StructureClerk

NIS2

Also known as: NIS2 Directive · EU cybersecurity directive

NIS2 is the European directive imposing cybersecurity measures and incident-notification duties on entities classed as essential or important.

It widens the scope of the directive it replaces considerably, covering whole sectors rather than operators designated one by one: energy, transport, health, digital infrastructure — but also manufacturing, food, and waste management.

It engages management by name: governing bodies must approve risk-management measures and can be held liable for failing to. That is a change in kind, not in degree.

It sets a staged notification chain after a significant incident is detected, which presupposes having decided in advance who declares, to whom, and on what criteria.

What it means for a small business

A small business can be affected without being a designated entity itself: supply-chain security requirements push the questions down to suppliers, through contracts.

The NIS2 page

So what actually applies to you?

A definition tells you what a term means, not what your organization must do. The assessment answers the second question — free, no credit card.

Updated September 1, 2026 · Educational definition; not legal advice.