Skip to content
Säkerhet

What is NIS2?

The EU's updated cyber security rules that say "raise your game — or else". Forces thousands of businesses to take security seriously, with fines as the wake-up call.

NIS2 is an EU directive — a shared EU law that each member state builds into its own national legislation — on cyber security. The name stands for Network and Information Security, version 2: the successor to an earlier, weaker variant. Think of it like fire safety rules for buildings suddenly also applying to your data network: the same idea of preventing disasters before they happen.

The big difference from before is that NIS2 covers many more industries. Not just energy companies and hospitals, but also food, manufacturing, waste management, digital services, and plenty of suppliers. If you deliver to a customer that falls under the rules, the requirements can cascade down to you too.

In practice, NIS2 requires businesses to have three things in order: protection (technical measures against intrusion), incident handling (a plan for when things go wrong anyway), and reporting (telling the authority quickly when something serious happens). Leadership also becomes personally accountable — you can no longer blame "the IT person".

Why is NIS2 important for your business?

If your business falls under NIS2 and ignores the requirements, it can get expensive — the directive allows for significant penalties and personal liability for management. But even if you are not directly covered, your customers may start demanding that you meet the same standard, because a weak supplier is a risk to them.

The upside: working to NIS2 makes your business more resilient. A company that survives a data breach without grinding to a halt is simply worth more — to customers and to you sleeping better at night.

NIS2 in practice

Say you run a manufacturing business that supplies components to the automotive industry. Your largest customer falls under NIS2 and suddenly sends a questionnaire: How do you protect your systems? Do you have an incident plan? Who is responsible? If you cannot answer well, you risk losing the contract.

The right approach is to map which systems and data are critical, introduce baseline protection such as two-factor authentication and backups, and write down a simple plan for what you do if you are hacked. It does not need to be complicated — but it does need to exist on paper.

Common questions about NIS2

What does NIS2 mean?

NIS2 is an EU directive on cyber security that requires businesses in essential sectors to protect their systems, handle incidents, and report serious events. It is a tightened follow-up to the earlier NIS directive.

Which businesses does NIS2 cover?

NIS2 covers businesses in a range of essential sectors, including energy, transport, health, food, manufacturing, and digital services. Suppliers can also be affected indirectly if their customers fall under the rules.

What happens if you do not comply with NIS2?

Businesses that fail to meet the requirements risk significant penalties, and management can be held personally accountable. You may also lose customers who require suppliers to meet the same security level.

Related terms

← Full glossary