The Network and Information Systems Directive (NIS Directive) is the European Union's cybersecurity law for operators of critical infrastructure and digital services. Its 2023 revision, NIS2 (Directive (EU) 2022/2555), replaced the original and widened it: more sectors in scope, tighter incident reporting, supply-chain obligations, and real penalties. Member states had to transpose it into national law by October 17, 2024.
What is NIS2?
NIS2 sets a baseline of cybersecurity duties for organizations the EU deems essential to society. It sorts them into two tiers, essential entities and important entities, and holds both to the same core risk-management measures while applying stricter supervision to the essential tier. The idea is simple: if your outage would ripple across the economy or public safety, you have to prove you manage cyber risk properly.
Who has to comply with NIS2?
The scope is much broader than the original NIS Directive. It covers energy, transport, banking, financial markets, health, drinking and waste water, digital infrastructure, public administration, and space in the essential tier, and adds sectors like postal services, waste management, chemicals, food, manufacturing of critical products, and digital providers as important entities. Size matters too: most medium and large organizations in these sectors are in scope by default, which pulls in a lot of industrial operators who were never regulated before. France implements this through its OIV/OSE regime.
What does NIS2 actually require?
Four things drive most of the work:
- Risk management. Article 21 lists the measures: risk analysis, incident handling, business continuity, supply-chain security, access control, encryption, and more.
- Incident reporting. An early warning to the national CSIRT within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month.
- Supply-chain security. You are accountable for the cyber risk your vendors and their products introduce. See supply chain security.
- Management accountability. Senior leadership must approve and oversee the measures and can be held personally liable, which is what changed the boardroom conversation.
Why does NIS2 matter for OT?
Because most in-scope entities run physical processes, and their OT is where a significant incident actually happens. A NIS2 program that only hardens the corporate IT side misses the plant floor. The directive's demands for network segmentation, access control, and monitoring map directly onto OT security practice, and they line up with IEC 62443 for industrial control systems.
How is NIS2 different from NERC CIP?
Different jurisdictions, different enforcement. NERC CIP is a US standard for the bulk electric system, enforced through audits with per-day penalties. NIS2 is an EU directive covering many sectors, transposed separately by each member state, and enforced by national authorities. The controls rhyme, but NIS2 is broader in scope and leans harder on management accountability and incident reporting.
How Access Gate helps
NIS2 asks for segmentation, access control, and the ability to show what happened during an incident. Access Gate delivers those as an agent-free overlay: it segments essential systems without re-cabling, enforces identity-based access so only authorized users reach in-scope assets, proxies and logs remote sessions, and forwards traffic to your SIEM so the 24-hour and 72-hour reports are backed by real evidence. An independent IMR feasibility study validated this on a brownfield OT testbed and mapped the evidence to CyFun, NIS2, IEC 62443, and ISO/IEC 27001. See NIS2 compliance for OT.

