NIS2 introduces a harmonised legal framework to strenghten cybersecurity within 18 critical sectors throughout the EU. Beyond those previously included under the NIS1 Directive - such as energy, transport, healthcare, financial services, water management, and digital infrastructure – NIS2 extends to providers of public electronic communications, a broader range of digital service providers (including social media platforms), waste and wastewater management, manufacturing of critical products (medical devices, computers, electronics, motor vehicles), food production and distribution, chemicals, postal and courier services, public administration, and the space sector.
NIS2 APPLICABILITY SELF-ASSESSMENT
NIS2 APPLICABILITY SELF-ASSESSMENT
Does your business fall under the NIS2 Directive?
We have prepared a brief short self-assessment tool to check whether your organisation is likely to be subject to the requirements of Network and Information Systems Directive 2 (Directive (EU) 2022/2025) ("NIS2"): the EU’s strengthened cyber-security framework for essential and important entities.
Why this matters:
If your business is in scope of NIS2, it may soon face obligations around cyber-risk management, reporting, governance accountability and potentially significant penalties for non-compliance.
Status of NIS2 implementation across EU jurisdictions
(Date of publication: July 2026. This map is based on publicly available information. We will continue to review and update it on a regular basis as new information becomes available.)