What the framework addresses
NIS2 widens the scope of the earlier NIS framework and addresses cybersecurity risk management, reporting of significant incidents, governance, supervision and cooperation. The Commission describes coverage across 18 sectors.
Essential and important entities
The Directive distinguishes essential and important entities. Classification is connected to sector, type of entity, size and specific rules or exceptions. The label affects the supervisory approach, but it should not be assigned based on a sector name alone.
How to read this site
- Who is affected explains the scope review.
- Requirements groups the main obligations.
- Implementation connects them to practical work.
Official sources and context
Use these alongside the applicable national legislation and authority guidance. This page is general information and may not reflect every national measure or later amendment.