ILP Abogados
Madrid · Internacional

NIS 2 Directive (Also Known as SRI2)

A Two-Minute Overview of the NIS 2 Directive (Also Known as SRI2)

Directive (EU) 2022/2555, commonly referred to as the NIS 2 Directive or SRI 2, aims to ensure a high common level of cybersecurity across the European Union. This directive replaces Directive (EU) 2016/1148, which was characterized by significant disparities in its implementation across Member States.

A video presentation is available should you prefer this format:

Corporate Cybersecurity Get close to Directive NIS 2, also known as SRI2, in 2 minutes💭

Who is Subject to the NIS 2 Directive?

The NIS 2 Directive primarily applies to two categories of entities:

Essential Entities:

These are entities operating in highly critical sectors such as energy, transport, banking, healthcare, drinking water supply, space, public administration, and research. It also includes entities such as qualified trust service providers and top-level domain name registries.

Important Entities:

This category includes entities from additional sectors such as the food industry, chemical manufacturing, postal and courier services, waste management, manufacturing, production and distribution of digital products, legal and accounting services, and digital service providers.

In general, the Directive applies to medium-sized and large enterprises operating in the aforementioned sectors. However, it may also apply to small and micro-enterprises that play a critical role in society or the economy.

Entities within the public administration whose activities are primarily concerned with national security, public security, defence, or law enforcement are expressly excluded from the scope of the Directive.

Practical Effects of the NIS 2 Directive

The NIS 2 Directive imposes a range of obligations on the entities falling within its scope:

  • Implementation of Cybersecurity Risk Management Measures: This includes measures to identify, protect against, detect, respond to, and recover from cybersecurity incidents.
  • Notification of Significant Cybersecurity Incidents: Entities are required to report incidents that may have a significant impact on the provision of their services.
  • Cooperation in Cybersecurity Information Sharing: The Directive encourages the exchange of information regarding cyber threats, vulnerabilities, and incidents.

To ensure compliance, the Directive establishes supervisory and enforcement regimes:

  • Essential Entities: These are subject to more stringent supervision, including on-site inspections and security audits.
  • Important Entities: These are subject to less stringent, primarily ex post supervision.

The competent authorities in each Member State are responsible for overseeing the implementation of the Directive. In addition, the European Union Agency for Cybersecurity (ENISA) plays a key role in supporting the Directive’s implementation.

Financial regulation changes constantly; at ILP we analyse it to anticipate its impact on our clients.

If you found this article informative, you may also be interested in reading the following:

DORA: The New Paradigm in ICT Incident Reporting for Financial Entities

Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.



Contact
Don’t be left in doubt, get in touch. We’ll be happy to help and offer you solutions.

GUÍA GRATUITA

Regulación Financiera España 2026

DORA + MiCA + MiFID II + EMIR en un solo documento

Descargar gratis →

Videos relacionados

Cargando videos…

Discover more from ILP Abogados

Subscribe now to keep reading and get access to the full archive.

Continue reading