The NIS2 Directive (EU 2022/2555) strengthens cybersecurity requirements for essential and important entities in critical sectors across the EU. It expands the original NIS scope and introduces more severe penalties.
Sectors covered
Energy, transport, banking, financial market infrastructures, healthcare, water, digital infrastructure, managed ICT services, public administration and space.
Key obligations
- Cybersecurity risk management
- Incident notification (24h early warning, 72h notification, 1-month final report)
- Supply chain security
- Management body liability
ermine and NIS2
ermine maps NIS2 controls against your current security posture, manages a supply chain vendor inventory and automates incident notification workflows within regulatory deadlines.