NIS2 Directive

The Directive 2022/2555 of the European Parliament and of the Council, known as NIS2, is the cybersecurity legislation adopted for the entire European Union. It provides legal measures to increase the overall level of cybersecurity in the EU and the resilience of critical infrastructures and digital services in Europe. It sets out cybersecurity, oversight and enforcement obligations for Member States, risk management measures and notification obligations for entities in its scope (Annexes I and II) and concerning the exchange of cybersecurity information. 

The directive entered into force in January 2023 and should have been transposed before October 17, 2024. 

Consultation service

The National Cryptologic Centre has set up a service to help entities comply with the technical, operational and organisational measures of the NIS2. They can send their queries to the mailbox: 

nis2

Teaching material

Qué es la NIS2

¿Qué es la NIS2?

Requerimientos de la Directiva NIS2

Requerimientos de la Directiva NIS2

Ámbito de aplicación | Sector público

Ámbito de aplicación | Sector público


Frequently asked questions (FAQ) 

Directive (EU) 2022/2555 of 14 December 2022 (NIS2 Directive), which will update and repeal Directive (EU) 2016/1148 of 6 July 2016, known as the NIS1 Directive, is a European legal norm that aims to establish a regulatory framework to ensure a high level of security in network and information systems across the European Union, with the objective of achieving a high common level of cybersecurity.

To this end, obligations are established to be adopted by those entities included in its scope of application. These obligations take the form of obligations to notify and exchange information on incidents and appropriate technical, operational and organisational security measures, established to manage the cybersecurity risks of the information systems and networks used by these entities in their operations or in the provision of their services. 

In order to better adapt the cybersecurity requirements applicable to entities within its scope, the NIS2 Directive distinguishes between critical and important entities. In any case, the 10 groupings of security measures set out in Article 21 will apply to both types of entities, although with a higher level of requirements for critical entities.