GlossaryGlossary

NIS2

NIS2 is the EU cybersecurity directive that sets risk management, incident reporting, governance, and supply-chain expectations for covered entities.

August 31, 2026Updated August 2026
NIS2Cybersecurity regulationIncident response

NIS2 is the common name for the EU Directive on measures for a high common level of cybersecurity across the Union.

It addresses cybersecurity risk management, incident handling and reporting, business continuity, supply-chain security, governance, and related organizational responsibilities for entities covered by national implementation rules.

Whether a particular business is in scope depends on its sector, services, size, structure, country, and national rules. Businesses outside direct scope can still face customer, supplier, insurance, or procurement requirements connected to NIS2 expectations.

This glossary entry is educational, not legal advice. Start with the NIS2 compliance and incident readiness guide and verify scope with the relevant official authority.