What is the NIS2 Directive? - Check Point Software

What is the NIS2 Directive?

Directive (EU) 2022/2555, more commonly known as NIS2, is the second iteration of the EU’s Network and Information Security (NIS) directive, and it is the primary cybersecurity standard in the EU. NIS2 updates NIS by expanding the sectors affected by the law and its requirements. By October 17, 2024, EU member states are required to implement NIS2 in their national laws, so all organizations affected by NIS2 must be in compliance by Q4 2024.

The Importance of the NIS2 Directive

NIS2 creates a standard set of cybersecurity requirements for organizations providing essential or important services to EU member states. By doing so, it reduces the risk that cyberattacks against these organizations could result in significant repercussions for EU citizens.

Sectors Affected By The NIS2 Directive

Organizations that meet all three of the following criteria must comply with the NIS2 Directive by October 18, 2024

The NIS2 directive classifies sectors into essential and important entities. Examples of essential entities (EE) include:

NIS2 also impacts important entities (IE), such as:

In addition to sectors, NIS2 compliance is also affected by the size of the organization. In general, EEs must have at least 250 employees and an annual turnover of over 50 million euros or a balance sheet of 43 million euros. IEs generally must have at least 50 employees and an annual turnover or balance sheet of at least 10 million euros. However, these rules vary by sector. Additionally, companies that are the sole provider of a particular service within an EU member state may be classified as an EE or IE regardless of size.

What are the NIS2 Requirements?

NIS2 creates four sets of high-level organizational requirements, including:

Additionally, it specifies a set of ten minimum requirements, which include:

  1. Performing risk assessments and implementing security policies for IT systems.
  2. Implementing policies and procedures for the use of cryptography and encryption.
  3. Securing and managing vulnerabilities in system procurement.
  4. Implementing security procedures for users who can access sensitive data.
  5. Using multi-factor authentication (MFA), continuous authentication, and encrypted communications when appropriate.
  6. Evaluating the effectiveness of the security controls put in place.
  7. Planning for incident detection and response.
  8. Training employees on basic computer hygiene.
  9. Planning for business continuity and disaster recovery (backups, continued access, etc.)
  10. Securing the supply chain and how the company manages potential vulnerabilities in third-party relationships.

Penalties for NIS2 Violations

NIS2 lays out various types of penalties that can be levied against an organization for non-compliance, including:

Ensure that Your Business is in Compliance with the NIS2 with IGS

The NIS2 directive is designed to limit the risk that cyberattacks against essential and important entities within the EU will impact their ability to provide services to EU citizens. This update to the original NIS expands the scope of the directive, implements updated requirements, and provides regulators with the power to levy additional, more stringent penalties against organizations that fail to comply with its requirements.

Achieving compliance with the NIS2 directive by deadlines in Q4 2024 is essential for all affected organizations and requires the implementation of a robust cybersecurity program. Check Point offers support for companies attempting to achieve this and other cybersecurity goals through its Check Point Services program.

Check Point’s External Risk Management offering helps with compliance in several ways, from supply chain monitoring to attack surface management.