Skip to main content
European Union flag
EU Retail Platform

Directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive)

Policy

03 July 2025

Directive on measures for a high common level of cybersecurity across the Union (NIS2 Directive)

Retail

Login / create an account to be able to react

The NIS2 Directive is the EU-wide legislation on cybersecurity. It provides legal measures to boost the overall level of cybersecurity in the EU.

Publishing org

Editorial team

Topics
Geographical descriptors

EU-27

Organisation Type

EU Institutions

  • Ecosystem

    • Retail

Share

The EU cybersecurity rules introduced in 2016 were updated by the NIS2 Directive that came into force in 2023. It modernised the existing legal framework to keep up with increased digitisation and an evolving cybersecurity threat landscape. By expanding the scope of the cybersecurity rules to new sectors and entities, it further improves the resilience and incident response capacities of public and private entities, competent authorities, and the EU as a whole.

The Directive on measures for a high common level of cybersecurity across the Union (the NIS2 Directive) provides legal measures to boost the overall level of cybersecurity in the EU by ensuring:

• Member States' preparedness, by requiring them to be appropriately equipped. For example, with a Computer Security Incident Response Team (CSIRT) and a competent national network and information systems (NIS) authority,

• cooperation among all the Member States, by setting up a Cooperation Group to support and facilitate strategic cooperation and the exchange of information among Member States,

• a culture of security across sectors that are vital for our economy and society and that rely heavily on ICT, such as energy, transport, water, banking, financial market infrastructure, healthcare and digital infrastructure.

Businesses identified by the Member States as operators of essential services in the above sectors will have to take appropriate security measures and notify relevant national authorities of serious incidents. Key digital service providers, such as search engines, cloud computing services and online marketplaces, will have to comply with the security and notification requirements under the Directive.

No votes yet

Comments (0)

See also

-
Comment
0
  • Policy
  • 03 Jul 2025

A European retail sector fit for the 21st century

This Communication outlines the challenges and opportunities facing the European retail sector, proposing best practices and legal guidance to foster competitiveness, support digital transformation, and...
Categories
-
Comment
0
  • Policy
  • 03 Jul 2025

Commission work programme 2025

The 2025 Commission work programme sets out the European Commission’s strategic agenda to build a bolder, simpler, and faster Union, addressing key challenges in competitiveness...
Categories