NIS2 and cybersecurity

NIS2 is a European directive on cybersecurity that broadens the range of organisations with obligations compared with the previous regulation. It concerns not only energy, transport, healthcare and digital infrastructure, but also manufacturing, the food industry, waste management, and providers of digital services above a certain size. The obligations include risk management, supply chain security, incident handling and reporting within set deadlines, and demonstrable accountability of management, which cannot plead ignorance. Even smaller companies that are not themselves obliged will feel the impact indirectly – larger customers will start requiring evidence of security from them as a condition of the contract. Preparation should therefore not be tied only to one's own obligation, but also to customer requirements.

See also: Cybersecurity as an expense, ISO 27001 and its relationship to ISO 42001, AI Supply Chain.