NIS 2
Directive (EU) 2022/2555 — Network and Information Security 2
What it is
NIS 2 expanded the EU's cybersecurity baseline from the original NIS Directive's seven sectors to eighteen, brought medium and large enterprises into scope, hardened incident reporting timelines to 24/72 hours, and made management bodies personally accountable for compliance.
What it requires
Applies to medium and large enterprises (50+ employees or EUR 10M+ turnover) operating in eighteen sectors — energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing, digital providers, and research. Requires risk management, incident reporting, supply-chain security, vulnerability disclosure, governance documentation, and management-body sign-off.
Key facts
- Supervisor
- Member-state designated competent authority per sector — varies by country (see /nis2/country/[country])
- Maximum fine
- EUR 10 million or 2% of global annual turnover (essential entities); EUR 7 million or 1.4% (important entities)
- Key deadline
- 2024-10-17 (national transposition deadline)
- Official text
- https://eur-lex.europa.eu/eli/dir/2022/2555/oj
DSI services for NIS 2
DSI Advisory Services helps covered entities translate NIS 2 obligations into evidence a supervisor, auditor, or board can sign off on — gap assessment, control mapping, and documentation that survives review.
See the service →Read NIS 2 transposition status for your jurisdiction
NIS 2 is a directive — each member state transposes it into national law on its own timeline, with its own competent authority, its own scope additions, and its own fine regime. Pick your jurisdiction:
Related briefings
Pavel Durov says the ship of our personal freedoms has hit the iceberg and is sinking without us realising it. He is partly right, partly wrong, and entirely worth taking seriously. This GISI assessment evaluates his argument against the evidence: the UK's 30 online-speech arrests a day, Germany's platform-fining model, France's crypto-kidnapping wave, the EU's Chat Control revival on 9 July 2026, and the online-safety regimes of Australia and New Zealand. What is accurate survives scrutiny. What is exaggerated — the collapse of the distinction between Western democracies and Russia, China, and Iran — does not. The right question is not whether the West is becoming authoritarian. It is whether the architecture being built in the name of safety — age verification, identity wallets, bulk collection, biometric mandates — creates the conditions under which essential liberty becomes, in practice, optional, regardless of who governs it. The series has been asking that question. The answer, so far, is not consistently yes.
Since 7 July 2026, every new car and van registered in the EU must carry an infrared camera aimed at the driver's face - the Advanced Driver Distraction Warning (ADDW), specified under the General Safety Regulation. It tracks gaze, warns after 3.5 seconds' distraction above 50 km/h, and cannot be permanently turned off. The safety case is real (the wider package is projected to save 25,000+ lives by 2038) and the rule prohibits facial recognition. But the regulation mandates the hardware while leaving the data surface unanswered - retention, sharing, insurer and law-enforcement access - and the same automakers now installing it have already been documented collecting, sharing, and losing connected-vehicle data. The stronger concern is structural: the camera is always-on infrastructure, and the Commission has committed to further ADDW requirements by July 2027. My assessment: this is 'every box is governed, the space between is no one's job' arriving on the road. The camera cannot be turned off - and who benefits from what it sees, beyond the driver, is still being answered by the parties with the most incentive to answer it in their own favour.
From a conference stage, Claus Balslev, head of digitalisation at Denmark's STAR labour-market agency, said the sentence everyone hedges around: if you put data in a US cloud, you share it directly with the US intelligence service. Then he acted on it, migrating STAR's systems off Microsoft and onto European cloud in roughly nine months, and saving money doing it. My assessment: the statement is not rhetoric, it is the precise legal architecture. The CLOUD Act attaches jurisdiction to the US entity, not the data; FISA 702 authorises bulk collection from US providers with no warrant and a gag order; RISAA (2024) extends reach toward the silicon itself; and the 12 June 2026 Fable/Mythos AI suspension proved Washington can switch off the capability globally by letter. Asked under oath before the French Senate in 2025 whether Microsoft could guarantee EU data is never sent to US authorities, Microsoft France's legal-affairs director answered: no. This is not a governance gap but a governance collision, two irreconcilable legal systems applied to the same data, which is why Safe Harbor, Privacy Shield, and soon the current framework all fall. Residency is where the bits sit; sovereignty is who controls access. STAR removed the last excuse, and the AI layer is the next Schrems ruling.
985,000 passports and driver's licences sat on public URLs with no password, no access control, nothing. No hack, no exploit chain. The custodian was not a government agency or a bank but Nefos Solutions, a two-person Irish startup that built membership software for Spanish cannabis clubs, with a Stripe key in plain text inside its app. My assessment: this is not one breach. France Titres (national identity agency, IDOR found by a 15-year-old, 11.7M records), the UK Visa Portal (guessable URL, 100,000+ passports), the Texas hunting-licence vendor (third-party breach, 3.09M Texans), and Nefos (public URL, 985,000 passports) are four expressions of one structural reality. From the most capable national agency to a two-person startup, the security outcome is identical: government identity documents on the open internet. The EU's age-verification mandate will create thousands more Nefos-scale custodians collecting the one category of data that cannot be reset. Identity documents are only as secure as the weakest custodian in the chain that now holds them. Extends the DSI EU regulatory series: France Titres, the EUDI Wallet, and the age-verification oxymoron.
On 12 January 2024, a Russian state actor read the email of Microsoft's senior leadership. Not through a zero-day — through a forgotten legacy test tenant with no MFA, an over-permissioned OAuth app, and an elevated consent grant nobody owned. The path crossed four domains; not one team owned the route. Every control was green. Storm-0558 was the same shape: a consumer signing key accepted as valid for enterprise mailboxes — a seam between two identity planes. This is the failure the industry refuses to name. A vulnerability is a property of a component; a threat is a property of the system. We have spent two decades building frameworks that make each silo defensible in isolation and almost no time building the thing that lets a defender reason across them the way an attacker already does. The fix is not another framework. It is an operating model — decision rights, intake, prioritisation, governance, delivery engagement — the connective tissue that owns the seams. Run the removal test: if your security function vanished tomorrow, would any business decision change? Part I of two. Part II continues on ARIA.
The operational lesson of the Fable 5 and Mythos 5 suspension is not about whether the directive was justified. It is about what it demonstrated: every non-US enterprise running production AI workloads on a US-headquartered frontier model is, structurally, one letter away from an outage that no contract, no regional setting, and no sovereign cloud reseller can prevent. Anthropic had to “abruptly disable” both models for all customers globally to comply — within hours of receiving the 5:21pm ET letter. Three categories of exposure: hard-coded production dependencies, research collaborations with non-US personnel, and government / regulated-industry partnerships (TCS-50K-users-across-56-countries, DXC-banking, all in scope). The full threat surface framework now treats provider home jurisdiction as a primary variable. Single-provider risk is single-sovereign risk. The failover architecture that survives the next 5:21pm letter, with five cross-cutting controls (contract, cache, drill, audit, board), the sovereignty risk matrix across seven provider categories, and the action list for the next four working days under DORA, NIS2, the EU AI Act, and the Tech Sovereignty Package.
Read more on this
Other cybersecurity frameworks in the DSI registry: