NIS2 Directive
The Network and Information Security Directive
Direktiva NIS2 (Direktiva (EU) 2022/2555) vzpostavlja skupen okvir kibernetske varnosti v Evropski uniji. Nadomestila je prvotno direktivo NIS ter bistveno razširila nabor sektorjev in organizacij, za katere veljajo zahteve glede obvladovanja tveganj kibernetske varnosti, poročanja o incidentih, upravljanja in nadzora.
NIS2 zajema subjekte v 18 kritičnih sektorjih, vključno z energetiko, prometom, zdravstvom, digitalno infrastrukturo, upravljanjem storitev IKT, javno upravo, proizvodnjo in drugimi kritičnimi dejavnostmi.
NIS2 je direktiva EU in ne enoten predpis, ki bi se v vseh državah članicah uporabljal povsem enako. Vsaka država članica jo mora prenesti v svojo nacionalno zakonodajo, 5. člen pa državam članicam izrecno omogoča sprejetje ali ohranitev pravil, ki zagotavljajo višjo raven kibernetske varnosti, kot jo določa sama direktiva. Organizacije morajo zato razumeti tako evropski okvir kot nacionalno zakonodajo, ki velja zanje.
What is NIS2 and why is it important?
The objective of NIS2 is to achieve a high common level of cybersecurity across the EU. To do this, the Directive requires Member States to establish national cybersecurity strategies, competent authorities, single points of contact and CSIRTs, while imposing cybersecurity risk-management and incident-reporting obligations on essential and important entities.
Direktiva uvaja tudi pravila za nadzor, izvrševanje zahtev in izmenjavo informacij o kibernetski varnosti.
NIS2 makes cybersecurity a management responsibility, not just an IT issue.
Under Article 20, management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation and receive cybersecurity training. Compliance therefore requires clear responsibilities and active management involvement.
V primerjavi s predhodno direktivo ima NIS2 širše področje uporabe ter zajema več sektorjev in organizacij. Evropska komisija navaja, da okvir vključuje 18 kritičnih sektorjev in praviloma srednje velike ter velike subjekte, ki delujejo v teh sektorjih. Direktiva določa tudi izjeme, na podlagi katerih lahko nekatere organizacije spadajo na področje njene uporabe ne glede na svojo velikost.
Kibernetska varnost v okviru NIS2 ni omejena zgolj na oddelek IT. V skladu z 20. členom morajo organi upravljanja bistvenih in pomembnih subjektov odobriti ukrepe za obvladovanje tveganj kibernetske varnosti ter nadzirati njihovo izvajanje. Člani organov upravljanja se morajo tudi usposabljati na področju kibernetske varnosti, države članice pa morajo spodbujati redno usposabljanje zaposlenih.
Pomemben je tudi okvir za izvrševanje zahtev in sankcioniranje kršitev. Za kršitve 21. ali 23. člena morajo države članice zagotoviti, da lahko najvišje upravne globe za bistvene subjekte znašajo najmanj 10 milijonov evrov ali 2 % skupnega svetovnega letnega prometa, odvisno od tega, kateri znesek je višji. Za pomembne subjekte mora najvišja upravna globa znašati najmanj 7 milijonov evrov ali 1,4 % skupnega svetovnega letnega prometa, odvisno od tega, kateri znesek je višji. Natančen postopek izvrševanja zahtev je urejen z nacionalno zakonodajo.
Države članice so morale direktivo NIS2 prenesti v svojo nacionalno zakonodajo do 17. oktobra 2024. Vendar prenos direktive v vseh državah članicah ni potekal enako hitro. Evropska komisija je 8. julija 2026 Irsko, Španijo, Francijo in Nizozemsko napotila na Sodišče Evropske unije, ker do takrat niso sporočile popolnega prenosa direktive v nacionalno zakonodajo. To kaže, zakaj morajo organizacije, ki poslujejo na mednarodni ravni, preveriti trenutno stanje nacionalne zakonodaje in se ne zanašati zgolj na besedilo direktive.
Does NIS2 apply to your organisation?
The first question is not simply whether your organisation “does cybersecurity”. Applicability depends on the type of activity, size of the entity, and specific exceptions or national rules.
Key requirements of NIS2
Odgovornost vodstva in usposabljanje
Cybersecurity governance starts at management level. Management bodies of essential and important entities must approve cybersecurity risk-management measures and oversee their implementation. Members of management bodies must receive training so that they can understand cybersecurity risks and assess their possible impact on the organisation’s services.
Cybersecurity risk management
Article 21 requires essential and important entities to implement appropriate and proportionate technical, operational and organisational measures to manage risks affecting their network and information systems and to prevent or minimise the impact of incidents. Measures must reflect the organisation’s exposure to risk and the potential consequences of incidents.
Incident handling and business continuity
Risk-management measures must include incident handling as well as business continuity. The Directive specifically refers to backup management, disaster recovery, and crisis management. Organisations therefore need to define responsibilities, escalation procedures and recovery arrangements rather than relying only on preventive controls.
