← All frameworks
Cyber
NIS2 Directive
EU / national CSIRTs · Brussels, EU · effective Transposition Oct 2024
EU-wide cybersecurity baseline for essential and important entities. Risk management, incident reporting and management accountability — with AI systems in scope where they support essential services.
Your Council assistant — do it all here
You are interacting with an AI system.
Who must comply
- ▸Essential & important entities (energy, transport, health, digital, water…)
- ▸Their key ICT/AI suppliers
Penalties
Up to €10M or 2% of global turnover (essential entities).
Key obligations
Risk-management measures
Policies, crypto, access control, supply-chain security.
Incident reporting
Early warning within 24h, full report within 72h.
Management accountability
Boards liable; must approve and oversee cyber measures.
Supply-chain security
Assess and manage supplier & service-provider risk.
Sectors in scope
EnergyTransportHealthWaterDigital infrastructurePublic administration
Threats & cybersecurity it addresses
Critical-infrastructure attackRansomwareSupply-chain intrusionAI-assisted intrusion
Crosswalks — comply once, cover many
CSOAI Layer 0 mapping
Charter Art. 21, 39 (Rainbow Stack)
Governed MCP tools — open source, pip/npx install