The SRI 2 Directive establishes a unified legal framework to safeguard cybersecurity in eighteen critical sectors across the EU. It also calls on Member States to define national cybersecurity strategies and to collaborate with the EU on cross-border response and enforcement.
Cybersecurity involves protecting network and information systems (NIS), their users, and other affected individuals from cyber incidents and threats. To address Europe’s increased exposure to cyber threats, Directive 2022/2555, also known as NIS2, replaced its predecessor, Directive 2016/1148, or NIS1. NIS 2 raises the EU’s common level of ambition in cybersecurity through a broader scope, clearer rules, and stronger oversight tools. It requires Member States to improve their cybersecurity capabilities, while introducing risk management measures and reporting requirements for entities in more sectors and establishing rules for cooperation, information sharing, oversight, and compliance with cybersecurity measures.