+49 (0) 821 / 80 99 46 - 0
+49 (0) 821 / 80 99 46 - 0
Request call-back
Contact us
Report a claim
exali.com My business. My insurance.
My exali login
exali.com
  • Insurance

    Professional Indemnity

    Professional Indemnity Insurance for Digital Professions

    General

    Professional Indemnity Insurance
    General Liability Insurance
    Financial Losses Insurance

    More Information

    Selected Professions
    Glossary
  • News & Stories
  • Blog
  • Product finder
    Product finder
  • My exali login
  • Report a claim
"Innovative protection - because your
Polish business keeps up with the times"
Ralph Günther
exali Founder & CEO
Ralph Günther,exali Founder & CEO
My business. My insurance.
Ralph Günther
exali Founder & CEO
Ralph Günther,exali Founder & CEO

Already in?

With our Newsflash, you benefit from the latest news and topics relating to your business every month:

  • Tips, information and expert interviews
  • Real damage events
  • Legal matters and dangers of warnings
The perfect support for your success.

Home / News&Stories /
NIS-2-Directive: What the Requirements Mean For Companies
NIS-2: New Regulations For Companies

NIS-2-Directive: What the Requirements Mean For Companies

Post by Vivien GebhardtPost by Vivien GebhardtAuthor
Post by Vivien GebhardtPost by Vivien GebhardtAuthor
Thursday, 20 March 2025
Thursday, 20 March 2025
Back to the overview

The risk of cyber attacks is growing year on year. In order to counter this development and strengthen important infrastructures, the European Union has launched the NIS 2 Directive. Read the article to find out whether your company is affected and which requirements you need to fulfil.

Article Overview:

New Requirements For More Cyber Security

NIS-2 Directive: These Companies Are Affected

Affected by NIS-2: What You Need To Do!

Cyberattack: How To React Correctly

Violations of NIS-2: These Sanctions Are Imminent

New Requirements For More Cyber Security

The NIS-2 Directive (NIS = Network and Information Security) is intended to improve cyber security in the European Union - for example by increasing the requirements for dealing with risks. Important innovations include:

Extended Scope of Application: The directive covers even more sectors and companies.

Increased Security Requirements: Affected companies are obliged to implement cyber security measures.

Reporting Obligations: If security incidents occur, you are obliged to report these incidents.

Cooperation: EU countries should cooperate more closely and exchange information in a targeted manner.

Sanctions: If you do not comply with the legal requirements, you will face severe penalties.

In this way, the directive aims to help affected companies achieve greater cyber resilience with appropriate measures. In the long term, awareness of the risks within your own company should grow - for example, by regularly analysing threats and their consequences. In the best case scenario, those affected can understand the dependencies between different systems and their consequences and constantly adapt security measures to the current threat situation.

Subscribe to the exali Newsflash and never miss an article again

 

NIS-2 Directive: These Companies Are Affected

The NIS 2 Directive is particularly relevant for the following companies:

  • Companies in economic sectors or with tasks within the critical infrastructure such as energy, drinking water or banking
  • Companies in other critical sectors such as research, public administration or production and processing

The NIS 2 Directive distinguishes between essential and important facilities.

Large companies Medium-sized companies
  • More than 250 employees
  • Tasks within the critical infrastructure
  • Fulfilment of risk measures
  • Regular security checks
  • Cybersecurity incidents must be reported within 24 hours, update after 3 and after 30 days
  • Company management can be held liable for breaches

 

  • Less than 250 employees
  • Belongs to the NIS 2-relevant sector
  • Fulfilment of risk measures
  • Official review in case of suspicion
  • Cybersecurity incidents must be reported within 24 hours, update after 3 and after 30 days
  • Company management can be held liable for violations

 

-> Essential facility

-> Important facility
  • Belongs to the critical sector
  • Fulfilment of risk measures
  • Official review in case of suspicion
  • Cybersecurity incidents must be reported within 24 hours, update after 3 and after 30 days
  • Company management can be held liable for breaches

 

 
-> Important facility  

 

Smaller companies may be affected by the legislation if they offer a critical service.

Tip:

The Cyber Resilience Act also aims to improve cyber security in Europe. Read our article to find out which security standards apply to affected companies.

