---
title: "NIS 2 Directive: who it applies to and which security measures to adopt"
description: The NIS 2 Directive standardizes the prevention and management of cyber threats across Europe. Here's how.
image: https://newsroom.kireygroup.com/hubfs/Blog_Security_NIS2.webp
---

[kireygroup.com](https://www.kireygroup.com/)

[![](https://newsroom.kireygroup.com/hubfs/item-2020-dicembre/logo-Blog-v2.svg)](https://newsroom.kireygroup.com/en/news)

- [Ita](https://newsroom.kireygroup.com/news/direttiva-nis-2-guida-alla-compliance-a-chi-si-applica-e-quali-misure-di-sicurezza-adottare?hsLang=it)
- Eng
- [Esp](https://newsroom.kireygroup.com/es/news?hsLang=en)

[Kireygroup.com](https://www.kireygroup.com/)

# Get your daily dose of tech!

## We Shape Your Knowledge

# [Legacy modernization in banking: discover the true cost of legacy systems](https://newsroom.kireygroup.com/en/news/legacy-modernization-in-banking-discover-the-true-cost-of-legacy-systems?hsLang=en)

The banking sector is one of the world’s largest investors in digital transformation and innovation,...

[Read more](https://newsroom.kireygroup.com/en/news/legacy-modernization-in-banking-discover-the-true-cost-of-legacy-systems?hsLang=en)

 10 MIN READ

22 September 2026

### Latest News

- [Legacy modernization in banking: discover the true cost of legacy systems](https://newsroom.kireygroup.com/en/news/legacy-modernization-in-banking-discover-the-true-cost-of-legacy-systems?hsLang=en)
- [Context Engineering, the art and science behind AI Agents](https://newsroom.kireygroup.com/en/news/context-engineering-the-art-and-science-behind-ai-agents?hsLang=en)
- [Agentic AI Governance: how to effectively manage AI that can act](https://newsroom.kireygroup.com/en/news/agentic-ai-governance-how-to-effectively-manage-ai-that-can-act?hsLang=en)
- [Autonomous SOC: reality, limitations, and prospects for AI-driven security](https://newsroom.kireygroup.com/en/news/autonomous-soc-reality-limitations-and-prospects-for-ai-driven-security?hsLang=en)
- [Data Virtualization, the pillar of data-driven companies: what it is and how it works](https://newsroom.kireygroup.com/en/news/data-virtualization-the-pillar-of-data-driven-companies-what-it-is-and-how-it-works?hsLang=en)
- [Cloud Economics: the goal is not to spend less, but to spend better](https://newsroom.kireygroup.com/en/news/cloud-economics-the-goal-is-not-to-spend-less-but-to-spend-better?hsLang=en)

- [Data Value](https://newsroom.kireygroup.com/en/news/tag/data-value) /

# NIS 2 Directive: who it applies to and which security measures to adopt

#### Kirey

[![](https://newsroom.kireygroup.com/hubfs/it.svg)](https://newsroom.kireygroup.com/news/direttiva-nis-2-guida-alla-compliance-a-chi-si-applica-e-quali-misure-di-sicurezza-adottare?hsLang=it)    [![](https://newsroom.kireygroup.com/hubfs/ES.svg)](https://newsroom.kireygroup.com/?hsLang=es)

 13 MIN READ

10 September 2024

- Share on:
- <https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fnewsroom.kireygroup.com%2Fen%2Fnews%2Fnis-2-directive-who-it-applies-to-and-which-security-measures-to-adopt>
- <https://www.twitter.com/share?url=https%3A%2F%2Fnewsroom.kireygroup.com%2Fen%2Fnews%2Fnis-2-directive-who-it-applies-to-and-which-security-measures-to-adopt>
- <http://www.linkedin.com/shareArticle?mini=true&url=https://newsroom.kireygroup.com/en/news/nis-2-directive-who-it-applies-to-and-which-security-measures-to-adopt>

