{"id":24764,"date":"2024-06-26T06:30:07","date_gmt":"2024-06-26T14:30:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/06\/26\/news-18494\/"},"modified":"2024-06-26T06:30:07","modified_gmt":"2024-06-26T14:30:07","slug":"news-18494","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/06\/26\/news-18494\/","title":{"rendered":"EU NIS 2 Directive: what it is and how to prepare for it | Kaspersky official blog"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/26092738\/what-is-nis2-directive-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Alanna Titterington| Date: Wed, 26 Jun 2024 13:31:08 +0000<\/strong><\/p>\n<p>Today&#8217;s topic is the NIS 2 Directive, which aims to improve the cyber-resilience of critical infrastructure and essential and important entities. NIS 2 looks set to do for information security in the EU what GDPR did for user data privacy.<\/p>\n<p>It won&#8217;t be long now before the new directive will be transposed into national law, so if your organization is not yet ready, now&#8217;s the time to take steps.<\/p>\n<h2>What is NIS 2?<\/h2>\n<p>The revised Network and Information Security Directive (<a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/nis2-directive\">NIS 2<\/a>) is the EU-wide legislation on cybersecurity. NIS 2 updates and complements the original NIS Directive, adopted in 2016, and creates a legal framework to enhance the overall level of cybersecurity across the EU.<\/p>\n<p>The updated NIS 2 Directive focuses on three main areas:<\/p>\n<ul>\n<li><strong>Expanding the scope of application<\/strong>: the seven sectors covered by the original NIS Directive are supplemented by a number of new ones<\/li>\n<li><strong>New mechanisms for incident reporting and information sharing<\/strong>: NIS 2 mandates the timely reporting of significant incidents<\/li>\n<li><strong>Tighter enforcement of compliance<\/strong>: the updated NIS 2 introduces specific sanctions for non-compliance, including fines of up to 2% of global annual turnover<\/li>\n<\/ul>\n<h2>What organizations does NIS 2 apply to?<\/h2>\n<p>As mentioned above, the revised directive <em>significantly<\/em> broadens the scope of application compared to the original 2016 version. In addition, NIS 2 introduces a classification that divides the covered sectors into two categories:<\/p>\n<ul>\n<li><strong>Sectors of high criticality (Annex I):<\/strong>\n<ul>\n<li>Energy (electricity, district heating &amp; cooling, gas, hydrogen, oil)<\/li>\n<li>Transport (air, rail, water, road)<\/li>\n<li>Banking<\/li>\n<li>Financial market infrastructure<\/li>\n<li>Health<\/li>\n<li>Drinking water<\/li>\n<li>Waste water<\/li>\n<li>Digital infrastructure<\/li>\n<li>ICT-service management (MSP, MSSP)<\/li>\n<li>Public administration entities<\/li>\n<li>Space<\/li>\n<\/ul>\n<\/li>\n<li><strong>Other critical sectors (Annex II):<\/strong>\n<ul>\n<li>Postal and courier services<\/li>\n<li>Waste management<\/li>\n<li>Manufacture, production, and distribution of chemicals<\/li>\n<li>Production, processing, and distribution of food<\/li>\n<li>Manufacturing (medical devices, computer, electronic, or optical products, electrical equipment, machinery, motor vehicles, other transport equipment)<\/li>\n<li>Digital providers<\/li>\n<li>Research<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>Besides classifying sectors, NIS 2 introduces an additional classification of specific entities. It too consists of two categories:<\/p>\n<ul>\n<li><strong>Essential (Article 3.1):<\/strong>\n<ul>\n<li>Large entities (annual revenue of over \u20ac50 million) in sectors of high criticality<\/li>\n<li>Certification authorities, top-level domain registrars, and DNS providers, regardless of size of the business<\/li>\n<li>Telecom providers, from medium-sized upwards (revenue over \u20ac10 million)<\/li>\n<li>Public administration institutions<\/li>\n<li>Any entity belonging to a highly critical or other critical sector that&#8217;s defined by an EU Member State as <em>essential<\/em><\/li>\n<li>Entities defined as <em>critical<\/em> under <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2557\/oj\">Directive (EU) 2022\/2557<\/a><\/li>\n<\/ul>\n<\/li>\n<li><strong>Important (Article 3.2):<\/strong>\n<ul>\n<li>Medium-sized entities (annual revenue of \u20ac10-50 million) in highly critical sectors<\/li>\n<li>Medium and large entities in other critical sectors<\/li>\n<li>Any entity that&#8217;s defined by an EU Member State as <em>important<\/em><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>The category an entity belongs to has significant practical implications. The activities of entities classified as <em>essential<\/em> will be subject to much stricter and proactive oversight, including random raids, special security checks, and requests for proof of compliance. For non-compliance with NIS 2, <strong><em>essential<\/em> entities may face a fine of up to \u20ac10 million or 2% of global annual turnover<\/strong>.