THREAT-WATCH logo

THREAT‑WATCH

Glossary

NIS2 Directive

An EU law setting minimum cybersecurity and incident-reporting requirements for essential and important entities across critical sectors.

The NIS2 Directive is the EU's updated network and information security law, replacing the original 2016 NIS Directive. It expands the list of covered sectors (energy, transport, banking, health, digital infrastructure, public administration, certain manufacturing, and more), imposes specific cybersecurity risk-management measures, and sets strict incident-reporting deadlines with meaningful penalties for non-compliance. Each EU member state transposes it into national law, so exact obligations vary slightly by country.