Interactive Guide to the NIS2 Directive
The tool for Telco companies, Cloud, and digital service providers to understand and apply the new European cybersecurity regulation.
Information updated to June 2025
What is the NIS2 Directive
Directive (EU) 2022/2555, or NIS2, raises the common level of cybersecurity across the EU, repealing the previous NIS1 directive. The goal is to strengthen the resilience of critical infrastructures in the face of increasingly sophisticated cyber threats.
Extended Scope
NIS2 covers a larger number of sectors, introducing a clear distinction between **Essential Entities (EE)** and **Important Entities (IE)**, primarily medium and large enterprises.
Stringent Security Obligations
It mandates a risk-based approach, with mandatory minimum measures in 10 areas, including incident management, supply chain security, and training.
Responsibility of the Executives
Introduce the direct responsibility of management bodies (e.g., Board of Directors) for the approval and supervision of security measures, with penalties in case of non-compliance.
Is my company subject to NIS2?
Select the services your company offers to discover your likely classification and main obligations. The final classification also depends on size criteria (medium/large enterprise).
Analysis Result
Main Obligations:
Test Your Knowledge
Answer these questions to verify your understanding of the key concepts of NIS2.
Frequently Asked Questions (FAQ)
Find quick answers to the most common questions about the NIS2 directive.
NIS2 in Europe
A comparison on the state of transposition of the directive in the main European countries (data as of June 2025).
Useful Sources and Links
Consult official sources for insights and updates.