My favourites

NIS 2 Directive

About the NIS 2 Directive

Full name: Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union, amending Regulation (EU) No 910/2014 and Directive (EU) 2018/1972, and repealing Directive (EU) 2016/1148 (NIS 2 Directive)

(Link to original text)

Type: Directive

Objective and key elements:

  • Enhances the preparedness of the Member States, such as forming and cooperating among other Member states through a Computer Security Incident Response Team (CSIRT) and a competent national network and information systems (NIS) authority and EU-wide Cooperation Group
  • Requirements to form a culture of security across sectors that are vital for the EU economy and society and that rely heavily on ICTs, such as:
    • energy, transport, water, banking, financial market infrastructures, healthcare, and digital infrastructure
  • Operators of essential services (as appointed) in the above sectors will be obliged to take appropriate security measures and notify relevant national authorities of serious incidents
  • Key digital service providers, such as search engines, cloud computing services, and online marketplaces, will have to comply with the security and notification requirements under NIS 2

Relevant to: Operators of essential services as well as key digital service providers.

Status: In force since 16 January 2023, applicable from 18 October 2024.

Related legislation: Directive (EU) 2022/2557 of the European Parliament and of the Council of 14 December 2022 on the resilience of critical entities and repealing Council Directive 2008/114/EC (CER-directive) (Link to original text)

Guidance:

Proposed Changes to NIS 2 Directive under the Digital Omnibus Proposal:

Full name: Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Regulations (EU) 2016/679, (EU) 2018/1724, (EU) 2018/1725, (EU) 2023/2854 and Directives 2002/58/EC, (EU) 2022/2555 and (EU) 2022/2557 as regards the simplification of the digital legislative framework, and repealing Regulations (EU) 2018/1807, (EU) 2019/1150, (EU) 2022/868, and Directive (EU) 2019/1024 (Digital Omnibus)

(Link to original text)

Type: Regulation (amending regulation)

Objective and key elements (as regards NIS2):

  • the insertion of a new Article 23a on the development and maintenance of a single-entry point for incident reporting;
  • the amendment of Article 23(4) to require the use of the single-entry point for notifications of severe incidents;
  • the insertion of a new Article 23(12) to ensure that severe incidents subject to reporting obligations under both the NIS2 Directive and the Cyber Resilience Act are reported only once;
  • the amendment of Article 30(1) to provide that the single-entry point may also be used, on a voluntary basis, for notifications submitted by different entities.

Status: Proposal submitted on 19 November 2025

Next steps: The proposed amendments to the NIS2 Directive form part of the broader Digital Omnibus package, which is currently under consideration by the European Parliament and the Council.

Proposed Changes under the Cybersecurity Package Proposal:

Full name: Proposal for a DIRECTIVE OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL amending Directive (EU) 2022/2555 as regards simplification measures and alignment with the [Proposal for the Cybersecurity Act 2]

(Link to original text)

Type: Directive

Objective and key elements (as regards NIS2):

  • Harmonisation of cybersecurity requirements through Commission implementing acts and EU cybersecurity certification schemes.
  • Clarification of the scope of application and sector-specific definitions, including for healthcare, electricity, hydrogen and chemical sectors.
  • Extension of the scope to include providers of European Digital Identity Wallets and European Business Wallets, which would be classified as essential entities irrespective of their size.
    • In addition, a new category of essential entities would be established for operators of submarine data-transmission infrastructure.
  • Introduction of a new category of small mid-cap enterprises, which would be classified as important entities where operating in NIS2-covered sectors.
  • Requirement for Member States to include policies on migration to post-quantum cryptography (PQC) in their national cybersecurity strategies.
  • Promotion of EU-wide cybersecurity certification as a means of demonstrating compliance with Article 21 NIS2 requirements.

Status: Proposal published by the European Commission on 20 January 2026.

Next steps: The proposed amendments to the NIS2 Directive form part of the broader Cybersecurity Package, alongside the proposed Cybersecurity Act 2. The package is currently at an early stage of examination by the European Parliament and the Council.

Guidance:

(Last updated 21 August 2026)

Implemented in Finland as:

Status:

  • In force

Competent authorities: The Cybersecurity Act introduces sector-specific competent authorities:

  • The Finnish Transport and Communications Agency (Traficom) is the competent authority in relation to operators carrying out activities related to airway traffic, rail traffic, waterborne traffic, road traffic, digital infrastructure, and ICT services, as well as ground station or radar activities or other maintainers of ground-based infrastructure that support the provision of space-based services, owned, managed, and operated by member states or private entities, excluding providers of public electronic communications networks;
  • The Energy Authority is the competent authority in relation to operators carrying out activities related to electricity and proprietors of district heating or district cooling as defined in Directive (EU) 2018/2001 of the European Parliament and of the Council of 11 December 2018 on the promotion of the use of energy from renewable sources and certain operators concerning natural gas and hydrogen;
  • The Finnish Safety and Chemicals Agency (Tukes) is the competent authority for certain operators involved in natural gas, oil, hydrogen production and storage, chemicals, and undertakings referred to in NACE Rev. 2 Section C Divisions 26 to 28.
  • The Finnish Supervisory Agency is the competent authority in relation to operators providing healthcare services, EU reference laboratories designated under Regulation (EU) 2022/2371, and companies carrying out waste management activities.
  • The Economic Development Centre is the competent authority in relation to certain operators distributing water intended for human consumption and certain operators in the field of urban waste-water treatment;
  • The Finnish Food Authority is the competent authority in relation to both public and private profit and non-profit undertakings carrying out any of the activities related to any stage of the production, processing, and distribution of food;
  • The Finnish Medicines Agency (Fimea) is the competent authority in relation to operators involved in the research and development of specified medicinal products, undertakings referred to in NACE Rev. 2 Section C Division 21, operators manufacturing critical medical devices, operators carrying out activities relative to blood establishments, pharmacies, and suppliers of medicinal products and medical devices;
  • The Financial Supervisory Authority (FIN-FSA) is the competent authority in relation to banking and financial market infrastructure.

Single point of contact: National Cyber Security Centre

(Last updated 21 August 2026)