Back
Back
Back
Blog

NIS2: What it is, who it applies to, and what it really changes

In this article

NIS2: What it is, who it applies to, and what it really changes

June 20, 2025

·

6 min read

Anna Acquasaliente

Anna Acquasaliente

Illustration NIS2 Directive

Introduction

This guide offers practical, detailed information to help you understand how the NIS2 Directive affects your organization and what concrete steps you can take. It does not replace the official text of the directive, which remains the main legal reference. You can read the full version on the European Union website, in English or Italian (eur-lex.europa.eu).

Understanding the directive and preparing for compliance early is not just about following rules. It is also a way to strengthen your resilience, gain customer trust, and protect business continuity.

NIS Directive 2: What it is and why it matters

Directive (EU) 2022/2555, known as NIS2, is the new European cyber security framework that replaces the previous NIS1 directive (2016/1148), improving and expanding its scope.

Its goal is to ensure a high and consistent level of security for networks and information systems across the European Union. This requires all member states to align their regulations, strengthen cross-border cooperation, and enforce minimum security standards for digital infrastructure and essential services.

NIS2 was introduced in response to a sharp rise in cyber attacks, increasing digitalization, critical dependence on technology, and the tight interconnection between public and private sectors. In a scenario where cyber threats impact hospitals, local governments, and manufacturing firms alike, a coordinated and structured response is no longer optional.

What’s new compared to NIS1

NIS1 was an important first step toward a more secure digital ecosystem, but it exposed several weaknesses. These included inconsistent implementation across member states, unclear criteria for identifying essential operators, and limited powers for supervisory authorities.

NIS2 aims to close these gaps. Its scope is broader and now includes sectors that were previously excluded, such as postal services, cloud providers, critical technology manufacturers, and certain areas of public administration. It introduces clear inclusion criteria based on company size and impact, applying the same rules across the EU.

Risk management requirements are more detailed. Organizations must now have plans in place for incident response, supply chain security, vulnerability management, and ongoing staff training. Reporting rules have also changed: significant incidents must be reported within 24 hours, followed by a full report.

National authorities will have stronger enforcement powers. They can carry out inspections, request documentation, and issue penalties of up to 10 million euros or 2% of global annual turnover, depending on the severity of the violation, similar to GDPR enforcement.

NIS2: Who it applies to

The directive mainly applies to two categories of organizations: essential entities and important entities.

Essential entities operate in sectors that are critical to national security and economic stability, such as:

  • Energy
  • Transport
  • Healthcare
  • Financial services
  • Digital infrastructure

Important entities provide supporting or related services, including:

  • ICT service providers
  • Postal and courier services
  • High-tech manufacturers
  • Data center operators

Unlike NIS1, inclusion is no longer left to the discretion of individual member states. NIS2 introduces objective criteria: companies with at least 50 employees and annual revenue over 10 million euros fall within its scope. Member states can also include smaller companies if they deliver services considered strategic.

Crucially, NIS2 doesn’t apply only to the private sector. Certain public administration bodies, especially those with key roles in healthcare, national security, or transport, are also covered.

When does NIS2 come into force?

The directive was published in the Official Journal on December 27, 2022, and took effect on January 16, 2023.

Member states have until October 17, 2024, to implement it into national law. Companies affected by the directive must be fully compliant by that date. Preparing takes time and effort, especially for those without formal processes in place, so it’s important to act now.

NIS 2 Obligations

Organizations affected by NIS2 must adopt technical and organizational cybersecurity measures that match their level of risk, sector, and size.

Key obligations include:

  • Identifying and assessing risks
  • Protecting data and critical infrastructure
  • Managing vulnerabilities
  • Ensuring business continuity
  • Providing ongoing staff training

In the event of a major incident, the directive requires a three-step notification process:

  • An initial alert within 24 hours
  • A detailed report within 72 hours
  • A final report within one month

National authorities will have broad inspection powers and can impose severe penalties for non-compliance. It’s not just about how a company reacts to incidents, preventive measures also matter. Missing processes, continuity plans, or activity tracking can all be considered violations.

How to comply with NIS2

Complying with NIS2 starts with understanding your role in the digital supply chain. Each company must begin with a self-assessment: check if the directive applies, evaluate current cybersecurity maturity, and identify any gaps.

The next step is to build a structured action plan across several areas: governance, technology, staff training, and vendor management. This includes defining formal policies, appointing security officers, setting up incident response processes, and using tools for traceability.

Working with experienced partners in IT security and regulatory compliance can help speed up the process and ensure better results.

NIS2 and related regulations

NIS2 doesn’t exist in isolation. It must be interpreted alongside other key European regulations. The GDPR continues to govern personal data protection and often overlaps with the security requirements of NIS2. The DORA regulation, taking effect in 2025, focuses on the digital resilience of financial entities. The CER Directive (Critical Entities Resilience) targets the physical protection of critical infrastructure.

