Fill in the form below and we will contact you shortly to organised your personalised demonstration of the Noggin platform.
An integrated resilience workspace that seamlessly integrates 10 core solutions into one, easy-to-use software platform.
The world's leading integrated resilience workspace for risk and business continuity management, operational resilience, incident & crisis management, and security & safety operations.
Explore Noggin's integrated resilience software, purpose-built for any industry.
Security Management Software
Updated July 20, 2026
Like every other major economic bloc, the European Union has experienced a precipitous rise in cyberattacks, particularly on its critical infrastructure assets. Indeed, the Commission of the European Union was one of the first regulators to promulgate legislation specifically designed to improve the security and resilience of its critical services.
Passed into law in 2016, the NIS1 (Network and Information Security) Directive sought to enhance cybersecurity cooperation among EU Member States and harmonize approaches across the Bloc.
The goal of NIS1 was to bolster the ability of critical infrastructure entities to withstand attack by attempting to mitigate the threats to network and information systems used to provide essential services in key sectors. This would ensure the continuity of such services and contribute to the security and effective functioning of the EU’s economy and society.
As we all know, the cyber risk environment has only deteriorated since 2016. By most accounts, the years during which COVID-19 was declared a public health emergency of international concern by the World Health Organization represented a watershed moment for the acceleration of the cyber threat.
Meanwhile, implementation of the Directive — which was written to give Member States wide latitude to regulate their own critical infrastructure sectors — lagged far behind the risks it was intended to mitigate.
For instance, incident reporting obligations were implemented in significantly different ways across the Bloc. Divergences in supervision and enforcement also abounded. As a result, fragmentation of the internal market persisted, while cyber vulnerabilities increased.
Ultimately, despite some successes, NIS1 was not able to effectively address the Bloc’s current and emerging cybersecurity challenges.
Due to NIS1's failure to fully unify and bolster the cybersecurity preparedness of Member States, major reforms were in order. They soon came in the form of NIS2, the successor to NIS1, which was passed into law in November 2022 and came into full force in 2023.
What are some of the major changes from NIS1?
Under NIS1, Member States themselves were responsible for identifying critical infrastructure entities qualifying as operators of essential services.
That’s not the case with NIS2. The current Directive establishes a uniform criterion for determining qualifying entities via the application of a size-cap rule. Now, all medium-sized or larger enterprises or larger operating within the following sectors (many of which are additions from NIS1) are subject to the new Directive:
Besides essential entities, important entities now fall under the scope of the Directive as well. These organizations must also comply with the stringent new cybersecurity risk-management measures and reporting obligations that we’ll detail later.
However, important entities will have a different supervisory authority than essential entities to enforce their obligations, as well as a different penalty regime for non-compliance.
The heart of NIS2 compliance for both essential and important entities is the requirement to adopt cybersecurity risk-management measures. These are measures that will apply to all operations and services of the entity concerned, not only to specific information technology (IT) assets or critical services that the entity provides.
In subsequent guidance, the EU clarifies that these entities must “take appropriate and proportionate technical, operational[,] and organizational measures to manage the risks posed to the security of network and information systems which those entities use for their operations or for the provision of their services.” In this context, network and information systems refer to the following:
Additionally, the measures — which cover hardware, firmware and software used in the activities of an entity — should be risk-based and able to prevent or minimize the impact of incidents.
In the Directive, the EU also points out that network and information systems’ security threats can have different points of origins, with any type of event having a negative impact on an entity’s network or information system, potentially leading to an incident.
On these grounds, the Directive requires compliant measures to be based on “an all-hazard approach.” To comply with the terms of the Directive, such an approach must address the physical and environmental security of network and information systems from systems’ failure, human error, malicious acts or natural phenomena.
Therefore, compliant measures should protect both the entity’s network and information systems and the physical environment of those systems from any event, including sabotage, theft, fire, flood, telecommunication or power failures and/or unauthorized physical access that is capable of compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems.
Per the Directive, entities should at least take the following measures:
Another important aspect of NIS2 is its incident reporting obligations. The Directive compels essential and important entities to notify their computer security incident response teams (CSIRTs) or, where applicable, their competent authority, of any significant incident without undue delay.
What qualifies as an incident? Per the Directive, an incident represents a broad category, defined as any event compromising the availability, authenticity, integrity or confidentiality of stored, transmitted or processed data or of the services offered by, or accessible via, network and information systems.