- [All](https://newsroom.kireygroup.com/news?hsLang=en)
- Categories + 
    - [Corporate](https://newsroom.kireygroup.com/en/news/tag/corporate)
    - [Cybersecurity](https://newsroom.kireygroup.com/en/news/tag/cybersecurity)
    - [Events/Webinars](https://newsroom.kireygroup.com/en/news/tag/events-webinars)
    - [Cloud](https://newsroom.kireygroup.com/en/news/tag/cloud)
    - [Data Value](https://newsroom.kireygroup.com/en/news/tag/data-value)
    - [Innovation](https://newsroom.kireygroup.com/en/news/tag/innovation)
    - [Artificial Intelligence](https://newsroom.kireygroup.com/en/news/tag/artificial-intelligence)
    - [Monitoring](https://newsroom.kireygroup.com/en/news/tag/monitoring)
    - [DevSecOps](https://newsroom.kireygroup.com/en/news/tag/devsecops)
    - [Software Development](https://newsroom.kireygroup.com/en/news/tag/software-development)
    - [Corporate Social Responsibility](https://newsroom.kireygroup.com/en/news/tag/corporate-social-responsibility)
    - [Data Privacy](https://newsroom.kireygroup.com/en/news/tag/data-privacy)
    - [Advisory](https://newsroom.kireygroup.com/en/news/tag/advisory)
    - [Accessibility](https://newsroom.kireygroup.com/en/news/tag/accessibility)
    - [Automation](https://newsroom.kireygroup.com/en/news/tag/automation)
    - [Digital Banking](https://newsroom.kireygroup.com/en/news/tag/digital-banking)
    - [Digital Industry](https://newsroom.kireygroup.com/en/news/tag/digital-industry)
    - [Use case](https://newsroom.kireygroup.com/en/news/tag/use-case)
    - [Welfare & Social Services](https://newsroom.kireygroup.com/en/news/tag/welfare-social-services)
- [Press & PR](https://newsroom.kireygroup.com/en/news/tag/press)

In 2024, digital technology **permeates every sector of the economy and society**. This makes it essential to have a solid regulatory framework, ideally at a supranational level, aimed at minimizing risks related to cyber threats and **their impact on critical infrastructures and essential services**. 

The NIS 2 Directive addresses this need by setting [**new security standards**](https://www.kireygroup.com/en/competencies/cybersecurity) for European public and private organizations. 

## What is NIS 2: An Overview of the Directive and Differences from NIS 

The NIS 2 Directive (Network and Information Security 2) is an EU legislative act that **updates and expands the framework for network and information system security,** replacing the previous NIS Directive from 2016. 

### **The NIS Directive and the Evolution to NIS 2 ** 

NIS laid the foundation for a **unified European regulatory framework** on cybersecurity, promoting standardized security practices and marking a turning point in protecting information systems, especially in **critical industries of the economy and society**. 

Despite being a significant step forward, the NIS Directive has proven **inadequate over time** in addressing the evolving threats. On one hand, the exponential increase in cyberattacks (+12% in 2023, according to Clusit), which are increasingly sophisticated and targeted; on the other hand, the pervasive digitalization of essential sectors and services, combined with the increasing value of data, has driven the need to update and revise the regulatory framework. The NIS 2 Directive emerges from this necessity and introduces **stricter requirements** and a proactive approach to managing cyber risks. The differences between NIS and NIS 2 primarily concern five areas: 

- **Wider scope of the directive** compared to NIS; 

- **Stricter security and reporting requirements** than in the past; 

- **Sanctions**: NIS 2 introduces a uniform and severe European sanction regime; 

- **Management board responsibilities**: with NIS 2, cybersecurity becomes the direct responsibility of corporate management bodies, not just IT departments; 

- **Supply Chain Focus**: NIS 2 requires organizations to consider security throughout the supply chain. 

### **NIS 2 Entry into Force ** 

The NIS 2 Directive formally came into force on **January 17, 2023**. However, as it is not a regulation (which would have had immediate effect), it must be transposed into national law by Member States by **October 17, 2024.**  

## Which Companies Are Subject to NIS 2  

The scope of the NIS 2 Directive is one of the key elements and **a clear difference from the previous regulation**. The European legislator has recognized the increasing interconnection between information systems, the economy, and society and has significantly expanded the range of entities required to comply with its provisions. So, **who does the NIS 2 Directive apply to**? 

1. Primarily**, public and private entities** offering services or conducting activities **within the European Union.** 
2. These entities must fall within one of the sectors specified in the [directive's annexes](https://eur-lex.europa.eu/legal-content/IT/TXT/PDF/?uri=CELEX:32022L2555), which are divided into **two categories:** *highly critical sectors* and other *critical sectors*. The first category includes energy, transport, banking, healthcare, water supply, and digital infrastructure (such as cloud service providers). The second group includes, among others, postal and courier services, waste management, production and distribution of chemicals, food production and processing, digital service providers (e-commerce, search engines, social media platforms), and other key areas of the economy and daily life in every country. 
3. A **size criterion** also applies: NIS 2 is mandatory only for **medium and large companies**, with the baseline parameters being 50 employees and 10 million euros in revenue. 

