5 Key Changes From NIS1 to NIS2

Martin Bastius
07.02.2025
5
min.

The shift from NIS1 to NIS2 marks a significant evolution in the EU's approach to cybersecurity.

NIS1 laid the groundwork for the security of network and information systems, focusing primarily on providers of essential services, while NIS2 expands this framework to cover a much broader range of sectors and entities, with an emphasis on the need for robust cybersecurity practices.

And although many EU member states, including Germany, have yet to transpose the NIS2 directive, its implementation is inevitable. Organizations should use this time to prepare and familiarize themselves with the key changes NIS2 brings.

Delays in Implementing NIS2

The NIS2 Directive has been in force since January 16, 2023, requiring EU member states to transpose it into national law by October 17, 2024.

As of mid-2025, the European Commission reported that only a handful of countries, including Belgium, Croatia, Hungary, Italy, Latvia, and Lithuania, had fully transposed the directive into national law. In key member states such as France, Germany, the Netherlands, and Sweden, the corresponding legislative process had not yet been completed.

This results in a fragmented implementation landscape across the EU, with varying levels of preparation and compliance.

According to the Commission's official guidance, EU directives don't have direct effect but must be transposed into national law by each member state. In countries without transposition, there is therefore no binding legal basis for requiring companies to comply with key NIS2 provisions, such as those on cybersecurity or reporting obligations.

Despite the inconsistent implementation, the Commission is urging organizations to act early. Once national legislation is in place, enforcement will begin, and delayed preparation can lead to compliance risks.

What Organizations Should Do Now

This extra time gives companies and institutions the opportunity to prepare in a targeted way:

  1. Understand the differences between NIS1 and NIS2, such as expanded sectors, stricter requirements, and higher fines
  2. Systematically analyze your own cybersecurity posture
  3. Identify gaps in technical and organizational measures
  4. Prepare for new reporting obligations, such as the 24-hour deadline for serious security incidents

As the transposition process nears completion in the remaining member states, organizations and companies should closely monitor legislative developments at the national level and start aligning with the directive's objectives now, even without a formal obligation.

Key Differences — NIS1 vs. NIS2

1. Expanded Scope

The shift from NIS1 to NIS2 brings a significantly expanded scope. While NIS1 focused primarily on operators of essential services (e.g., in energy, health, transport, and digital infrastructure), NIS2 now also covers numerous additional sectors, such as postal and courier services, food production, water supply, waste management, and space-related services.

A complete overview of the affected sectors and subsectors is available in Annexes I and II of the directive.

The directive also introduces a new classification into two categories:

  • Essential entities: e.g., energy providers or hospitals.
  • Important entities: e.g., companies in the food sector or the chemical industry.

In addition, the size threshold has been lowered: small and medium-sized enterprises (SMEs) that play a critical role in these sectors now also fall under the directive. The goal is a more resilient and consistent level of cybersecurity across the EU, with no exceptions for particularly vulnerable areas.

2. Risk Management and Cybersecurity Requirements

Compared to NIS1, NIS2 significantly tightens risk management requirements. According to Article 21 of the directive, affected organizations must, among other things:

  • Use state-of-the-art encryption for both data transmission and data storage.
  • Develop and regularly test emergency plans and business continuity strategies.
  • Conduct cybersecurity audits and risk assessments, both internally and with service providers.
  • Train employees, for example on recognizing phishing, password security, or reporting suspicious incidents.

Particular focus is placed on risks from the supply chain and third parties. NIS2 emphasizes that cybersecurity must be considered not only internally but also across partners.

3. Incident Reporting Obligations

Incident reporting also sees significant changes under NIS2. Under Article 23, the following now applies:

  • An initial report within 24 hours of becoming aware of an incident.
  • A follow-up report within 72 hours at the latest.
  • A final report within one month, including root cause analysis, impact, and measures taken.

Reports must be submitted through a central EU reporting system. Standardized protocols are designed to facilitate cooperation with national CERTs/CSIRTs and support a rapid response to threats.