For businesses, this means adopting an integrated approach to compliance. Different regulations may have distinct requirements, but they also share common ground. A solid security management system can help meet multiple obligations at once, making compliance more efficient.

Download NIS2 in PDF format

You can view the full text of the directive directly in PDF format from the Official Jorunal at this link to the Official Gazette. If you want to compare it with the previous version, the NIS1 directive is also available at this link.

Conclusion

NIS2 marks a key regulatory and strategic shift in the protection of European information systems and digital infrastructure. It is a call to step up security practices, not just as a technical safeguard, but as a foundation for business continuity and market trust.

How Deepser can help with incident management

One of the key requirements of NIS2 is managing cybersecurity incidents quickly and effectively. Meeting strict reporting deadlines and coordinating responses requires tools that track every event and action.

Deepser is a comprehensive IT Service Management (ITSM) solution that helps companies manage all IT service processes, including incident handling.

Thanks to its integration with other business systems, user-friendly dashboards, and advanced SLA tracking, Deepser supports fast, compliant responses to NIS2 requirements while improving overall efficiency and IT resilience.

Try our free demo

Subscribe to our newsletter

Get the best content on ITSM software, customer service and processes in your inbox twice a month.

Summarize this article with AI

Access the recording

See Deepser in action

Work with us

Access the Resource

Complete the form to get immediate access.

