Skip to content

Glossary

NIS2 Directive (EU) 2022/2555

NIS2 is an EU directive that imposes mandatory cyber risk management measures, incident reporting duties and management accountability on organizations in designated critical and important sectors.

Because NIS2 is a directive rather than a regulation, it does not apply directly: Member States transpose it into national law, which sets the precise scope of covered entities, thresholds, competent authorities, supervision and penalties. In Slovenia the field is governed by information security legislation. NIS2 replaced the original network and information systems directive and substantially widened the range of entities covered.

Covered entities are classified as essential or important. The difference lies mainly in the supervisory regime — proactive and routine for essential entities, generally reactive for important ones, triggered by an event or suspicion — while the substantive security obligations are the same for both. As a rule, medium and large enterprises in the listed sectors are covered, including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration and space, with postal and courier services, waste management, chemicals, food, parts of manufacturing, digital service providers and research organizations in the important group. Entities whose disruption would have a significant effect may be covered regardless of size.

Substantively, the directive requires technical, operational and organizational measures proportionate to the identified risk. These include policies on risk analysis and information system security, incident handling, business continuity with backup management and crisis management, supply chain security, security in the acquisition, development and maintenance of systems together with vulnerability handling, assessment of the effectiveness of measures, cyber hygiene and training, cryptography, human resources security, access control and asset management, and multi-factor authentication and secured communications.

Reporting of significant incidents is staged: an early warning to the competent authority or response team, then a fuller notification with an assessment, and finally a final report, with interim reports where needed; in certain cases recipients of services must also be informed. A distinctive feature of NIS2 is explicit management accountability — management bodies must approve the measures, oversee their implementation and undergo training, and may be held personally liable for breaches. For financial sector entities, the sector-specific DORA regime takes precedence.

Back to glossary

Ready to strengthen security across your organization?

Contact us to see how our turnkey solutions can build a safer, more resilient organization.