+359 887 407 840 office@escert.com Stara Zagora · Sofia · Plovdiv
BGEN

ResourcesNIS 2Information security

NIS 2 — the Network and Information Security Directive

Who the directive affects and how ISO/IEC 27001 helps with compliance

NIS 2 is the European directive on network and information security — Directive (EU) 2022/2555, which raises the level of cybersecurity across the Member States. It widens the range of organizations that must manage cyber risks and introduces stricter requirements for security measures, incident reporting and supplier oversight.

Euro Standard CertificationThe ESCERT team Published
Updated
4 minread
Server cabinets with network equipment

What is NIS 2?

NIS 2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It replaced the first directive on network and information security and aims to increase the resilience of organizations that provide services important to society and the economy.

Compared with the previous framework, the directive widens the range of organizations that must apply cybersecurity risk-management measures and introduces stricter requirements for information security management, incident reporting and supplier oversight.

With the entry into force of the amendments to the Cybersecurity Act (State Gazette No. 17 of 13 February 2026), the requirements of NIS 2 become mandatory for many organizations in what is known as critical infrastructure.

Which organizations does NIS 2 affect?

NIS 2 affects organizations in critical and important sectors, which the directive divides into two categories — essential and important entities.

Category 1Essential entities

Usually larger organizations in highly critical sectors. They are subject to stricter supervision, which may be preventive.

Category 2Important entities

Organizations in other critical sectors, or smaller organizations in highly critical sectors. They are supervised mainly after a report or an incident.

  • Energy and transportElectricity, gas, oil, district heating and hydrogen; air, rail, water and road transport.
  • HealthcareHealthcare providers and manufacturers of basic pharmaceutical products and certain medical devices.
  • Digital infrastructure and ICT servicesData centres, cloud services, managed ICT service providers and others.
  • Finance and public administrationBanking, financial market infrastructures and public administration bodies.
  • Food and manufacturingProduction, processing and distribution of food, and manufacturing of certain products.
  • Postal services and wastePostal and courier services, waste management, drinking water and waste water.

What does NIS 2 require of organizations?

NIS 2 requires organizations to put in place appropriate technical, operational and organizational measures to manage the risks to their network and information systems, and to report significant incidents.

  • policies on risk analysis and information system security;
  • incident handling;
  • business continuity — backup management, disaster recovery and crisis management;
  • supply chain security and relationships with suppliers;
  • security in the acquisition, development and maintenance of systems, including vulnerability handling;
  • assessment of the effectiveness of the measures;
  • basic cyber hygiene and cybersecurity training;
  • cryptography and encryption;
  • human resources security, access control and asset management;
  • multi-factor authentication and secured communications.

Management bodies approve the measures, oversee their implementation and are accountable for them. In the event of a significant incident, the directive provides for reporting in stages.

  1. Within 24 hours

    An early warning to the competent authority or the incident response team.

  2. Within 72 hours

    An incident notification with an initial assessment of its severity and impact.

  3. Within 1 month

    A final report describing the incident, its causes and the measures taken.

How does ISO/IEC 27001 help with NIS 2 compliance?

ISO/IEC 27001 helps because many of the NIS 2 requirements — risk management, information security policies, incident management, access control and supply chain security — are directly covered by the standard’s framework.

The standard sets out the requirements for building an information security management system (ISMS). Implementing it and certifying to it provide a structured approach to managing risks, security controls and continual improvement. You will find more about the standard in the article ISO/IEC 27001 — information security.

NIS 2 requirements and ISO/IEC 27001
NIS 2 requirementHow ISO/IEC 27001 covers it
Risk analysisRisk assessment and treatment, Statement of Applicability
Incident handlingControls for planning, responding to and learning from incidents
Business continuityControls for security during disruption and ICT readiness
Supply chainControls for security in supplier relationships
Management accountabilityRequirements for leadership, policy and management review

An ISO/IEC 27001 certificate does not replace legal obligations — such as reporting incidents to the competent authorities. It does, however, help you build the policies, processes and controls that NIS 2 requires.

What are the benefits of ISO/IEC 27001 for NIS 2 compliance?

  • A systematic approachCyber risks are managed using a clear, verifiable methodology.
  • Easier complianceThe regulatory requirements of NIS 2 are easier to meet.
  • TrustGreater trust from customers, partners and regulators.
  • Incidents and continuityBetter management of incidents and business continuity.

ISO/IEC 27001 certification is one of the most widely recognized frameworks that help organizations build the policies, processes and controls needed to meet the requirements of NIS 2. For business continuity, see also ISO 22301.

ISO/IEC 27001 certificationQuote within two hours during business hoursRequest a quote

Questions about NIS 2

What is NIS 2?

NIS 2 is Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. It introduces requirements for cybersecurity risk management and incident reporting.

Is ISO/IEC 27001 mandatory under NIS 2?

The directive does not require a specific certificate. However, ISO/IEC 27001 covers a large part of the required measures and is a recognized way of demonstrating a systematic approach to security.

What is the difference between essential and important entities?

Both categories apply risk-management measures and report incidents. The difference lies mainly in the supervisory regime, which is stricter for essential entities.

Within what timeframes must a significant incident be reported?

The directive provides for an early warning within 24 hours, a notification within 72 hours and a final report within one month.

Free preliminary assessment and quote

Prepare for NIS 2 with ISO/IEC 27001 — quote within two hours

Describe your activity, locations and the number of employees within the scope — you will receive a quote with the scope, the audit duration and an all-inclusive price.