{"id":102393,"date":"2026-04-01T19:30:42","date_gmt":"2026-04-01T17:30:42","guid":{"rendered":"https:\/\/firstcolo.net\/glossar\/nis2-directive\/"},"modified":"2026-05-28T23:26:54","modified_gmt":"2026-05-28T21:26:54","slug":"nis2-directive","status":"publish","type":"glossary","link":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/","title":{"rendered":"NIS2 Directive"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"102393\" class=\"elementor elementor-102393 elementor-100101\" data-elementor-post-type=\"glossary\">\n\t\t\t\t<div class=\"elementor-element elementor-element-4f527a20 e-flex e-con-boxed e-con e-parent\" data-id=\"4f527a20\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t<div class=\"elementor-element elementor-element-7c71da23 e-con-full e-flex e-con e-child\" data-id=\"7c71da23\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t<div class=\"elementor-element elementor-element-45232fef e-con-full e-flex e-con e-child\" data-id=\"45232fef\" data-element_type=\"container\" data-e-type=\"container\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t<div class=\"elementor-element elementor-element-7f74fb75 e-con-full e-flex e-con e-child\" data-id=\"7f74fb75\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-3afc0ba6 elementor-widget elementor-widget-heading\" data-id=\"3afc0ba6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h1 class=\"elementor-heading-title elementor-size-default\">What is the NIS2 Directive?<\/h1>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4c105d1e elementor-widget elementor-widget-text-editor\" data-id=\"4c105d1e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\tNIS2 (Network and Information Security Directive) is an EU directive that ensures a high common level of cybersecurity across the European Union by establishing stricter security requirements, supervisory measures, and sanctions for companies in critical sectors. \n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-4161aedc e-flex e-con-boxed e-con e-parent\" data-id=\"4161aedc\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-48ddf608 elementor-widget elementor-widget-heading\" data-id=\"48ddf608\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What does the NIS2 Directive state?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2db0bedb elementor-widget elementor-widget-text-editor\" data-id=\"2db0bedb\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The directive obliges companies to take proactive risk management measures to ensure the security of their network and information systems. This includes not only technical precautions but also organizational processes such as securing the supply chain and structured incident management. The goal is to significantly increase the resilience of the European economy against cyberattacks such as ransomware or espionage.  <\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-78c2734a elementor-widget elementor-widget-heading\" data-id=\"78c2734a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Who must implement NIS2 and who is affected?\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ba4d70a elementor-widget elementor-widget-text-editor\" data-id=\"1ba4d70a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>The NIS2 Directive massively expands the circle of affected organizations. In principle, companies are affected if they employ more than 50 people or achieve an annual turnover of over 10 million euros and operate in one of the regulated sectors. The classification is divided into two categories:  <\/p><ul><li><strong>Essential entities:<\/strong> Energy, transport, banking, healthcare, drinking water, digital infrastructure.<\/li><li><strong>Important entities:<\/strong> Postal and courier services, waste management, chemicals, food, manufacturing.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4d6e406d elementor-widget elementor-widget-heading\" data-id=\"4d6e406d\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Difference between KRITIS and NIS2\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-49537848 elementor-widget elementor-widget-text-editor\" data-id=\"49537848\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Although both concepts aim for the security of critical infrastructures, there are clear differences in scope and application.<\/p><ul><li><a href=\"https:\/\/firstcolo.net\/glossary\/kritis\/\"><strong>KRITIS:<\/strong><\/a> In Germany, this traditionally refers to facilities with a very high degree of supply (e.g., large power plants).