Affected by NIS-2: What You Need To Do!

Is your company affected? Then you will be subject to various obligations:

  • Risk management and business continuity measures
  • Reporting obligations
  • Registration obligations
  • Information obligations
  • Approval, monitoring and training obligations for management

In some member states, further legal regulations are planned:

  • Issuance of security certificates
  • IT security labelling
  • Certification obligations for products, services and processes
  • Critical services and systems

These risk and reporting measures are mandatory for both essential and important facilities. The only difference is that compliance with the measures in essential facilities is checked at regular intervals - in important facilities this is only done on suspicion. In addition, all facilities must register with the national responsible authority.

Cyberattack: How To React Correctly

You must make an initial report of an incident within the next 24 hours. The report is sent to the responsible supervisory authority. After three and 30 days, you provide an update on your handling of the situation. This is intended to provide the most accurate overview possible of the current threat situation. In addition, the authorities want to evaluate the effectiveness of the measures taken in the long term.

Violations of NIS-2: These Sanctions Are Imminent

If you do not comply with the legal requirements, you must expect fines. The amount depends on the importance of the facility. For significant facilities, the fine is up to two per cent of the annual turnover or a maximum of ten million euros. If you are part of the management, you can also be held liable personally. Supervisory authorities are authorised to monitor and issue instructions.

With its risk-based approach, the NIS 2 Directive aims to improve cyber security systematically. Affected companies should start implementing it at an early stage in order to arm themselves against the increasing threats posed by cyber risks.

Vivien Gebhardt
Author profile
Vivien Gebhardt
Online Editor

Vivien Gebhardt is an online editor at exali. She creates content on topics that are of interest to self-employed people, freelancers and entrepreneurs. Her specialties are risks in e-commerce, legal topics and claims that have happened to exali insured freelancers.
She has been a freelance copywriter herself since 2021 and therefore knows from experience what the target group is concerned about.

Author profile
Vivien Gebhardt
Vivien Gebhardt

Online Editor

Vivien Gebhardt is an online editor at exali. She creates content on topics that are of interest to self-employed people, freelancers and entrepreneurs. Her specialties are risks in e-commerce, legal topics and claims that have happened to exali insured freelancers.
She has been a freelance copywriter herself since 2021 and therefore knows from experience what the target group is concerned about.

Previous article
 
Back
 
Next article
These articles might also interest you
Digital Service Act: What It Means For Companies
Digital Service Act: What It Means For Companies
Stricter Product Liability: What Companies Need To Know
Stricter Product Liability: What Companies Need To Know
Data Act: These Changes Will Be Introduced By the European Data Law
Data Act: These Changes Will Be Introduced By the European Data Law
AI Act: These Innovations Will Be Introduced By the New Law
AI Act: These Innovations Will Be Introduced By the New Law
These articles might also interest you
Digital Service Act: What It Means For Companies
Digital Service Act: What It Means For Companies
Stricter Product Liability: What Companies Need To Know
Stricter Product Liability: What Companies Need To Know
Data Act: These Changes Will Be Introduced By the European Data Law
Data Act: These Changes Will Be Introduced By the European Data Law
AI Act: These Innovations Will Be Introduced By the New Law
AI Act: These Innovations Will Be Introduced By the New Law
0 Comments
Write a comment
Please fill in all areas marked as * required fields.

By clicking the ‘Send’ button, the data entered in the above form will be collected and processed for the purpose of processing your request. All data is transmitted in encrypted form and only processed within the scope of the information in the data protection information. You have a right of objection with effect for the future.

Insurance

  • Professional Indemnity for Digital Professions
  • Selected Professions
  • Report damage event

News & Stories

  • Articles
  • Videos
  • Glossary
  • Subscribe to Newsletter

About us

  • About exali
  • Jobs
  • Contact us
  • Imprint
  • Data Protection Declaration
  • Right of withdrawal
© exali AG, all rights reserved
Unfortunately, your web browser is out of date! Please update your browser in order to be able to use all functions in the premium calculator.
Choose the location of your headquarter
Depending on your country, the insurance offered by exali may vary slightly. Please select the country where you have your headquarter to get the offer that suits you best.