European Union emblem.

NIS2 is Directive (EU) 2022/2555, establishing measures for a high common level of cybersecurity across the EU. It addresses cybersecurity risk management, reporting and supervision for entities within its scope. It is a directive, not a regulation. See the official NIS2 text.

Establish the applicable obligations

Determine the relevant entity, activities, sector, jurisdiction and national implementing measures. Essential and important entity classifications and any sector-specific rules need to be assessed in that context.

The directive's scope extends beyond a generic list of critical infrastructure. Outsourcing systems does not by itself remove the relevant entity's cybersecurity responsibilities.

Use in CSFaaS

The reviewed library lists EU NIS2 - EN. Use the imported structure to organise assessment, owners, policy controls and evidence, while retaining the authoritative national and EU sources relevant to the organisation.

Connect business context, systems, third parties and risk work to the requirements they support. Review reporting and governance obligations through the appropriate operational process; an application score or framework approval does not determine legal applicability or fulfil all reporting duties.