NIS2 Directive: Strengthening EU-Wide Cybersecurity

The NIS2 Directive (Directive (EU) 2022/2555) is the current EU cybersecurity law, which officially entered into force across all EU Member States on 17 October 2024.

It replaces the original NIS Directive and significantly expands the scope, requirements and enforcement mechanisms to strengthen the resilience of essential and important entities across the EU.

NIS2 introduces stricter risk management, incident reporting obligations, supply chain oversight and board-level accountability, applying to a broader range of sectors — including cloud providers, data center operators, digital infrastructure and critical manufacturing.

Nebius aligns its cybersecurity practices with NIS2 requirements and actively monitors developments in national implementation to ensure continued compliance across its services within the EU.

Questions and answers

NIS2 is the European Union’s updated cybersecurity directive that replaces the original NIS Directive. It aims to improve the resilience and security of network and information systems across critical and digital sectors in the EU.