Glossary · OT cybersecurity
NIS 2 Directive
Also known as: NIS2, Directive (EU) 2022/2555
German: NIS-2-Richtlinie
The NIS 2 Directive, Directive (EU) 2022/2555, is EU legislation on measures for a high common level of cybersecurity. It requires essential and important entities in listed sectors, including parts of manufacturing, to take cybersecurity risk-management measures and to report significant incidents, and it makes management bodies accountable.
- OT security
In one sentence
NIS 2, Directive (EU) 2022/2555, requires essential and important entities to manage cybersecurity risks and report significant incidents.
Example
A manufacturer of machinery with more than 50 employees checks whether it falls under NIS 2 as an important entity under its country's transposition law and registers with the national authority.
How it applies
- Scope: NIS 2 covers entities in sectors of high criticality and other critical sectors; the latter include manufacturing of, among others, machinery and equipment, electrical equipment, motor vehicles and computer and electronic products. Size thresholds and national rules decide whether a company is essential, important or out of scope.
- Measures: Article 21 lists risk-management measures such as risk analysis, incident handling, business continuity, supply chain security, secure development and vulnerability handling, cryptography, access control and multi-factor authentication.
- Reporting: Significant incidents are reported in stages (24 hours, 72 hours, one month).
- Documentation: Covered entities need documented policies, procedures and evidence. Suppliers to covered entities increasingly receive security questionnaires; clear product security documentation makes these easier to answer.
NIS 2 vs. Cyber Resilience Act
NIS 2 is a directive addressed to organizations that operate services. The Cyber Resilience Act (CRA) is a regulation addressed to products with digital elements and their manufacturers. A machine builder can be affected by both.