines of up to €10 million or 2% of global annual turnover from the previous fiscal year, whichever is higher. NIS-2 also creates the potential for personal liability for executives, adding legal and financial implications for corporate leadership.

    Conclusion

    The NIS-2 Directive marks a pivotal moment in European cybersecurity policy. While the challenges are significant, they can be managed through thorough preparation and a solid understanding of the requirements. The German Security and Defense Industry Association is available to assist organizations in navigating the adaptation process and ensuring compliance with the new standards.

    Our experts

    Get to know us.

    Our consulting expertise

    Discover where we provide tailored solutions to enhance value for our clients.

    Our expertise
    All insights

    Select your location

    Contact

    You are currently viewing a placeholder content from HubSpot. To access the actual content, click the button below. Please note that doing so will share data with our partners.

    More Information