A subset of such events, significant incidents are those that go one step further in impact. They are events that either have caused or can cause severe operational disruption of the services or financial loss for the entity concerned, or either have affected or can affect other natural or legal persons by causing considerable material or non-material damage.
To respond to significant incidents, entities must follow a multi-stage approach, entailing early warning, incident notification and a final report. If that’s not enough, these three elements may have to be supplemented by intermediate reports and a progress report.
As the Guidance notes, this multi-stage approach “aims at striking the right balance between, on one hand, swift reporting that helps mitigate the potential spread of significant incidents and allows essential and important entities to seek assistance, and, on the other, in-depth reporting that draws valuable lessons from individual incidents and improves over time the cyber resilience of individual entities and entire sectors.”
So, what’s the multi-stage approach in its entirety? Entities must:
Submit an early warning to the competent CSIRT or authority, without undue delay and, in any event, within 24 hours of becoming aware of the significant incident.
The early warning must include, where applicable, an indication of whether the significant incident is suspected of being caused by unlawful or malicious acts or if it could have (in terms of its likelihood) a cross-border impact.
What’s more, an initial assessment should consider the affected network and information systems, in particular their importance in the provision of the entity’s services, the severity and technical characteristics of a cyber threat and any underlying vulnerabilities that are being exploited, as well as the entity’s experience with similar incidents.
Indicators such as the extent to which the functioning of the service is affected, the duration of an incident or the number of affected recipients of services may play an important role in identifying whether the operational disruption of the service is severe.
Submit an incident notification, without undue delay and in any event within 72 hours of becoming aware of the significant incident. Thereafter, an intermediate report may be requested by a competent CSIRT or authority. If an intermediate report is requested, it must include relevant status updates.
Submit a final report to the competent CSIRT or authority not later than one month after the submission of the incident notification, unless the incident is still ongoing at that time, in which case a progress report must be provided and the final report within one month of the handling of the incident.
The final report must include a detailed description of the incident, including its severity and impact, the type of threat or root cause that is likely to have triggered the incident, the applied and ongoing mitigation measures, and, where applicable, the cross-border impact of the incident.
On January 20, 2026, the European Commission proposed a number of changes to the NIS2 Directive. According to the Commission, these changes are intended to “increase legal clarity by simplifying jurisdictional rules, streamlining the collection of data on ransomware attacks and facilitating the supervision of cross-border entities with ENISA's reinforced coordinating role.”
Targeted adjustments within the proposed amendment include:
As the amendment has only been proposed, it is currently in deliberation by the European Parliament. Should a version of the amendment be passed and signed, EU Member States will more than likely have at least a year to make adjustments to any transposed national laws designed to carry out the requirements of the NIS2 Directive in their respective countries.
Beyond requirements for entities themselves, NIS2 includes mandates for Member States. Each Member State must adopt a national cybersecurity strategy, inclusive of policies touching on supply-chain security, vulnerability management and cybersecurity education and awareness. Member States must also produce and regularly update a list of operators of essential services, ensuring that entities within their borders comply with requirements.
The date by which Member States were required to adopt and publish the national measures necessary to ensure compliance with the Directive was set for October 17, 2024, with enforcement set to begin the day after. However, as of this writing, only 22 out of 27 EU Member States fully transposed the Directive into national law.
To encourage the remaining Member States to continue their adoption of the Directive, the Commission has further legal leverage. The Commission may issue a reasoned opinion, i.e., a formal request to comply with EU law. Continued non-compliance on the part of a Member State could then lead to its referral to the Court of Justice of the European Union, introducing the spectre of financial sanctions.
As such, the clock is ticking for critical infrastructure entities, many of whom were already identified by NIS1. What’s more, although the majority of Member States have yet to complete their respective transposition of the Directive into national law, many have already begun, including the EU’s largest economy, Germany.
So, whether NIS2 is national law or not, it’s EU law. Accordingly, critical infrastructure entities should be prepared.
How can they? Well, Noggin can help if you’re looking for an integrated resilience workspace that helps your teams work together to anticipate and manage threats, conduct preparedness activities, effectively respond to disruptions and continually learn from insights to strengthen resilience.
Don’t take our word for it though. Request a demonstration to see Noggin in action for yourself.