Viri › Zakonodaja › NIS2
Zakonodaja

NIS2 Directive

The Network and Information Security Directive

Direktiva NIS2 (Direktiva (EU) 2022/2555) vzpostavlja skupen okvir kibernetske varnosti v Evropski uniji. Nadomestila je prvotno direktivo NIS ter bistveno razširila nabor sektorjev in organizacij, za katere veljajo zahteve glede obvladovanja tveganj kibernetske varnosti, poročanja o incidentih, upravljanja in nadzora.

NIS2 zajema subjekte v 18 kritičnih sektorjih, vključno z energetiko, prometom, zdravstvom, digitalno infrastrukturo, upravljanjem storitev IKT, javno upravo, proizvodnjo in drugimi kritičnimi dejavnostmi.

ZInfV-1

NIS2 je direktiva EU in ne enoten predpis, ki bi se v vseh državah članicah uporabljal povsem enako. Vsaka država članica jo mora prenesti v svojo nacionalno zakonodajo, 5. člen pa državam članicam izrecno omogoča sprejetje ali ohranitev pravil, ki zagotavljajo višjo raven kibernetske varnosti, kot jo določa sama direktiva. Organizacije morajo zato razumeti tako evropski okvir kot nacionalno zakonodajo, ki velja zanje.

Datum objave 6 October 2026
Legal reference Directive (EU) 2022/2555
Transposition deadline 17 October 2024
01

What is NIS2 and why is it important?

The objective of NIS2 is to achieve a high common level of cybersecurity across the EU. To do this, the Directive requires Member States to establish national cybersecurity strategies, competent authorities, single points of contact and CSIRTs, while imposing cybersecurity risk-management and incident-reporting obligations on essential and important entities.

Direktiva uvaja tudi pravila za nadzor, izvrševanje zahtev in izmenjavo informacij o kibernetski varnosti.

KEY POINT

NIS2 makes cybersecurity a management responsibility, not just an IT issue.

Under Article 20, management bodies of essential and important entities must approve cybersecurity risk-management measures, oversee their implementation and receive cybersecurity training. Compliance therefore requires clear responsibilities and active management involvement.

V primerjavi s predhodno direktivo ima NIS2 širše področje uporabe ter zajema več sektorjev in organizacij. Evropska komisija navaja, da okvir vključuje 18 kritičnih sektorjev in praviloma srednje velike ter velike subjekte, ki delujejo v teh sektorjih. Direktiva določa tudi izjeme, na podlagi katerih lahko nekatere organizacije spadajo na področje njene uporabe ne glede na svojo velikost.  

Kibernetska varnost v okviru NIS2 ni omejena zgolj na oddelek IT. V skladu z 20. členom morajo organi upravljanja bistvenih in pomembnih subjektov odobriti ukrepe za obvladovanje tveganj kibernetske varnosti ter nadzirati njihovo izvajanje. Člani organov upravljanja se morajo tudi usposabljati na področju kibernetske varnosti, države članice pa morajo spodbujati redno usposabljanje zaposlenih.  

Pomemben je tudi okvir za izvrševanje zahtev in sankcioniranje kršitev. Za kršitve 21. ali 23. člena morajo države članice zagotoviti, da lahko najvišje upravne globe za bistvene subjekte znašajo najmanj 10 milijonov evrov ali 2 % skupnega svetovnega letnega prometa, odvisno od tega, kateri znesek je višji. Za pomembne subjekte mora najvišja upravna globa znašati najmanj 7 milijonov evrov ali 1,4 % skupnega svetovnega letnega prometa, odvisno od tega, kateri znesek je višji. Natančen postopek izvrševanja zahtev je urejen z nacionalno zakonodajo.  

Države članice so morale direktivo NIS2 prenesti v svojo nacionalno zakonodajo do 17. oktobra 2024. Vendar prenos direktive v vseh državah članicah ni potekal enako hitro. Evropska komisija je 8. julija 2026 Irsko, Španijo, Francijo in Nizozemsko napotila na Sodišče Evropske unije, ker do takrat niso sporočile popolnega prenosa direktive v nacionalno zakonodajo. To kaže, zakaj morajo organizacije, ki poslujejo na mednarodni ravni, preveriti trenutno stanje nacionalne zakonodaje in se ne zanašati zgolj na besedilo direktive.

