๐Ÿ“ Europe ยท NIS2 Directive (EU) 2022/2555 ๐Ÿ‡ฎ๐Ÿ‡น Italian Version
๐Ÿ“– Summary

NIS2 โ€” The European Cybersecurity Directive

A comprehensive guide to Directive (EU) 2022/2555: what it is, who it applies to, obligations, and penalties for businesses.

๐Ÿ“š What is NIS2?

NIS2 (Network and Information Security Directive 2) is European Directive 2022/2555 of the European Parliament and of the Council of 14 December 2022, establishing measures for a high common level of cybersecurity across the European Union.

It replaces and repeals the previous NIS Directive (2016/1148).

๐Ÿข Who Does NIS2 Apply To?

NIS2 applies to two categories of entities:

๐Ÿ”ด Essential Entities (Annex I)

Medium to large entities in highly critical sectors:

  • Energy (electricity, gas, oil, district heating, hydrogen)
  • Transport (air, rail, maritime, road)
  • Banking and credit institutions
  • Financial market infrastructures
  • Healthcare
  • Drinking water supply
  • Wastewater management
  • Digital infrastructure
  • Public administration (central and regional)
  • Space sector

๐ŸŸก Important Entities (Annex II)

Other critical sectors:

  • Postal and courier services
  • Waste management
  • Manufacture, production, and distribution of chemicals
  • Production, processing, and distribution of food
  • Manufacturing (medical devices, electronics, machinery)

๐Ÿ“Š Size Criteria

NIS2 applies to medium-sized enterprises as defined in Recommendation 2003/361/EC:

โš ๏ธ Who is EXEMPT (by default)

Micro-enterprises (fewer than 10 employees, turnover < โ‚ฌ2 million), self-employed professionals, and artisans.

BUT โ€” Micro and small enterprises also fall within scope if they are the sole national provider of an essential service or are explicitly designated by the Member State.

โš ๏ธ Key Obligations

1. Cybersecurity Risk Management Measures (Art. 21)

Entities must implement appropriate measures to manage risks, including:

  • Risk analysis and assessment
  • Incident handling
  • Network and information system security
  • Backup and disaster recovery policies
  • Supply chain security
  • Security in the procurement and maintenance of systems
  • Access control policies
  • Use of cryptography and encryption
  • Security testing and vulnerability assessment
  • Intrusion detection systems

2. Incident Reporting Obligations (Art. 23)

  • Report significant incidents within 24 hours to your national CSIRT
  • Provide updates with substantial information as soon as it becomes available
  • Final report within 1 month with complete details

3. Registration

Entities must provide essential information to the competent national authority.

๐Ÿ’ฐ Penalties (Art. 34)

๐Ÿ”ด Essential Entities

Maximum fine:

โ‚ฌ10,000,000

OR 2% of global annual turnover (whichever is higher)

Management liability for serious violations

๐ŸŸก Important Entities

Maximum fine:

โ‚ฌ7,000,000

OR 1.4% of global annual turnover

๐Ÿ‡ช๐Ÿ‡บ Implementation in EU Member States

EU Directive 2022/2555 (NIS2) transposes NIS2 into national law in each Member State.

๐Ÿ“ˆ NIS1 vs NIS2 โ€” Key Differences

Aspect๐Ÿ†• NIS1โœ… NIS2
Entities covered (example)~700~4,000-5,000 estimated
Sectors7 sectors15 sectors + Public Administration
ObligationsGenericDetailed and specific
Maximum penaltiesโ‚ฌ150,000Up to โ‚ฌ10M or 2% of turnover
Incident reportingNot mandatoryMandatory within 24 hours
Supply chainNot mentionedIncluded (Art. 21)

๐Ÿ“… Entry into Force