Skip to main content

Directive (EU) 2022/2555

NIS2, whole

A Directive that puts cybersecurity in the boardroom, sorts entities into essential and important, and sets a clock that starts at twenty-four hours. The walk runs from the duty, through the measures and the clock, to the consequence.

Assembling the NIS2 graph...

Every provision of NIS2

The whole act as plain links, grouped as it is grouped. Each one opens that provision on its own page, with the official text, what it cites, what cites it and where it reaches another act.

Chapter IGENERAL PROVISIONS

Chapter IICOORDINATED CYBERSECURITY FRAMEWORKS

Chapter IIICOOPERATION AT UNION AND INTERNATIONAL LEVEL

Chapter IVCYBERSECURITY RISK-MANAGEMENT MEASURES AND REPORTING OBLIGATIONS

Chapter VJURISDICTION AND REGISTRATION

Chapter VIINFORMATION SHARING

Chapter VIISUPERVISION AND ENFORCEMENT

Chapter VIIIDELEGATED AND IMPLEMENTING ACTS

Chapter IXFINAL PROVISIONS

Annexes (3)

Defined terms (41)

Recitals (144)

Source texts: the Official Journal, through the Publications Office. Study aid, not legal advice.

NIS2 32022L2555

NIS2 gives way to DORA for financial entities, and defers to the GDPR in its own scope article. Both of those sentences are on the crossover map at /tools/cross-compliance-graph/crossover.