02

Does NIS2 apply to your organisation?

The first question is not simply whether your organisation “does cybersecurity”. Applicability depends on the type of activity, size of the entity, and specific exceptions or national rules.

1
Check your sector
NIS2 applies to entity types listed in Annex I and Annex II. Annex I covers sectors of high criticality such as energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space. Annex II covers additional critical sectors including postal and courier services, waste management, chemicals, food, certain manufacturing activities, digital providers, and research.
2
Check the size criteria
Under Article 2, NIS2 generally applies to entities in Annex I or II that qualify as medium-sized enterprises or exceed the ceilings for medium-sized enterprises under the EU SME rules. This is more precise than simply saying that NIS2 applies to every company with a particular number of employees, because the EU SME classification also takes financial and organisational factors into account.
3
Check the exceptions
Some organisations fall within the Directive regardless of size. Examples include certain providers of public electronic communications networks or services, trust service providers, top-level domain registries, and DNS service providers. Member States can also identify entities as critical because of their importance to public safety, public health, systemic risk or essential economic and societal activities.
4
Essential or important entity?
NIS2 distinguishes between essential and important entities. Classification depends on the sector, size, and several special rules. For example, Article 3 treats certain larger Annex I entities as essential, while qualified trust service providers, TLD registries and DNS service providers can be essential regardless of size. Other in-scope entities that do not meet the criteria for essential status are generally classified as important. The distinction matters particularly for supervision and enforcement, but both categories are subject to the core cybersecurity risk-management and incident-reporting requirements.
5
Finally, check the national law
This step is essential. NIS2 is a minimum-harmonisation directive, so Member States may introduce stricter cybersecurity provisions. Registration procedures, competent authorities, national reporting systems, supervisory practices, and other implementation details can therefore differ. For a group operating in several EU countries, applicability should be assessed for the relevant entities against the relevant national implementing legislation in each applicable jurisdiction.
03

Key requirements of NIS2

Odgovornost vodstva in usposabljanje

Cybersecurity governance starts at management level. Management bodies of essential and important entities must approve cybersecurity risk-management measures and oversee their implementation. Members of management bodies must receive training so that they can understand cybersecurity risks and assess their possible impact on the organisation’s services.  

Approval
management approval and oversight of cybersecurity measures
Training
required for management bodies
21
člen

Cybersecurity risk management

Article 21 requires essential and important entities to implement appropriate and proportionate technical, operational and organisational measures to manage risks affecting their network and information systems and to prevent or minimise the impact of incidents. Measures must reflect the organisation’s exposure to risk and the potential consequences of incidents.

Incident handling and business continuity

Risk-management measures must include incident handling as well as business continuity. The Directive specifically refers to backup management, disaster recovery, and crisis management. Organisations therefore need to define responsibilities, escalation procedures and recovery arrangements rather than relying only on preventive controls.

Supply chain security

NIS2 explicitly includes supply chain security, which covers cybersecurity aspects of relationships with direct suppliers and service providers. An organisation’s assessment should therefore extend beyond its internal environment to dependencies that could affect the security or continuity of its services.

Secure acquisition, development and vulnerability management 

Article 21 also covers security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure. This connects cybersecurity requirements with procurement, software development, maintenance, and vulnerability management processes. 

Cyber hygiene, access control and authentication 

The Directive requires measures covering basic cyber hygiene and cybersecurity training, policies and procedures regarding cryptography and encryption, human resources security, access control policies and asset management. It also includes the use of multi-factor authentication or continuous authentication solutions where appropriate.  

23
Article

Significant incident reporting 

NIS2 does not require the full regulatory reporting process for every minor security event. Under Article 23, an incident is significant if it has caused or is capable of causing severe operational disruption or financial loss, or if it has affected or could affect other persons by causing considerable material or non-material damage.  

For a significant incident, the Directive establishes a staged process: an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report no later than one month after the incident notification. Intermediate reports may also be requested.

Additional requirements for certain digital entities

For certain digital infrastructure, ICT service management and digital provider entities, Commission Implementing Regulation (EU) 2024/2690 provides more detailed technical and methodological requirements and further criteria for determining when an incident is significant.  

