Skip to content
Compliance

NIS2

Updated Aug 20261 min read
Definition

The NIS2 Directive (Network and Information Security Directive 2) is the EU's updated cybersecurity legislation for essential and important entities across critical sectors. It expands scope, strengthens security requirements, and introduces stricter incident reporting obligations and supply chain security mandates compared to the original NIS Directive.

Why It Matters

NIS2 applies to a broader set of sectors than its predecessor, including energy, transport, health, digital infrastructure, ICT service management, public administration, and space. Organizations in these sectors must implement risk-based cybersecurity measures and report significant incidents in stages: an early warning within 24 hours, a fuller incident notification within 72 hours and a final report within one month.

For AI agent governance, NIS2's supply chain security requirements are directly relevant. If an organization in a covered sector uses AI agents that access critical systems, the governance of those agents becomes part of the organization's NIS2 compliance surface.

Member states were required to transpose NIS2 into national law by October 2024, though implementation timelines vary. Organizations in scope should already be assessing how their AI agent deployments affect their NIS2 compliance posture.