What is NIS2?
The EU's expanded cybersecurity directive (replacing NIS1) — mandates risk-management, incident reporting, and supply-chain security for thousands of in-scope entities.
Also known as
NIS2 — explained.
NIS2 (Network and Information Security Directive 2, Directive (EU) 2022/2555) is the EU's expanded cybersecurity directive, in force since 17 January 2023 with national transposition deadline of 17 October 2024. It replaces and significantly expands the original NIS1 directive. The scope now covers thousands of additional entities across 18 critical sectors (energy, transport, banking, financial infrastructure, healthcare, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal and courier services, waste management, manufacture of chemicals, food production, manufacture of medical devices, computers and electronics, machinery, motor vehicles, electrical equipment, transport equipment, digital providers including DNS providers and TLD registries, research). The core obligations: risk-management measures (governance, supply-chain security, vulnerability disclosure, MFA, encryption); 24-hour early-warning + 72-hour incident notification to national authorities; senior-management accountability with personal liability; supply-chain security requirements that flow down to vendors. Fines reach €10m or 2% of global turnover for essential entities. NIS2 is reshaping EU enterprise procurement — vendors increasingly need to demonstrate NIS2-aligned controls to win in regulated sectors.
Zeour solutions that operate on this layer.
Verticals where nis2 is operationally critical.
Blog posts that go deeper on nis2.
Adjacent definitions to read next.
GDPR
Compliance & DataThe EU's data-protection regulation — establishes consent, purpose-limitation, residency, breach-notification, and the data-subject rights regime.
ISO 27001
Compliance & DataThe international standard for Information Security Management Systems (ISMS) — a certifiable framework for managing information-security risk.
Sovereign Deployment
Sovereign DeploymentSoftware that runs entirely inside the operator's perimeter — their hardware, their network, their backups, their keys — with no third-party dependency for continued operation.
CCPA / CPRA
Compliance & DataCalifornia's data-protection law — and the CPRA amendment in force since 2023 — establishing data-subject rights for California residents.
Cyber Essentials
Compliance & DataThe UK NCSC's baseline cybersecurity certification — a five-control posture (firewalls, secure config, access control, malware, patches) increasingly required for UK government contracts.
Data Subject Access Request (DSAR)
Compliance & DataThe data-subject's right to request a copy of all personal data an operator holds about them, plus deletion, correction and processing-restriction rights — under GDPR, PDPL and equivalent laws.
Explicit Consent
Compliance & DataConsent that is specific, informed, unambiguous and given by a clear affirmative action — separate tickboxes per purpose, not bundled — required under GDPR, PDPL and equivalent laws.
HIPAA
Compliance & DataThe US healthcare-data-protection law governing Protected Health Information (PHI) — covers privacy, security, breach notification, and business-associate agreements.
Talk to a Zeour engineer.
A 30-minute scoping call to walk your operational profile against where nis2 actually sits in your stack, then a fixed-fee Discovery price by the end of the call.