The NIS2 Directive (Network and Information Systems Directive 2) is a key legislative act of the European Union. Its primary goal is to reinforce cybersecurity across EU member states by setting uniform rules and increasing the resilience of critical organizations against cyber threats.
Key Objectives of the NIS2 Directive
- Elevating cybersecurity standards: The directive establishes unified mandates for safeguarding network and information systems across the EU.
- Broader scope than the original NIS: NIS2 expands coverage to additional sectors beyond the original directive, including energy, transport, healthcare, and other essential infrastructure.
- Greater executive responsibility: High priority is placed on the accountability of top management for deploying and maintaining effective cybersecurity measures.
- Stricter penalties: The directive introduces harsher sanctions for non-compliance, including administrative fines of up to EUR 10 million (approx. CZK 250 million) alongside other regulatory enforcement measures.
- Fostering cross-border cooperation: NIS2 promotes information sharing and coordinated action among EU member states in the field of cybersecurity.
Impact on Organizations
The NIS2 Directive covers a wide range of public and private entities providing essential services to society. Covered organizations must implement security measures, handle risks systematically, and notify authorities of major incidents—including reporting critical cybersecurity events to NÚKIB within 24 hours of detection. Details can be found in the information on the new Cybersecurity Act. As a general rule, the law does not apply to individuals, small enterprises (provided they do not meet key criticality criteria), or entities that do not operate within regulated sectors or provide regulated services.