The NIS2 Directive Explained for Website Owners

NIS2 is the European Union’s updated cybersecurity law for essential and important organisations. It widens the scope of the original 2016 NIS directive, raises the baseline security expected of covered entities, and puts real accountability on management. If your business operates in certain sectors, it may now apply to you even if it did not before.

The short version

NIS2 (Directive (EU) 2022/2555) expands EU cybersecurity rules to more sectors, sets a common baseline of risk-management measures, and adds incident reporting and management accountability. It is implemented through each member state’s national law. Check whether your sector and size bring you into scope, then work on the technical baseline. This is general information, not legal advice.

What NIS2 actually is

NIS2 replaces the first Network and Information Security directive from 2016. The original left too many gaps and was applied inconsistently across member states. NIS2 broadens the range of covered sectors, standardises requirements, strengthens supervision, and introduces clearer incident-reporting timelines. Because it is a directive rather than a regulation, it takes effect through national laws in each EU country — so the precise details depend on where you operate.

Who is in scope

NIS2 splits covered organisations into essential and important entities across sectors such as energy, transport, banking, health, drinking and waste water, digital infrastructure, public administration, and certain digital providers. Manufacturing of critical products, postal services, food and chemicals are among the added sectors. Size matters too: the rules generally target medium and large organisations, though some entities are covered regardless of size because of their critical role.

ElementWhat NIS2 introduces
ScopeMore sectors; essential vs important entities
Risk managementA required baseline of technical and organisational measures
Incident reportingEarly warning and follow-up reports within set deadlines
AccountabilityManagement responsibility and oversight duties
SupervisionStronger enforcement by national authorities

The baseline security measures

NIS2 asks covered entities to take “appropriate and proportionate” technical, operational and organisational measures. In practice that translates into a familiar set of controls:

  • Risk analysis and information system security policies
  • Incident handling and response procedures
  • Business continuity, backups and disaster recovery
  • Supply chain and vendor security
  • Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure
  • Policies to assess how effective those measures are
  • Basic cyber hygiene, training, and use of cryptography and encryption
  • Access control, asset management and, where appropriate, multi-factor authentication

For a website, much of this baseline overlaps with ordinary good practice: enforce HTTPS, keep software patched, use strong authentication, and add security headers. Our website security basics roadmap is a sensible starting point, and a free scan highlights the most obvious technical gaps.

Reporting and accountability

Covered entities must report significant incidents to their national authority on a defined timeline — an early warning quickly after detection, followed by a fuller report. NIS2 also makes senior management responsible for approving and overseeing cybersecurity measures, so security is treated as a governance issue rather than something left entirely to IT.

Tip. Even if you are not directly in scope, larger covered organisations will push these expectations down their supply chain. Being able to show solid baseline security can become a condition of winning or keeping their business.

Where NIS2 fits in the EU picture

NIS2 sits alongside other EU frameworks. It complements the GDPR, which governs personal data, and rules like the Digital Operational Resilience Act for finance. Together they signal a clear direction: stronger, more accountable cybersecurity across the European economy. Our compliance overview maps how these pieces relate.

This guide is general information to help you understand NIS2, not legal advice. National implementations differ; consult a qualified professional to confirm your obligations.

Frequently asked questions

Does NIS2 apply to my small website?

NIS2 targets specific sectors and generally medium and large organisations, though some critical entities are covered regardless of size. Check your sector and the national law where you operate.

Is NIS2 the same across the EU?

No. It is a directive, so each member state implements it through national law. The core requirements are common, but timelines and details can vary by country.

What is the first thing I should do?

Confirm whether you are in scope, then work on the security baseline: risk management, incident response, patching, backups, access control and encryption.

Related guides

Check your site against this guide

Run a free ScanOpsPro scan and see how your site handles the fundamentals.

Run a free scan