Glossary Updates12 new terms added to the glossaries · October 2, 2026, 22:44 CEST
AI TechDocKnowledge

Glossary · OT cybersecurity

NIS 2 Directive

Also known as: NIS2, Directive (EU) 2022/2555

German: NIS-2-Richtlinie

The NIS 2 Directive, Directive (EU) 2022/2555, is EU legislation on measures for a high common level of cybersecurity. It requires essential and important entities in listed sectors, including parts of manufacturing, to take cybersecurity risk-management measures and to report significant incidents, and it makes management bodies accountable.

  • OT security

In one sentence

NIS 2, Directive (EU) 2022/2555, requires essential and important entities to manage cybersecurity risks and report significant incidents.

Example

A manufacturer of machinery with more than 50 employees checks whether it falls under NIS 2 as an important entity under its country's transposition law and registers with the national authority.

How it applies

  • Scope: NIS 2 covers entities in sectors of high criticality and other critical sectors; the latter include manufacturing of, among others, machinery and equipment, electrical equipment, motor vehicles and computer and electronic products. Size thresholds and national rules decide whether a company is essential, important or out of scope.
  • Measures: Article 21 lists risk-management measures such as risk analysis, incident handling, business continuity, supply chain security, secure development and vulnerability handling, cryptography, access control and multi-factor authentication.
  • Reporting: Significant incidents are reported in stages (24 hours, 72 hours, one month).
  • Documentation: Covered entities need documented policies, procedures and evidence. Suppliers to covered entities increasingly receive security questionnaires; clear product security documentation makes these easier to answer.

NIS 2 vs. Cyber Resilience Act

NIS 2 is a directive addressed to organizations that operate services. The Cyber Resilience Act (CRA) is a regulation addressed to products with digital elements and their manufacturers. A machine builder can be affected by both.

By knowledge.aitechdoc.world · Published September 26, 2026 · Last reviewed

Source: Directive (EU) 2022/2555 of the European Parliament and of the Council of 14 December 2022 on measures for a high common level of cybersecurity across the Union (NIS 2 Directive)

Definitions follow the cited standards and specifications. Where a source is a copyrighted publication, such as an ISO, IEC or EN standard, the definition is a close paraphrase, not a verbatim quotation, so as not to infringe copyright. We recommend reading the original publication. The sections “How it applies” are editorial commentary by AI TechDoc Blog and are not part of any standard.

Seen a mistake? Send us a note!