Directive (EU) 2022/2555
NIS2, whole
CELEX 32022L2555
A Directive that puts cybersecurity in the boardroom, sorts entities into essential and important, and sets a clock that starts at twenty-four hours. The walk runs from the duty, through the measures and the clock, to the consequence.
Assembling the NIS2 graph...
Every provision of NIS2
The whole act as plain links, grouped as it is grouped. Each one opens that provision on its own page, with the official text, what it cites, what cites it and where it reaches another act.
Chapter IGENERAL PROVISIONS
Chapter IICOORDINATED CYBERSECURITY FRAMEWORKS
- Article 7National cybersecurity strategy
- Article 8Competent authorities and single points of contact
- Article 9National cyber crisis management frameworks
- Article 10Computer security incident response teams (CSIRTs)
- Article 11Requirements, technical capabilities and tasks of CSIRTs
- Article 12Coordinated vulnerability disclosure and a European vulnerability database
- Article 13Cooperation at national level
Chapter IIICOOPERATION AT UNION AND INTERNATIONAL LEVEL
Chapter IVCYBERSECURITY RISK-MANAGEMENT MEASURES AND REPORTING OBLIGATIONS
Chapter VJURISDICTION AND REGISTRATION
Chapter VIINFORMATION SHARING
Chapter VIISUPERVISION AND ENFORCEMENT
- Article 31General aspects concerning supervision and enforcement
- Article 32Supervisory and enforcement measures in relation to essential entities
- Article 33Supervisory and enforcement measures in relation to important entities
- Article 34General conditions for imposing administrative fines on essential and important entities
- Article 35Infringements entailing a personal data breach
- Article 36Penalties
- Article 37Mutual assistance
Chapter VIIIDELEGATED AND IMPLEMENTING ACTS
Chapter IXFINAL PROVISIONS
Annexes (3)
Defined terms (41)
- network and information system
- security of network and information systems
- cybersecurity
- national cybersecurity strategy
- near miss
- incident
- large-scale cybersecurity incident
- incident handling
- risk
- cyber threat
- significant cyber threat
- ICT product
- ICT service
- ICT process
- vulnerability
- standard
- technical specification
- internet exchange point
- domain name system
- DNS service provider
- top-level domain name registry
- entity providing domain name registration services
- digital service
- trust service
- trust service provider
- qualified trust service
- qualified trust service provider
- online marketplace
- online search engine
- cloud computing service
- data centre service
- content delivery network
- social networking services platform
- representative
- public administration entity
- public electronic communications network
- electronic communications service
- entity
- managed service provider
- managed security service provider
- research organisation
Recitals (144)
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- 58
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- 87
- 88
- 89
- 90
- 91
- 92
- 93
- 94
- 95
- 96
- 97
- 98
- 99
- 100
- 101
- 102
- 103
- 104
- 105
- 106
- 107
- 108
- 109
- 110
- 111
- 112
- 113
- 114
- 115
- 116
- 117
- 118
- 119
- 120
- 121
- 122
- 123
- 124
- 125
- 126
- 127
- 128
- 129
- 130
- 131
- 132
- 133
- 134
- 135
- 136
- 137
- 138
- 139
- 140
- 141
- 142
- 143
- 144
Source texts: the Official Journal, through the Publications Office. Study aid, not legal advice.
NIS2 gives way to DORA for financial entities, and defers to the GDPR in its own scope article. Both of those sentences are on the crossover map at /tools/cross-compliance-graph/crossover.