<\/p>\n<p>Entities classified as important can breathe a bit more easily \u2014 they&#8217;re subject to less stringent controls. <strong>For <em>important<\/em> entities, the penalties are slightly more modest: up to \u20ac7 million or 1.4% of global annual turnover<\/strong>.<\/p>\n<h2>NIS 2 timeline<\/h2>\n<p>Note that, unlike GDPR, NIS 2 is a <a href=\"https:\/\/european-union.europa.eu\/institutions-law-budget\/law\/types-legislation_en\">directive<\/a>, \u2014 not a <em>regulation<\/em> of the European Union. This means that EU Member States are legally required to amend their national legislation within the designated time frame. In the case of NIS 2, the deadline is set for October 17, 2024.<\/p>\n<p>In addition, EU Member States will have to draw up lists of <em>essential<\/em> and <em>important<\/em> entities subject to NIS 2 by April 17, 2025.<\/p>\n<p>It will be useful to revisit the timeline of the main stages of NIS 2:<\/p>\n<ul>\n<li>July 6, 2016: adoption of <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2016\/1148\/oj\">Directive (EU) 2016\/1148<\/a>, the original NIS<\/li>\n<li>May 9, 2018: deadline for EU Member States to transpose the NIS Directive into their national legislation<\/li>\n<li>July 7, 2020: start of European Commission (EC) consultations on the revision of NIS<\/li>\n<li>December 16, 2020: publication of the proposal for NIS2 by the EC<\/li>\n<li>May 13, 2022: European Parliament vote on adoption of the NIS 2 Directive<\/li>\n<li>November 10, 2022: approval of the NIS 2 Directive by the Council of the EU<\/li>\n<li>December 14, 2022: publication of the NIS 2 Directive in the Official Journal of the EU under the title <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/oj\">Directive (EU) 2022\/2555<\/a><\/li>\n<li>January 16, 2023: entry into force of the NIS 2 Directive<\/li>\n<li>October 17, 2024: deadline for EU Member States to transpose the NIS 2 Directive into their national legislation<\/li>\n<li>April 17, 2025: deadline for EU Member States to draw up lists of <em>essential<\/em> and <em>important<\/em> These lists must be updated regularly thereafter \u2014 at least every two years<\/li>\n<li>October 17, 2027: review of the NIS 2 Directive<\/li>\n<\/ul>\n<h2>How to prepare for NIS 2 implementation?<\/h2>\n<ul>\n<li>Assess whether, and to what extent, the requirements of NIS 2 apply to your organization<\/li>\n<li>Investigate how the NIS Directive was transposed into the national legislation in your EU Member State<\/li>\n<li>Follow the recommendations of national cybersecurity authorities<\/li>\n<li>Assess and develop technical, operational, and organizational measures for managing network and information systems; security risks<\/li>\n<\/ul>\n<p>More information about the updated EU Network and Information Security Directive, and how organizations can prepare for its entry into force, is available on our <a href=\"https:\/\/go.kaspersky.com\/nis2-directive.html\">dedicated NIS 2 site<\/a>.<\/p>\n<p><a href=\"https:\/\/www.kaspersky.com\/blog\/what-is-nis2-directive\/51536\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2024\/06\/26092738\/what-is-nis2-directive-featured.jpg\"\/><\/p>\n<p><strong>Credit to Author: Alanna Titterington| Date: Wed, 26 Jun 2024 13:31:08 +0000<\/strong><\/p>\n<p>What is the NIS 2 Directive, which companies are affected, what are the consequences of non-compliance, and how to prepare for it.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[1001,12534,10420,12177,7598,12116,12553,31584,21293,31585,714,12321,10438],"class_list":["post-24764","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-business","tag-compliance","tag-critical-infrastructure","tag-enterprise","tag-eu","tag-gdpr","tag-ics","tag-industrial-control-system-security","tag-industrial-security","tag-nis-2","tag-security","tag-smb","tag-threats"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24764","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24764"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24764\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24764"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24764"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24764"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}