A Two-Minute Overview of the NIS 2 Directive (Also Known as SRI2)
Directive (EU) 2022/2555, commonly referred to as the NIS 2 Directive or SRI 2, aims to ensure a high common level of cybersecurity across the European Union. This directive replaces Directive (EU) 2016/1148, which was characterized by significant disparities in its implementation across Member States.
STAY UPDATED
A video presentation is available should you prefer this format:
Who is Subject to the NIS 2 Directive?
The NIS 2 Directive primarily applies to two categories of entities:
Essential Entities:
These are entities operating in highly critical sectors such as energy, transport, banking, healthcare, drinking water supply, space, public administration, and research. It also includes entities such as qualified trust service providers and top-level domain name registries.
Important Entities:
This category includes entities from additional sectors such as the food industry, chemical manufacturing, postal and courier services, waste management, manufacturing, production and distribution of digital products, legal and accounting services, and digital service providers.
In general, the Directive applies to medium-sized and large enterprises operating in the aforementioned sectors. However, it may also apply to small and micro-enterprises that play a critical role in society or the economy.
Entities within the public administration whose activities are primarily concerned with national security, public security, defence, or law enforcement are expressly excluded from the scope of the Directive.

Si te ha interesado este artículo no dudes en leer:
Deciphered: Keys to Digital Operational Resilience in Financial Entities
Practical Effects of the NIS 2 Directive
The NIS 2 Directive imposes a range of obligations on the entities falling within its scope:
- Implementation of Cybersecurity Risk Management Measures: This includes measures to identify, protect against, detect, respond to, and recover from cybersecurity incidents.
- Notification of Significant Cybersecurity Incidents: Entities are required to report incidents that may have a significant impact on the provision of their services.
- Cooperation in Cybersecurity Information Sharing: The Directive encourages the exchange of information regarding cyber threats, vulnerabilities, and incidents.
To ensure compliance, the Directive establishes supervisory and enforcement regimes:
- Essential Entities: These are subject to more stringent supervision, including on-site inspections and security audits.
- Important Entities: These are subject to less stringent, primarily ex post supervision.
The competent authorities in each Member State are responsible for overseeing the implementation of the Directive. In addition, the European Union Agency for Cybersecurity (ENISA) plays a key role in supporting the Directive’s implementation.
Financial regulation changes constantly; at ILP we analyse it to anticipate its impact on our clients.
If you found this article informative, you may also be interested in reading the following:
DORA: The New Paradigm in ICT Incident Reporting for Financial Entities
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.
Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