04

Pot do skladnosti

A practical implementation programme can follow eight steps.

SCOPE

Determine scope and applicable national law

Identify the relevant legal entity, sector and services, assess size and special exceptions, and determine whether the entity is essential or important. Then identify the national legislation implementing NIS2 and the competent authority.

GOVERNANCE

Establish governance and ownership

Define which management body approves cybersecurity measures, who owns individual risks and controls, and who is responsible for regulatory and incident reporting.

ASSETS

Map assets, services, and dependencies

Identify the systems, information, applications, infrastructure, business processes and external providers required to deliver in-scope services.

RISKS

Perform risk and business impact assessments

Assess threats, vulnerabilities, potential disruption, and dependencies. Use the results to prioritise controls and continuity requirements rather than treating every system identically.

CONTROLS

Assess controls against Article 21

Review existing practices for incident management, business continuity, backups, supply chain security, vulnerability management, access control, cryptography, training, and other required areas. Article 21 requires measures to be appropriate and proportionate to risk.

REPORTING

Establish the incident-reporting process

Organisations should know who decides whether an incident is significant, who contacts the relevant CSIRT or authority, which information must be collected and how the 24-hour and 72-hour deadlines will be met.

TESTING

Test continuity and response

Plans should be tested so that backups, recovery, crisis roles, and internal and external communication procedures work in practice.

REVIEW

Review effectiveness and retain evidence

Maintain risk assessments, decisions, assigned responsibilities, completed actions, tests, training records, and other evidence that demonstrates how cybersecurity measures are managed.

For entities covered by Implementing Regulation 2024/2690, ENISA’s NIS2 Technical Implementation Guidance provides additional practical support, including examples of evidence and mappings to relevant standards and frameworks. ENISA published the guidance in June 2025.

05

Kako lahko pomaga Blue Octopus?

Blue Octopus does not replace technical cybersecurity controls, a legal assessment, a competent authority, or an independent audit. Its role is in helping organisations structure the management layer around risks, analyses, responsibilities, and supporting documentation.

NIS2 area
How Blue Octopus can support it
Risk management
Structure, assess and prioritise risks
Ownership
Assign risks and actions to responsible owners
Analysis
Connect findings with risks and priorities
Documentation
Organise relevant documentation alongside analyses and risks
Management overview
Maintain visibility of priorities, responsibilities and open actions
Improvement actions
Track findings and corrective actions over time

Using a management platform does not demonstrate NIS2 compliance. The underlying risk assessments, cybersecurity measures, procedures and evidence still need to satisfy the applicable EU and national requirements.

06
FAQ

Frequently asked questions

Short answers to the most common questions about the scope and requirements of NIS2.

No. Medium-sized and larger organisations in covered sectors form the general scope, but Article 2 includes several situations in which entities can be covered regardless of size.

Both are subject to core NIS2 requirements, but the Directive distinguishes them for classification, supervision and enforcement. Article 3 sets out the detailed classification rules.

Not by itself. ISO/IEC 27001 can provide a useful framework for an information security management system (ISMS), but NIS2 contains specific legal obligations relating to governance, risk-management measures, reporting, and supervision. Compliance must therefore be assessed against the applicable NIS2 requirements and national law.

A supplier may or may not independently fall within NIS2. However, in-scope organisations must address supply chain security and their relationships with direct suppliers and service providers, so cybersecurity requirements can also affect suppliers contractually.

No. The staged Article 23 reporting process applies to significant incidents. The Directive defines the general significance criteria, while Implementing Regulation 2024/2690 provides more detailed criteria for specified categories of digital entities.

No. NIS2 is a minimum-harmonisation directive. Member States may impose a higher level of cybersecurity and implement national procedures, authorities, and enforcement arrangements. Organisations should therefore verify the applicable national transposition law.

07

Uradni viri

08

Naslednji korak

NIS2 readiness requires more than a cybersecurity policy. Organisations need a repeatable process that connects risks, critical services, responsible owners, suppliers, controls, incident response and evidence of implementation. 

Blue Octopus can help organisations structure risks, analyses, responsibilities and supporting documentation in one place, providing a clearer management view of what needs to be addressed and who is responsible.