NIS2 duties in 10 points

Last updated: 2023-09-26

Summary of basic measures for NIS2

NIS2, through the national acts in each country, defines a number of obligations and measures that organizations must meet. The goal of NIS2 is to increase cybersecurity resilience against cyber attacks and threats across the EU. Therefore the organization must implement preventive measures as well as be able to respond to cyber attacks correctly and report them to national authorities. Basic measures concern these topics

  • Cyber & Information Security Policies
  • Incident Management
  • Business Continuity
  • Supply Chain Security
  • Training
  • IT Asset Management
  • Reporting Obligations

What you need to do to meet duties for NIS2

The measures and obligations that organizations and companies have to implement due to NIS2 can be briefly summarized in these 10 basic steps:

  1. make an overview of your essential and most important data and other IT assets = keep assets 
  2. know your risks and weaknesses = make a risk assessment and implement risk management
  3. ensure you have access to your data under control 
  4. educate your employees, give them basics of information security, it can save you most troubles 
  5. have your IT processes and technologies under control, ensure the security of your IT - applications, software, hardware, and other IT equipment
  6. have external IT services and their suppliers, including cloud services, under control
  7. be able to respond to and protect against various cyber attacks  
  8. be able to recover your data and operations after an attack or disaster
  9. implement information security policies
  10. ensure improvement of the above, be sure you are focusing on important issues

Each organization is different and so individual-specific measures. Individual-specific measures will differ in each organization because each organization is the other.

You can view a more detailed list of measures for NIS2 in the following articles.

NIS2 in 10 points