4. Harmonization Across the EU

A major advantage of NIS2 over NIS1 is more consistent implementation across member states. While NIS1 gave countries more leeway in classifying companies, NIS2 introduces uniform criteria to minimize regulatory differences.

NIS2 also promotes cross-border cooperation, for example through:

  • Shared situational awareness and threat intelligence exchange via ENISA,
  • Coordinated responses to major incidents,
  • A central EU vulnerability database.

5. Enforcement and Sanctions

The new rules provide for significantly harsher penalties for violations. Under Article 34, companies face fines of up to €10 million or 2% of global annual revenue, whichever is higher.

In addition, managing directors and board members are explicitly held accountable. They must:

  • actively oversee compliance with cybersecurity requirements,
  • approve risk management strategies,
  • and ensure that reporting obligations are met.

This means NIS2 goes well beyond the IT department, requiring accountability at the executive level, including possible personal liability in the event of damage.

What Are the Risks of Non-Compliance With NIS2?

Failing to comply with the NIS2 Directive can have serious consequences for organizations. Beyond substantial financial penalties, it can damage a company's reputation, erode customer trust, and lead to legal consequences.

The key risks are:

  1. Administrative fines: Organizations can be fined up to €10 million or 2% of their global annual revenue, whichever is higher (NIS2 Directive, Article 34).
  2. Enforcement actions: Regulators can investigate and audit non-compliant companies. Such audits can uncover further security shortcomings, potentially leading to mandatory system upgrades or operational downtime.
  3. Reputational damage: Companies may be required to publicly disclose their non-compliance, seriously harming their standing and customer trust.
  4. Operational disruptions: Weak cybersecurity measures increase the risk of data breaches, which can lead to service interruptions and lost revenue.
  5. Personal sanctions: In cases of gross negligence, executives can be held personally liable. This can result in temporary bans from holding office and other sanctions.

Organizations should prioritize NIS2 compliance to avoid these risks and protect both their operations and their reputation.

Conclusion

The shift from NIS1 to NIS2 is a necessary step toward strengthening cybersecurity in the European Union (NIS2 Directive). The directive's expanded scope and stricter requirements reflect the evolving threat landscape and highlight the need for a proactive approach to protecting critical infrastructure and essential services.

Although many EU member states have delayed transposing NIS2 into national law, organizations need to act now to review their current cybersecurity measures, identify gaps, and implement strategies to comply with the directive.

Failing to do so can have serious consequences, including financial penalties and reputational damage (European Commission on enforcement).

To prepare for NIS2 compliance, organizations should carefully review the directive's requirements and seek expert advice where needed.

FAQ

What's the main difference between NIS1 and NIS2?

NIS2 expands the scope to more sectors and smaller organizations and introduces stricter requirements as well as faster reporting obligations.

What happens if an organization doesn't comply with NIS2?

Organizations can expect fines of up to 10 million euros or 2% of global revenue, reputational damage, audits, and legal consequences.

By when do the EU member states have to transpose NIS2 into national law?

The EU member states must transpose the NIS2 Directive into national law by October 17, 2024.

Does NIS2 really apply to our company if we're not a critical infrastructure operator?

Yes, that may well be the case. NIS2 is considerably broader than earlier critical infrastructure rules. Key factors include your industry, company size, and the type of services you provide. SaaS, cloud, IT, and digital service providers in particular should carefully check whether they're affected.

Published
07.02.2025
Martin Bastius
Co-Founder & CLO

More articles

View all articles
AI & Data Governance
8/17/26

Shadow Builder Policy: How to securely manage AI-built apps in your company

Shadow Builder Policy: How to securely manage AI-built apps in your company
Compliance in Practice
8/14/26

Compliance software vs. legal expertise: What your company really needs for modern compliance

Compliance software vs. legal expertise: What your company really needs for modern compliance
Data Protection & GDPR
4/3/24

Secure Handling of Ex-Employee Emails Under GDPR

Secure Handling of Ex-Employee Emails Under GDPR
Discover all stories