The NIS2 Directive is the EU-wide legislation on cybersecurity. It provides legal measures to boost the overall level of cybersecurity in the EU.
The EU's NIS2 Directive has arrived, bringing stricter cybersecurity regulations to vital sectors like energy, water, and transportation. Operational Technology (OT) systems, the backbone of our critical infrastructure, are now under the spotlight, requiring organizations to ramp up their security posture to ensure the continued operation of essential services. You can read my full article on NIS2, who it impacts, expectations…etc here.
The NIS2 Directive, designed to bolster cybersecurity across the European Union, has progressed from legislation to implementation. This article examines the current state of NIS2 since its enforcement, member state progress, potential penalties, and implications.
The most significant update is that many EU member states have been slow to transpose the NIS2 Directive into their national legal frameworks.
Member states are in varying stages of transposing NIS2 into national law.
NIS2 Implementation Progress
Member State |
Current Status |
Notes |
Belgium, Romania, Hungary, Lithuania, Italy, Latvia, Slovakia, Croatia, Greece |
ADOPTED NIS2 LAWS |
National laws in effect. |
Germany, Sweden, The Netherlands, Poland, Finland, Austria, Denmark, Bulgaria, Portugal, Luxembourg, Slovenia, Cyprus, Czech Republic, France, Ireland, Malta, Estonia |
DRAFT NIS2 LAWS |
Undergoing national legislative procedures |
Spain |
COUNTRIES AWAITING DRAFT NIS2 LAWS |
Public consultations underway. |
As NIS2 is relatively new, concrete examples of fines are still emerging. It is expected that enforcement will increase as national laws fully come into force. A key question for many is about enforcement and fines.
To support the implementation of the directive, key resources have been released:.
NIS2 is driving a fundamental shift in cybersecurity across the EU. While implementation is ongoing and enforcement actions are still developing, the directive is placing greater emphasis on security, especially in OT and NCI sectors. Organizations must stay informed, prioritize compliance, and enhance their cybersecurity posture to meet the new regulatory landscape.
--------------------
Author: Vinny Sagar, Field Strategist, swIDch
With over 15 years of experience in pre-sales, consulting and software development in the Identity and Cyber Security space Vinny has helped many clients across various industries and regions to design and deploy Zero Trust solutions that meet their specific needs and challenges.
--------------------
swIDch will continue its quest to innovate and pioneer next-generation authentication solutions. To stay up-to-date with the latest trends sign up to our newsletter and check out our latest solutions.