The NIS2 Directive Explained for Website Owners
NIS2 is the European Union’s updated cybersecurity law for essential and important organisations. It widens the scope of the original 2016 NIS directive, raises the baseline security expected of covered entities, and puts real accountability on management. If your business operates in certain sectors, it may now apply to you even if it did not before.
The short version
NIS2 (Directive (EU) 2022/2555) expands EU cybersecurity rules to more sectors, sets a common baseline of risk-management measures, and adds incident reporting and management accountability. It is implemented through each member state’s national law. Check whether your sector and size bring you into scope, then work on the technical baseline. This is general information, not legal advice.
What NIS2 actually is
NIS2 replaces the first Network and Information Security directive from 2016. The original left too many gaps and was applied inconsistently across member states. NIS2 broadens the range of covered sectors, standardises requirements, strengthens supervision, and introduces clearer incident-reporting timelines. Because it is a directive rather than a regulation, it takes effect through national laws in each EU country — so the precise details depend on where you operate.
Who is in scope
NIS2 splits covered organisations into essential and important entities across sectors such as energy, transport, banking, health, drinking and waste water, digital infrastructure, public administration, and certain digital providers. Manufacturing of critical products, postal services, food and chemicals are among the added sectors. Size matters too: the rules generally target medium and large organisations, though some entities are covered regardless of size because of their critical role.
| Element | What NIS2 introduces |
|---|---|
| Scope | More sectors; essential vs important entities |
| Risk management | A required baseline of technical and organisational measures |
| Incident reporting | Early warning and follow-up reports within set deadlines |
| Accountability | Management responsibility and oversight duties |
| Supervision | Stronger enforcement by national authorities |
The baseline security measures
NIS2 asks covered entities to take “appropriate and proportionate” technical, operational and organisational measures. In practice that translates into a familiar set of controls:
- Risk analysis and information system security policies
- Incident handling and response procedures
- Business continuity, backups and disaster recovery
- Supply chain and vendor security
- Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure
- Policies to assess how effective those measures are
- Basic cyber hygiene, training, and use of cryptography and encryption
- Access control, asset management and, where appropriate, multi-factor authentication
For a website, much of this baseline overlaps with ordinary good practice: enforce HTTPS, keep software patched, use strong authentication, and add security headers. Our website security basics roadmap is a sensible starting point, and a free scan highlights the most obvious technical gaps.
Reporting and accountability
Covered entities must report significant incidents to their national authority on a defined timeline — an early warning quickly after detection, followed by a fuller report. NIS2 also makes senior management responsible for approving and overseeing cybersecurity measures, so security is treated as a governance issue rather than something left entirely to IT.
Where NIS2 fits in the EU picture
NIS2 sits alongside other EU frameworks. It complements the GDPR, which governs personal data, and rules like the Digital Operational Resilience Act for finance. Together they signal a clear direction: stronger, more accountable cybersecurity across the European economy. Our compliance overview maps how these pieces relate.
This guide is general information to help you understand NIS2, not legal advice. National implementations differ; consult a qualified professional to confirm your obligations.
Frequently asked questions
Does NIS2 apply to my small website?
NIS2 targets specific sectors and generally medium and large organisations, though some critical entities are covered regardless of size. Check your sector and the national law where you operate.
Is NIS2 the same across the EU?
No. It is a directive, so each member state implements it through national law. The core requirements are common, but timelines and details can vary by country.
What is the first thing I should do?
Confirm whether you are in scope, then work on the security baseline: risk management, incident response, patching, backups, access control and encryption.
Related guides
GDPR Website Checklist for Small Businesses
A practical, jargon-free checklist to bring a small website in line with GDPR, from cookies to data requests.
Read →Privacy & ComplianceCookie Consent Done Right
How consent banners are supposed to work under EU law and how to avoid the most common compliance mistakes.
Read →Privacy & ComplianceWhat Every Privacy Policy Needs
The core sections a website privacy policy should contain and the plain-language way to write them.
Read →Check your site against this guide
Run a free ScanOpsPro scan and see how your site handles the fundamentals.
Run a free scan