Compare all features
Feature
Starter
Plus
Enterprise
Service & Ticketing
Service Management
Incident Management
Issue Management
Request Management
Problem Management
Change Management
Customizable Service Types
Help Desk
Manage Priority/Urgency
Manage Status
Multi-Level Customizable Categorization
Routing Rules
Request Assignment
Customizable Service Desk Queues
Reminders
Escalation Rules
Multichannel Communication
Email Ticketing
Unlimited Email Integrations
Automatic Email Notifications
Customizable Email Templates
Call Center Management
CTI Integration
Time Tracking
Worklog Activities & Reports
Internal Comments
Comments To Users
Pre-Defined Quick Replies And Macros/Templated Responses
Ticket Relationship Mapping
Custom Ticket Templates
Multiple Ticket Templates & Template Rules
Ticket Export
Task Automation
To Do List
Tasks For Maintenance Scheduling And Activity Planning
Visual Calendar And Progress
Split Activities To Multiple Users
Customizable Task Types
Customizable Task Templates And Fields
SLA
Multiple Service Level Agreements Policies
Custom Work Calendars
Custom Unlimited Metrics
Custom Unlimited Goals
Business Rules Management
Reminders And Notifications
Escalations For Sla Violation
Escalations To Prevent Sla Violation
Marketing
Conversions Management
Ads Campaigns Management
UTM Parameteres Tracking
Performance Monitoring
Advanced Collaboration
Changes Tracking
Sales
Catalog: Product Management
Catalog: Simple Products & Grouped Products
Catalog: Product Types and Visibility
Catalog: Related Products
Tax Management
Tax based on Country
Multiple taxes
Currency: Multiple Currency
Currency: Automatic Currency Rate Updates
Currency: Quotes & Orders with different currencies
Price List: Multiple Price List Management
Price List: Catalog Price List Rules & Priorities
Price Lists based on Account
Quotation Management
Quotation templates
Order Management
Order templates
Create Orders from Quotations
Invoice Management
Invoice templates
Create Invoice from Orders
Create Invoice from Tickets
Create Invoice from Products
Shipment Management
Shipment templates
Create Shipment from Orders
Calendar
Visual Calendars
Customizable Calendars Linked To Service, Cmdb, Crm, Tasks, Etc.
Integration with Microsoft 365 & Google Calendars
ITAM
IT Asset Manager With Auto-Discovery
Asset Lifecycle Management
Job Rules To Automatically Assign Assets To Companies/Users
Remote Collectors For Segregated Networks
Windows Agent
Agentless Discovery With Multiple Protocols
Monitoring
Software Manager: Auto-Detect Of Installed Software
Ip Address Manager With Subnets Auto-Discovery
Remote Control With Teamviewer
Remote Control With Anydesk
Remote Control With Splashtop
Integrations
Unlimited Ldap Integrations
LDAP Compliance With All Commercial Standards (Active Directory, Open Ldap, Etc.)
Import Users From LDAP
Import Groups From LDAP
Azure AD
SAML & OAuth2.0
SSO – Single Sign On
SSO Linked With Ldap Integration
Import – Powerful Native Tool
Import – Unlimited Customizable Imports
Export – Excel/Csv/Pdf Exports
Integration – Connector For External Integrations
API – Powerful Rest API
Open Source Library For Api Integration
Telephone Switchboards Via CTI
Dashboard
Real Time Html5 Dashboards
Dashboards Panels With Group Permissions
Unlimited Customizable Dashboards
Reports
Pre-Defined Reports
Unlimited Customizable Reports
Scheduled Email Reports
Grids
Massive Actions For Multiple Updates
Excel/Csv Export
Granular Visibility Permissions
Miscellaneous
Watchers Users
Multicompany
Multidepartment
Supervisor Users
Global Search On All Entities
Unlimited Custom Fields
Customizable Branding
Custom Fields For Every Entity: Ticket, Crm, Cmdb, Users, Companies, Itam, Etc.
Customizable Form Templates
Granular Visibility For Every Template Field
Customizable Template Rules
Custom Grids
Custom Grids: Easy Configuration With Drag&Drop Tool
Custom Events For Integrations Or Custom Processes
Multifactor Authentication
Multi Language
Flexible And Powerful Permission Management
Flexible User Groups
Customizable User Roles
System Lists With Advanced Permissions And Logic
Unlimited Customizable Lists With Advanced Permissions And Logic
Attachments For Document Storage
Unlimited Attachments With Drag&Drop Management
Attachment Types With Advanced Permissions For Visibility
Multiple Warehouse Management
Warehouse Loads and Unload
Warehouse: Tickets and Worklog integration
Portals
End User Portal
Self-Service Portal
User Registration With Customizable Signup Process
Guest Portal For Non-Registered Users
Cmdb Portal For End Users / Customers
Crm Portal For End Users/Customers
Cms For Guest Portal
Announcement: Type management
Announcement: ITSM Release Management
Announcement: Scheduling
Announcement: Visibility management & permissions
Announcement: Tag categorization and custom sorting
Announcement: Integration with Portal Designer
Chat
Internal Conversations
Internal Conversation Channels
End User Portal Chat
Conversation Channels With Multiple End Users / Customers
Web Widget
Branded Widget Published On Multiple Web Sites
Customization Of The Widget
Customizable Offline Module
Unlimited Simultaneous Chats
File Sending
Activity Hours
Board
Kanban With Entities Integration
Kanban With Free Forms
Contract
Integrated Worklogs
Purchase Orders Management
Suppliers Management
Contracts In Hours & Quantity
Contracts Workflows
CRM
Account Management (Customers, Providers, Suppliers, Partners, Etc.)
Contact Management (Leads, Prospects, Contacts, Etc.)
Opportunity Management
Customizable Opportunity Types
Linked With Service Management And Contracts
Sales Pipeline Management
Email Crm For Sales Opportunities And Contracts
Address management: Address type management (e.g. location address, billing, shipping, etc.)
Address management: Address association to Accounts, Offices, Warehouses and CMDB
Password Manager
Secure Password Manager With Double Key Encryption
Secure Password Manager Portal For End Users / Customers
Secure Password Manager With Corporate (Shared) Passwords
Secure Password Manager With Private Passwords
Audit Log For Passwords Security
Passwords Linked To All Entities Of The System
Password Manager: Automatic Generation
Password Manager: Strength Checker
Knowledge Base
Multiple Knowledge Bases
Kbs Visibility Based On Groups
Portal Kbs For End Users / Customers
Public Kbs For Non-Logged Users
Kb Linked To Tickets
Kb Linked To Cmdb / Itam
Kb Linked To Crm
CMDB
Unlimited Customizable Ci Object Types
Unlimited Cis
Relations Between Cis
Link With Tickets
Link With Crm And Contracts
Service Catalog Management
Contract Management
License Management
Locations
Link With Itam (Autodiscovery) Module
Planned Activities / Maintenance
Email Cmdb For Devices And Contracts
Graph view relations
Graph view layout & dynamic loading
Module Creator
Create Apps & Custom Modules
Create Custom Forms & Grids
Create End User Portal Custom Modules
Create Custom API
Survey
Customer Satisfaction Survey
Survey Form Visual Designer
Automatic Surveys
Realtime Dashboards
Periodic surveys
Project
Project Management
Auto-scheduling for tasks
Advanced Permissions
Project dependencies and constraints
Project milestones and deliverables
Flow
Approval Request Management
Management Of Approvals By Email
Management Of Approvals From User Portal
Approval Rules Management
Approval Stage Management
Management Of Scheduled Flows
Management Of Automatic Entity Creation
Management Of Automatic Entity Update
Scheduled Maintenance Management
Task Automation Management
Automatic Email Management
No Code / Low Code Platform
Portal Designer
Visual Portal Designer
Frontend Portal Visual Designer
Graphic Widget
Portal Page Management
Group Based Visibility Management
Graphic Widget Customization
Multiple Portals Management
Product Management
Development Task Prioritization
Bug and Fix Tracking
Product Issue Management
Product Backlog Management
Feature Requests Management
Changes Tracking
Task Assignment to Developers

How many agents are on your team?