<\/li><li><strong>NIS2:<\/strong> Expands the focus away from pure threshold values toward sector affiliation and company size. Many companies that were previously not considered KRITIS operators now fall under NIS2 regulation. <\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-75e32c4 elementor-widget elementor-widget-heading\" data-id=\"75e32c4\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What specifically needs to be implemented for NIS2?\n<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-254b6ca elementor-widget elementor-widget-text-editor\" data-id=\"254b6ca\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t\t\t\t\t\t<p>Implementation requires a bundle of measures that must be based on the state of the art. Central requirements include: <\/p><ul><li>Risk management: Concepts for risk analysis and security for information systems.<\/li><li>Incident management: Prevention, detection, and response to security incidents.<\/li><li>Supply chain security: Auditing security standards at suppliers and service providers.<\/li><li>Cryptography: Use of encryption and multi-factor authentication (MFA).<\/li><li>Management liability: Company management must monitor the measures and is personally liable in the event of violations.<\/li><\/ul><p> <\/p><h2>Timeline: When will NIS2 become mandatory in Germany?<\/h2><p>The EU-wide implementation deadline ended on October 17, 2024. In Germany, the legal obligation is established through the NIS2 Implementation and Cybersecurity Strengthening Act (NIS2UmsuCG). Following delays in the legislative process, the Cybersecurity Strengthening Act was passed by the German Bundestag on November 13, 2025, and the EU NIS2 Directive came into force on December 6, 2025.  <\/p><h2><br>firstcolo expert assessment:<\/h2><p>&#8220;An often underestimated aspect of NIS2 is supply chain security. Even if your company does not fall directly under the directive, you may be contractually forced to comply with NIS2 standards as a service provider for &#8216;Essential Entities.&#8217; Choosing a certified data center partner (e.g., ISO 27001) is a decisive building block for your own compliance strategy.&#8221;<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-25612556 e-con-full e-flex e-con e-child\" data-id=\"25612556\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1f8e30d3 elementor-widget elementor-widget-button\" data-id=\"1f8e30d3\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Homepage<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-653bbcb2 elementor-widget elementor-widget-button\" data-id=\"653bbcb2\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/firstcolo.net\/en\/knowledge\/glossary\/\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Glossary<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>What is the NIS2 Directive? NIS2 (Network and Information Security Directive) is an EU directive that ensures a high common level of cybersecurity across the European Union by establishing stricter security requirements, supervisory measures, and sanctions for companies in critical sectors. What does the NIS2 Directive state? The directive obliges companies to take proactive risk [&hellip;]<\/p>\n","protected":false},"author":43,"featured_media":0,"menu_order":0,"template":"","meta":{"content-type":"","footnotes":""},"glossary-categories":[],"glossary-tags":[],"class_list":["post-102393","glossary","type-glossary","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>NIS2 Directive | firstcolo Glossary<\/title>\n<meta name=\"description\" content=\"NIS2 (Network and Information Security Directive) is an EU directive for high cybersecurity across the entire European Union.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"NIS2 Directive\" \/>\n<meta property=\"og:description\" content=\"NIS2 (Network and Information Security Directive) is an EU directive for high cybersecurity across the entire European Union.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/\" \/>\n<meta property=\"og:site_name\" content=\"firstcolo\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/FirstColo.GmbH\" \/>\n<meta property=\"article:modified_time\" content=\"2026-05-28T21:26:54+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@firstcolo\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/\",\"url\":\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/\",\"name\":\"NIS2 Directive | firstcolo Glossary\",\"isPartOf\":{\"@id\":\"https:\/\/firstcolo.net\/en\/#website\"},\"datePublished\":\"2026-04-01T17:30:42+00:00\",\"dateModified\":\"2026-05-28T21:26:54+00:00\",\"description\":\"NIS2 (Network and Information Security Directive) is an EU directive for high cybersecurity across the entire European Union.