Parameter

What is NIS2?

NIS2 Directive

What the EU NIS2 Directive requires, which entities it covers, the 24-hour reporting rule, management liability and fines.

01Introduction

NIS2 extends EU cybersecurity law to thousands of mid-sized and large companies in sectors from energy and health to digital providers and manufacturing. Many are subject to it for the first time.

02What is NIS2?

The NIS2 Directive (EU 2022/2555) replaces the original NIS Directive. Member states had to transpose it into national law by 17 October 2024. It covers essential and important entities across 18 sectors and requires risk-management measures, incident reporting and supply chain security.

Article 21 lists minimum measures, including policies to assess the effectiveness of security controls, vulnerability handling and secure development. Article 23 sets reporting deadlines: an early warning within 24 hours, a notification within 72 hours and a final report within a month. Fines reach at least €10 million or 2% of global turnover for essential entities, and management can be held personally liable.

03How NIS2 works

Obligations depend on national transposition, but the structure is shared.

  1. 1.

    Determine scope

    Check sector and size thresholds, and register with the national authority.

  2. 2.

    Risk measures

    Implement Article 21 measures, approved and overseen by management, who must be trained.

  3. 3.

    Test effectiveness

    Assess controls through vulnerability management and penetration testing.

  4. 4.

    Report incidents

    Meet the 24-hour, 72-hour and one-month reporting timeline through incident response.

04Threats and risks

NIS2 is aimed at weaknesses exposed by recent attacks on European infrastructure.

  • Supply chain attacks

    Compromise through suppliers and service providers.

  • Ransomware

    Disruption to essential services such as hospitals and utilities.

  • Unmanaged vulnerabilities

    Known flaws left open on internet-facing systems.

  • Personal liability

    Management bodies accountable for failures to implement measures.

05How Parameter helps

Parameter helps demonstrate that security measures are effective, not just in place.

  • Effectiveness testing

    The pentesting agents test applications continuously and prove what is exploitable.

  • Vulnerability handling

    EASM and scanning keep the external surface under watch.

  • Supply chain security

    Supply Chain tracks third-party code risk, an explicit NIS2 measure.

[ AI Pentesting ]

See how Parameter AI Pentesting fits your NIS2 program.

Autonomous agents that find, prove and fix what matters. Every finding ships with evidence.