NIS2 (Network & Information Security)

The NIS2 Directive is now in effect as of January 16th, 2023.

We help you implement NIS2 and achieve compliance while also identifying strategic opportunities to strengthen your organisation’s resilience against threats and cyberattacks.

NIS2 (Network & Information Security)

NIS2 Directive Defined

The NIS2 Directive (Network and Information Security Directive) is the EU’s updated cybersecurity legislation aimed at strengthening the collective resilience of critical infrastructure, essential services, and digital providers.

NIS2 addresses the growing cybersecurity risks across borders, sectors, and supply chains by introducing stricter, harmonised requirements for risk management, incident reporting, and governance.

Broader Scope

NIS2 broadens the scope of critical sectors, extending beyond essential services.

Enhanced Cooperation

NIS2 emphasises increased cooperation and information sharing among member states.

Reporting Obligations

NIS2 introduces mandatory incident reporting for a broader range of entities.

Article Series: Insights & Best Practices

Explore the most common pitfalls companies face under the NIS2 Directive, and how to avoid them. This article series breaks down common mistakes, uncovers the reasons behind them, and offers clear, actionable recommendations to strengthen your cyber resilience and compliance strategy.

Cyber & Digital Risk, NIS2, Key features, introduction to NIS2

NIS2 Summarised

The NIS2 Directive strengthens EU cybersecurity by broadening critical sector coverage, improving member state cooperation, and enforcing mandatory incident reporting for swift response and mitigation of cyber threats.

Learn more

Who is affected by NIS2?

NIS2 affects all member states of the European Union, as it establishes requirements and regulations that must be adhered to by entities within those states.

Learn more

Cyber & Digital Risk, NIS2, Who is affected
Cyber & Digital Risk, NIS2, Key features

What is the difference between NIS2 and NIS?

Overall, NIS2 strengthens and expands upon the framework established by NIS to address evolving cybersecurity challenges and enhance the EU’s cyber resilience.

Learn more

Introduction of NIS2

NIS2 affects all entities that provide essential or critical services to the European economy and society, both companies and suppliers. This article presents 8 steps to prepare for NIS2.

Learn more

Overview of a city in sunset

Navigating the Transition

NIS2 aims to address emerging threats, technological advancements, and the evolving digital landscape. This article is about understanding NIS2 and its implications.

Learn more

NIS2 DIrective Compliance Network and information system

Discover the potential of NIS2 and make your organisation more resilient.

Our NIS2 Services

Advisense is uniquely positioned to guide you through the complex regulatory landscape and to support you with the necessary analyses and actions for a NIS2 implementation.

Our team of 100 experienced information and cyber security consultants combine regulatory, security, and technological expertise, offering leading-edge insights and knowledge.

GAP & Maturity Assessments

Directive Requirements

Organisations must implement proportionate risk-based cybersecurity measures and leadership holds legal accountability.

Example services

  • GAP/maturity assessments (ISO 27001)
  • Information security strategy
  • Integration of cybersecurity into GRC
  • CISO as a Service

NIS2 Article
Articles 20, 21.1, 21.2

Incident Management

Directive Requirements
Entities must report significant incidents (24h/72h) and ensure business continuity and crisis handling capabilities.

Example services

  • Incident response plans
  • Roles & responsibilities
  • Supervisory reporting preparation
  • Crisis & continuity management

NIS2 Article
Articles 13, 21.2(b–c), 23

Security Testing & Vulnerability Management

Directive Requirements
Entities must manage vulnerabilities and ensure secure system development and testing practices.

Example services

  • Penetration testing
  • Risk-based testing frameworks
  • Vulnerability disclosure
  • Policy for managing testing outcomes

NIS2 Article
Articles 12, 21.2(e)

Outsourcing & Third-Party Risk Management

Directive Requirements
Entities must assess and manage security risks in supply chains and outsourced services, including MSPs.

Example services

  • Third-party reviews
  • Critical supplier oversight
  • Outsourcing security assessments
  • Risk analysis (all-hazards approach)

NIS2 Article
Articles 21.2(d), 22, 85–86

Get Tailored Advice on NIS2

Please describe what you are interested in (please refrain from providing sensitive personal information)
This field is for validation purposes and should be left unchanged.

Client stories