\",\"breadcrumb\":{\"@id\":\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Start\",\"item\":\"https:\/\/firstcolo.net\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"NIS2 Directive\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/firstcolo.net\/en\/#website\",\"url\":\"https:\/\/firstcolo.net\/en\/\",\"name\":\"firstcolo\",\"description\":\"firstcolo.net\",\"publisher\":{\"@id\":\"https:\/\/firstcolo.net\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/firstcolo.net\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/firstcolo.net\/en\/#organization\",\"name\":\"firstcolo\",\"url\":\"https:\/\/firstcolo.net\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/firstcolo.net\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/firstcolo.net\/wp-content\/uploads\/firstcolo-logo_RGB-ohne-abstand.svg\",\"contentUrl\":\"https:\/\/firstcolo.net\/wp-content\/uploads\/firstcolo-logo_RGB-ohne-abstand.svg\",\"width\":118,\"height\":23,\"caption\":\"firstcolo\"},\"image\":{\"@id\":\"https:\/\/firstcolo.net\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/FirstColo.GmbH\",\"https:\/\/x.com\/firstcolo\",\"https:\/\/www.instagram.com\/accounts\/login\/?next=httpswww.instagram.comfirstcolo&is_from_rle\",\"https:\/\/www.linkedin.com\/company\/firstcolo\/posts\/?feedView=all\"]}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"NIS2 Directive | firstcolo Glossary","description":"NIS2 (Network and Information Security Directive) is an EU directive for high cybersecurity across the entire European Union.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/","og_locale":"en_US","og_type":"article","og_title":"NIS2 Directive","og_description":"NIS2 (Network and Information Security Directive) is an EU directive for high cybersecurity across the entire European Union.","og_url":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/","og_site_name":"firstcolo","article_publisher":"https:\/\/www.facebook.com\/FirstColo.GmbH","article_modified_time":"2026-05-28T21:26:54+00:00","twitter_card":"summary_large_image","twitter_site":"@firstcolo","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/","url":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/","name":"NIS2 Directive | firstcolo Glossary","isPartOf":{"@id":"https:\/\/firstcolo.net\/en\/#website"},"datePublished":"2026-04-01T17:30:42+00:00","dateModified":"2026-05-28T21:26:54+00:00","description":"NIS2 (Network and Information Security Directive) is an EU directive for high cybersecurity across the entire European Union.","breadcrumb":{"@id":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/firstcolo.net\/en\/glossary\/nis2-directive\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Start","item":"https:\/\/firstcolo.net\/en\/"},{"@type":"ListItem","position":2,"name":"NIS2 Directive"}]},{"@type":"WebSite","@id":"https:\/\/firstcolo.net\/en\/#website","url":"https:\/\/firstcolo.net\/en\/","name":"firstcolo","description":"firstcolo.net","publisher":{"@id":"https:\/\/firstcolo.net\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/firstcolo.net\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/firstcolo.net\/en\/#organization","name":"firstcolo","url":"https:\/\/firstcolo.net\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/firstcolo.net\/en\/#\/schema\/logo\/image\/","url":"https:\/\/firstcolo.net\/wp-content\/uploads\/firstcolo-logo_RGB-ohne-abstand.svg","contentUrl":"https:\/\/firstcolo.net\/wp-content\/uploads\/firstcolo-logo_RGB-ohne-abstand.svg","width":118,"height":23,"caption":"firstcolo"},"image":{"@id":"https:\/\/firstcolo.net\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/FirstColo.GmbH","https:\/\/x.com\/firstcolo","https:\/\/www.instagram.com\/accounts\/login\/?next=httpswww.instagram.comfirstcolo&is_from_rle","https:\/\/www.linkedin.com\/company\/firstcolo\/posts\/?feedView=all"]}]}},"_links":{"self":[{"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/glossary\/102393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/users\/43"}],"version-history":[{"count":4,"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/glossary\/102393\/revisions"}],"predecessor-version":[{"id":102442,"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/glossary\/102393\/revisions\/102442"}],"wp:attachment":[{"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/media?parent=102393"}],"wp:term":[{"taxonomy":"glossary-categories","embeddable":true,"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/glossary-categories?post=102393"},{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/firstcolo.net\/en\/wp-json\/wp\/v2\/glossary-tags?post=102393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}