
April 2025 · 4 min read
What is NIS2
The NIS2 Directive, formally known as the Directive on security of network and information systems, is a European legislation aimed at improving the overall level of cybersecurity in the EU.
This directive builds upon the original NIS Directive and introduces more rigorous security requirements for EU member states, critical infrastructure sectors, and digital service providers.
Target of NIS2
The NIS2 Directive aims to bolster cybersecurity resilience across the European Union by establishing clear compliance frameworks for the organisations in scope and enforces significant penalties for non-compliance, thereby emphasising the importance of adhering to these enhanced security standards.
The central reform relates to Article 21 of NIS2, which mandates reporting on risk management and specifies minimum cybersecurity measures that must be implemented.
Through these measures, NIS2 seeks to create a more secure digital environment, ensuring that both public and private entities are better equipped to mitigate cyber threats and protect essential services.
Critical Sectors
Energy | Transport | Banking |
Digital Infra | Healthcare | Space |
Water Treatment | Public Administration |
Critical Sectors
Postal & Courier Services | Waste Management | Critical Product Manufacturing |
Food Production & Distribution | Digital Services | Research Organisations |
Time for Action is Here
Member states were required to create or adjust their cybersecurity laws and frameworks in accordance with the NIS2 Directive by October 17th, 2024. Although some countries are delayed from this deadline, the entities in scope should, at the latest now, take proactive steps to understand their obligations and align their cybersecurity practices accordingly. As an example, see proposed legislation, approved on March 11th, 2025, for implementing NIS2 in Finland.
Sanctions for Non-Compliance
Penalties under the directive may include fines of up to 10 million euros or 2% of the organisation's total global annual turnover, whichever is higher.
The amount of the fine depends on several factors, including the severity and duration of non-compliance, the harm caused to individuals or entities, the organisation's cooperation during the investigation, and its compliance history. In addition to financial penalties, organisations may also face non-monetary sanctions such as operational restrictions, mandatory compliance measures, or exclusion from certain contracts.
Penalties for Non-Compliance
NIS2 introduces a range of sanctions for organizations that fail to comply with the directive. These sanctions can vary significantly depending on the severity of the non-compliance and the country's specific approach to enforcement.Fines
Member states may impose administrative fines on entities that do not meet the NIS2 requirements. Fines may be substantial, intended to serve as a deterrent against non-compliance.Regulatory Action
In addition to financial penalties, regulatory authorities may take other actions, such as issuing warnings, conducting audits, or imposing operational restrictions on non-compliant organisations.Notification Obligations
Organisations subject to NIS2 are required to report significant cybersecurity incidents to their national authorities in a timely manner. Failing to report these incidents may also lead to sanctions.Sector-Specific Regulations
Depending on the sector (e.g., energy, transport, healthcare), additional penalties may apply due to specific national laws aligned with the NIS2 provisions.
Due to the severe nature of the potential consequences, preparing for compliance should be a strategic priority for top management who are also held accountable for meeting NIS2 requirements.