## How to Address NIS 2 Compliance  

Compliance with NIS 2 is a complex issue that requires consultancy support from **experts capable of guiding the company through a comprehensive process**. This includes an in-depth assessment, a subsequent gap analysis, involvement of all relevant stakeholders, and the design and implementation of appropriate solutions, which are technical and organizational, requiring the management of change and discontinuity. 

From a purely regulatory perspective, organizations must adopt **technical, operational, and organizational measures** to address the risks posed to the security of the systems and networks they use in their activities or to provide services. The European legislator follows a typical **risk-based approach**, requiring each entity to select appropriate measures after assessing their exposure to risks, as well as the likelihood and severity of potential incidents. 

## **The Multi-Risk Approach and Measures to Adopt**  

Focusing on the protection measures, the European legislator (Art. 21) states that they must be "based on a multi-risk approach aimed at protecting IT and network systems and their physical environment from incidents." The **multi-risk approach is central to NIS 2** as it shows the legislator's intention: to go beyond technical attacks (typical external cyberattacks), embracing **360° security** that includes prevention and response capabilities to physical and environmental risks, human errors, supply chain risks, process interruptions, and more. 

In terms of **cyber risk prevention and management**, the legislator identifies 10 key areas, directly taken from the text of the directive: 

1. **Risk analysis** and IT system security policies; 
2. **Incident management;** 
3. **Business continuity**, including backup management and disaster recovery, and crisis management; 
4. **Supply chain security**, including security aspects related to relationships with suppliers or service providers; 
5. Security in the **acquisition, development, and maintenance of IT and network systems**, including vulnerability management and disclosure; 
6. Strategies and procedures for evaluating the **effectiveness of cyber risk management** measures; 
7. Basic cybersecurity hygiene practices and **cybersecurity training**; 
8. Policies and procedures regarding **encryption**; 
9. **Human resource security, access control strategies, and asset management;** 
10. Use of **multi-factor authentication** or continuous authentication solutions, secure voice, video, and text communications, and secure emergency communication systems within the organization. 

Among these points, of particular interest are the **business continuity** aspect (3), **supply chain security** (4), and **cyber hygiene practices** (7), which effectively require the targeted companies to organize **security awareness programs**. 

## Reporting and Penalties: What’s New in NIS 2  

The new European directive sets **stricter rules for incident reporting** than before and defines a fairly strict sanctioning system. The legislation specifies the information to be provided and the timeframe within which the incident must be reported to the CSIRT: 24 hours for a preliminary warning and no more than 72 hours for the incident notification. 

Regarding penalties, NIS 2 establishes that they must be effective, proportionate, and dissuasive, meaning they should be based on a careful assessment of the circumstances of each case. Here, a distinction is made between so-called essential and important entities, which will be defined by Member States by April 2025. For essential entities, penalties can reach up to **10 million euros or 2% of annual global turnover**, whichever is higher. The maximum is 7 million euros or 1.4% of global turnover for important entities. 

[Contact us](https://www.kireygroup.com/en/contact) to discover how we can support you throughout the NIS 2 compliance process.

- [Previous post](https://newsroom.kireygroup.com/en/news/the-challenge-of-data-democratization-and-how-to-overcome-it?hsLang=en)
- [Read all posts](https://newsroom.kireygroup.com/en/news?hsLang=en)
- [Next post](https://newsroom.kireygroup.com/en/news/robertas-story-a-year-in-tanzania-supporting-domestic-workers?hsLang=en)

## Related posts:

#### [Data Virtualization, the pillar of data-driven com...](https://newsroom.kireygroup.com/en/news/data-virtualization-the-pillar-of-data-driven-companies-what-it-is-and-how-it-works?hsLang=en)

Becoming a data-driven company is essential to remain competitive, but the journey is often slowed d...

[Read more](https://newsroom.kireygroup.com/en/news/data-virtualization-the-pillar-of-data-driven-companies-what-it-is-and-how-it-works?hsLang=en)

 10 MIN READ

10 September 2024

#### [DataOps: What It Is and Why It Is Revolutionizing ...](https://newsroom.kireygroup.com/en/news/dataops-what-it-is-and-why-it-is-revolutionizing-enterprise-data-management?hsLang=en)

As organizations strive to become truly data-driven, they are increasingly running into the limitati...

[Read more](https://newsroom.kireygroup.com/en/news/dataops-what-it-is-and-why-it-is-revolutionizing-enterprise-data-management?hsLang=en)

 20 MIN READ

10 September 2024

#### [Data Strategy: a practical guide to aligning data,...](https://newsroom.kireygroup.com/en/news/data-strategy-a-practical-guide-to-aligning-data-business-and-it-architecture?hsLang=en)

Companies have never had so much data available: management systems, applications, sensors, digital ...

