← All frameworks
Cyber

NIS2 Directive

EU / national CSIRTs · Brussels, EU · effective Transposition Oct 2024

EU-wide cybersecurity baseline for essential and important entities. Risk management, incident reporting and management accountability — with AI systems in scope where they support essential services.

Who must comply
  • Essential & important entities (energy, transport, health, digital, water…)
  • Their key ICT/AI suppliers
Penalties

Up to €10M or 2% of global turnover (essential entities).

Key obligations
Risk-management measures
Policies, crypto, access control, supply-chain security.
Incident reporting
Early warning within 24h, full report within 72h.
Management accountability
Boards liable; must approve and oversee cyber measures.
Supply-chain security
Assess and manage supplier & service-provider risk.
Sectors in scope
EnergyTransportHealthWaterDigital infrastructurePublic administration
Threats & cybersecurity it addresses
Critical-infrastructure attackRansomwareSupply-chain intrusionAI-assisted intrusion
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping

Charter Art. 21, 39 (Rainbow Stack)

Governed MCP tools — open source, pip/npx install