> ## Documentation Index
> Fetch the complete documentation index at: https://help.dsalta.com/llms.txt
> Use this file to discover all available pages before exploring further.

# NIS 2

> Meet the EU's expanded cybersecurity requirements for essential and important entities.

The NIS 2 Directive (Network and Information Security Directive 2) significantly expands the EU's cybersecurity requirements, covering more sectors and imposing stricter risk management, incident reporting, and governance obligations. It replaces the original NIS Directive.

<Warning>
  NIS 2 is mandatory across the EU. Non-compliance can result in fines up to **€10 million or 2% of global turnover** for essential entities. Senior management can be held **personally liable** for negligence.
</Warning>

## Who needs NIS 2 compliance?

NIS 2 applies to medium and large organizations in 18 sectors:

<CardGroup cols={2}>
  <Card title="Essential entities" icon="building">
    Energy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructure, ICT service management, public administration, and space.
  </Card>

  <Card title="Important entities" icon="building-columns">
    Postal services, waste management, chemicals, food production, manufacturing, digital providers, and research.
  </Card>
</CardGroup>

## Key requirements

| Requirement               | Description                                                                 |
| ------------------------- | --------------------------------------------------------------------------- |
| **Risk Management**       | Implement technical, operational, and organizational cybersecurity measures |
| **Incident Reporting**    | 24-hour early warning, 72-hour notification, 1-month final report           |
| **Supply Chain Security** | Assess and manage cybersecurity risks in your supply chain                  |
| **Governance**            | Senior management must approve and oversee cybersecurity measures           |
| **Business Continuity**   | Backup management, disaster recovery, and crisis management                 |
| **Training**              | Regular cybersecurity training for management and staff                     |

## How DSALTA helps

* **NIS 2 controls** mapped to all directive requirements
* **Incident response** documentation and reporting templates
* **Supply chain risk management** through vendor scoring
* **Governance documentation** for management accountability
* **Cross-framework mapping** — \~80% overlap with ISO 27001, significant overlap with DORA

## Frequently asked questions

<AccordionGroup>
  <Accordion title="Does NIS 2 apply outside the EU?" icon="globe">
    NIS 2 applies to organizations providing services or conducting activities within the EU, regardless of where they are headquartered. If you serve EU customers in covered sectors, you may be in scope.
  </Accordion>

  <Accordion title="How does NIS 2 relate to ISO 27001?" icon="diagram-project">
    There is approximately 80% overlap. Organizations with ISO 27001 certification have a strong foundation for NIS 2 compliance, but need to address additional requirements like incident reporting timelines and supply chain security.
  </Accordion>

  <Accordion title="Can management be personally liable?" icon="user-tie">
    Yes. NIS 2 allows member states to hold management personally liable for gross negligence in cybersecurity oversight.
  </Accordion>
</AccordionGroup>

## How DSALTA automates this

**314** of DSALTA's automated checks contribute evidence to this framework, drawn from **72** integrations. Browse them in the [Compliance Tests](/tests/overview) catalog. They are linked through the controls each check satisfies, so a single check usually contributes to several frameworks at once — the count is not a list of checks unique to this one.

## Related pages

* [DORA](/frameworks/dora/overview)
* [ISO 27001](/frameworks/iso27001/overview)
* [Active Frameworks](/guides/compliance/frameworks-active)
