Definition

NIS2 Directive

Directive (EU) 2022/2555 on cybersecurity of essential and important entities — regulates organisations, whereas the CRA regulates products.

The Network and Information Security Directive (EU) 2022/2555 sets cybersecurity risk-management and incident-reporting obligations for essential and important entities in listed sectors. It regulates organisations and their operations; the CRA regulates products placed on the market. Many manufacturers are subject to both: NIS2 incident reporting concerns their own services and systems, CRA Article 14 concerns their products. The CRA reuses NIS2's CSIRT network and its definition of incident.

Reference: Directive (EU) 2022/2555 · Regulation (EU) 2024/2847 on EUR-Lex

Updated 2026-09-12 · Paraphrase for orientation, not legal advice.

In practice

Related terms

See the term as a workflow.

Vellaci turns each of these definitions into a record with an owner, a timestamp and evidence.