Who needs to comply with the NIS2 Directive?

  • According to the NIS2 Directive provided by the European Union, compliance with this directive is mandatory for various categories of companies, which are divided into two major groups (Source).

Attention Leaders!

If you have a company in the European Union, you’ve probably heard of the NIS2 Directive. But wait, don’t run away yet! Let’s make this topic as simple as possible.

Let's find out together who needs to comply with this directive and what it really means.

What is the NIS2 Directive?

Imagine cybersecurity as a hero; the NIS2 Directive is the cape and shield that support your company to prevent anything bad from happening. This directive protects your digital infrastructure against hackers who threaten a company’s essential information and services. So, who needs to have this cape and shield?

Sectors Covered by NIS2

NIS2 divides companies into two major groups: Essential Sectors and Important Sectors.

Vamos lá ver onde é que a sua empresa se encaixa:

Essential Sectors

If your company is in one of the sectors listed below, you will need to comply with the NIS2 Directive regardless of its size, number of employees, or revenue.

  • Energy
  • Transportation
  • Health
  • Banking Sector
  • Financial Market Infrastructures
  • Wastewater
  • Digital Infrastructures
  • ICT Service Management
  • Public Administration
  • Space

Important Sectors

Now, if your company belongs to one of the sectors described below, take a deep breath. This directive will only be a concern if your company is considered medium or large.

  • Postal and Courier Services
  • Waste Management
  • Production, Manufacturing, and Distribution of Chemical Products
  • Production, Processing, and Distribution of Food Products
  • Manufacturing Industry
  • Digital Service Providers
  • Research

Compliance Obligations

So, you’ve discovered that you need to comply with NIS2. Now what? We’ll need to define some actions:

Risk Management

Develop security policies to identify potential threats.

Incident Reporting

Report incidents to the competent authorities. This allows for a quick and coordinated response.

Continuity Plans

Have a Plan B, C, and even D to ensure that the company continues to operate in the event of an attack.

Training

Knowledge is power! Train your team so everyone is prepared!

Quick Solution

Do you still have any questions? Here is our NIS2 ebook to help you better understand what this directive is all about. Don't hesitate to contact the Strongstep team if you have any questions!

New NIS2 Ebook



Download Your NIS2 Ebook Now!

In this Ebook, you will find:
- What NIS2 is.
- Deadlines you need to meet.
- Deadlines you need to meet.
- Benefits of being compliant with NIS2.

Services

Get to know some of the areas where we operate.