Who does NIS2 apply to?
NIS2 applies to all companies based within an EU member state. The NIS2 Directive builds on previous NIS1 Directive and sets out new obligation for operators of essential services (OES) and digital service providers (DSPs).
1. Operators of Essential Services (OES)
Companies that provide essential services such as energy, transportation, banking, financial market, infrastructures, health, water supply, and digital infrastructure. The NIS2 Directive defines OES as entities that meet certain criteria, including size, impact, and interdependence. OES are required to comply with the directive’s security and reporting requirements.
2. Digital Service Providers (DSPs)
Companies that provide online marketplaces, search engines, and cloud computing services. The NIS2 Directive defines DSPs as entities that meet certain criteria, including size and scope of services. DSPs are required to comply with the directive’s security requirements.
What are the NIS2 requirements?
NIS requires essential community services to adopt a systematic and risk-based security approach and report incidents. It expands the scope of sectors and services covered by the regulation and introduces new security and reporting requirements.
Customer case
Cyber Resilience for Aneo and Their Critical Energy Infrastructure
“River Security gives us clarity, structure, and sparring that adds real value. The Active Focus platform makes it easier to prioritize and follow up, and we truly appreciate having a skilled security professional in the loop.”
Thomas Mørtsell
Chief Technology Officer