[Read more](https://newsroom.kireygroup.com/en/news/data-strategy-a-practical-guide-to-aligning-data-business-and-it-architecture?hsLang=en)

 13 MIN READ

10 September 2024

#### Explore

- [Home](https://www.kireygroup.com/)
- [Competencies](https://www.kireygroup.com/en/competencies)
- [Industries](https://www.kireygroup.com/en/industries)
- [About Us](https://www.kireygroup.com/en/about-us)
- [Tech&Partners](https://www.kireygroup.com/en/tech-partners)
- [Careers](https://www.kireygroup.com/en/careers)
- [Contact](https://www.kireygroup.com/en/contact)
- [Corporate Social Responsibility](https://www.kireygroup.com/en/corporate-social-responsibility)
- [Advisory](https://www.kireyadvisory.com/en)

#### Policy

- [Quality](https://www.kireygroup.com/oven/media/PKG-COMP-AL14-Quality-Policy.pdf)
- [Security](https://www.kireygroup.com/oven/media/PKG-CIS-LG02-Security-Policy.pdf)
- [Gender Equality](https://www.kireygroup.com/oven/media/PKG-COMP-LG03-Politica-per-la-parita-di-Genere-v2.pdf)
- [Service Management](https://www.kireygroup.com/oven/media/PKG-COMP-AL45-Politica-per-la-gestione-dei-servizi.pdf)
- [Environment](https://www.kireygroup.com/oven/media/PKG-COMP-AL44-Politica-Ambientale-Kirey.pdf)
- [Health, Safety & Wellbeing](https://www.kireygroup.com/oven/media/PKG-COMP-LG02-Policy-on-health-safety-and-well-being-in-the-work-environment.pdf)
- [ESG](https://www.kireygroup.com/oven/media/Policy-ESG-ENG-v1.pdf)
- [Info on Data Processing](https://www.kireygroup.com/en/information-on-data-processing)

#### Certifications

- [ISO 9001:2015](https://www.kireygroup.com/oven/media/KIREY-S-R-L-9001.pdf)
- [ISO/IEC 27001:2022](https://www.kireygroup.com/oven/media/KIREY-S-R-L-27001.pdf)
- [PDR 125](https://www.kireygroup.com/oven/media/PDR-125-2022.pdf)  
  <https://www.kireygroup.com/oven/media/PKG-COMP-AL45-Politica-per-la-gestione-dei-servizi.pdf>
- [ISO/IEC 20000-1:2018](https://www.kireygroup.com/oven/media/ISOIEC-20000-12018-ENG.pdf)
- [ISO 14001:2015](https://www.kireygroup.com/oven/media/ISO-14001-2015-ENG.pdf)
- [ISO 45001:2018](https://www.kireygroup.com/oven/media/CERTIFICATO-ISO-45001-KIREY-ENG.pdf)
- [ISO 22301:2019](https://www.kireygroup.com/oven/media/ISO-22301-2019-ENG.pdf)

#### Info

**Kirey Srl**

[info@kireygroup.com](mailto:info@kireygroup.com)  
Viale Francesco Restelli, 5  
20124 Milano

[kirey@pec.it](mailto:kirey@pec.it)  
**PI/CF**: 06729880960  
**REA**: MI 1910802  
**Tel**: +39 02 78625200

Capitale sociale 1.089.620,00 

[![Linkedin](https://newsroom.kireygroup.com/hs-fs/hubfs/Linkedin.png?width=20&name=Linkedin.png)](https://www.linkedin.com/company/kireygroup/)<https://open.spotify.com/show/41V5g7d4zccIrVcmNB3ZWd>   <https://www.instagram.com/kireygroup/?igshid=MzRlODBiNWFlZA%3D%3D>

- [Privacy Policy](https://www.kireygroup.com/oven/media/Kirey-Privacy-ENG-policy-art-13.pdf)
- [Cookie Policy](https://www.kireygroup.com/oven/media/Kirey-Cookie-Policy-ENG-1.pdf)
- [Terms and Conditions](https://www.kireygroup.com/oven/media/Kirey-Website-Terms-and-Conditions-1.pdf)

[![KIREY LOGO](https://newsroom.kireygroup.com/hs-fs/hubfs/KIREY_LOGO_PAYOFF_RGB_POS.png?width=200&height=72&name=KIREY_LOGO_PAYOFF_RGB_POS.png)](https://www.kireygroup.com/)

© Copyright 2026 by Kirey 