Supply chain security
NIS2 explicitly includes supply chain security, which covers cybersecurity aspects of relationships with direct suppliers and service providers. An organisation’s assessment should therefore extend beyond its internal environment to dependencies that could affect the security or continuity of its services.
Secure acquisition, development and vulnerability management
Article 21 also covers security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. This connects cybersecurity requirements with procurement, software development, maintenance, and vulnerability management processes.
Cyber hygiene, access control and authentication
The Directive requires measures covering basic cyber hygiene and cybersecurity training, policies and procedures regarding cryptography and encryption, human resources security, access control policies and asset management. It also includes the use of multi-factor authentication or continuous authentication solutions where appropriate.
Significant incident reporting
NIS2 does not require the full regulatory reporting process for every minor security event. Under Article 23, an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or if it has affected or could affect other persons by causing considerable material or non-material damage.
For a significant incident, the Directive establishes a staged process: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Intermediate reports may also be requested.
Additional requirements for certain digital entities
For certain digital infrastructure, ICT service management and digital provider entities, Commission Implementing Regulation (EU) 2024/2690 provides more detailed technical and methodological requirements and further criteria for determining when an incident is significant.
Pot do skladnosti
A practical implementation programme can follow eight steps.
Determine scope and applicable national law
Identify the relevant legal entity, sector and services, assess size and special exceptions, and determine whether the entity is essential or important. Then identify the national legislation implementing NIS2 and the competent authority.
Establish governance and ownership
Define which management body approves cybersecurity measures, who owns individual risks and controls, and who is responsible for regulatory and incident reporting.
Map assets, services, and dependencies
Identify the systems, information, applications, infrastructure, business processes and external providers required to deliver in-scope services.
Perform risk and business impact assessments
Assess threats, vulnerabilities, potential disruption, and dependencies. Use the results to prioritise controls and continuity requirements rather than treating every system identically.
Assess controls against Article 21
Review existing practices for incident management, business continuity, backups, supply chain security, vulnerability management, access control, cryptography, training, and other required areas. Article 21 requires measures to be appropriate and proportionate to risk.
Establish the incident-reporting process
Organisations should know who decides whether an incident is significant, who contacts the relevant CSIRT or authority, which information must be collected and how the 24-hour and 72-hour deadlines will be met.
Test continuity and response
Plans should be tested so that backups, recovery, crisis roles, and internal and external communication procedures work in practice.
Review effectiveness and retain evidence
Maintain risk assessments, decisions, assigned responsibilities, completed actions, tests, training records, and other evidence that demonstrates how cybersecurity measures are managed.
For entities covered by Implementing Regulation 2024/2690, ENISA’s NIS2 Technical Implementation Guidance provides additional practical support, including examples of evidence and mappings to relevant standards and frameworks. ENISA published the guidance in June 2025.
Kako lahko pomaga Blue Octopus?
Blue Octopus does not replace technical cybersecurity controls, a legal assessment, a competent authority, or an independent audit. Its role is in helping organisations structure the management layer around risks, analyses, responsibilities, and supporting documentation.
Using a management platform does not demonstrate NIS2 compliance. The underlying risk assessments, cybersecurity measures, procedures and evidence still need to satisfy the applicable EU and national requirements.
Frequently asked questions
Short answers to the most common questions about the scope and requirements of NIS2.
No. Medium-sized and larger organisations in covered sectors form the general scope, but Article 2 includes several situations in which entities can be covered regardless of size.
Both are subject to core NIS2 requirements, but the Directive distinguishes them for classification, supervision and enforcement. Article 3 sets out the detailed classification rules.
Not by itself. ISO/IEC 27001 can provide a useful framework for an information security management system (ISMS), but NIS2 contains specific legal obligations relating to governance, risk-management measures, reporting, and supervision. Compliance must therefore be assessed against the applicable NIS2 requirements and national law.
A supplier may or may not independently fall within NIS2. However, in-scope organisations must address supply chain security and their relationships with direct suppliers and service providers, so cybersecurity requirements can also affect suppliers contractually.
No. The staged Article 23 reporting process applies to significant incidents. The Directive defines the general significance criteria, while Implementing Regulation 2024/2690 provides more detailed criteria for specified categories of digital entities.
No. NIS2 is a minimum-harmonisation directive. Member States may impose a higher level of cybersecurity and implement national procedures, authorities, and enforcement arrangements. Organisations should therefore verify the applicable national transposition law.
Uradni viri
Naslednji korak
NIS2 readiness requires more than a cybersecurity policy. Organisations need a repeatable process that connects risks, critical services, responsible owners, suppliers, controls, incident response and evidence of implementation.
Blue Octopus can help organisations structure risks, analyses, responsibilities and supporting documentation in one place, providing a clearer management view of what needs to be addressed and who is responsible.