WSGR logoWSGR logo
WSGR logo
  • Experience
  • People
  • Insights
  • About Us
  • Careers

  • Practice Areas
  • Industries

  • Corporate
  • Intellectual Property
  • Litigation
  • Patents and Innovations
  • Regulatory
  • Technology Transactions

  • Capital Markets
  • Corporate Governance
  • Corporate Life Sciences
  • Derivatives
  • Emerging Companies and Venture Capital
  • Employee Benefits and Compensation
  • Energy and Climate Solutions
  • Executive Advisory Program
  • Finance and Structured Finance
  • Fund Formation
  • Greater China
  • Mergers & Acquisitions
  • Private Equity
  • Public Company Representation
  • Real Estate
  • Restructuring
  • Shareholder Engagement and Activism
  • Tax
  • U.S. Expansion
  • Wealthtech

  • Special Purpose Acquisition Companies (SPACs)

  • Environmental, Social, and Governance

  • AI and Data Center Infrastructure
  • Energy Regulation and Competition
  • Project Development and M&A
  • Project Finance and Tax Credit Transactions
  • Sustainability and Decarbonization
  • Transportation Electrification

  • U.S. Expansion Library and Resources

  • Post-Grant Review
  • Trademark and Advertising

  • Antitrust Litigation
  • Arbitration
  • Board and Internal Investigations
  • Class Action Litigation
  • Commercial Litigation
  • Consumer Litigation
  • Corporate Governance Litigation
  • Employment Litigation
  • Executive Branch Updates
  • Government Investigations
  • Internet Strategy and Litigation
  • Patent Litigation
  • Securities Litigation
  • State Attorneys General
  • Supreme Court and Appellate Practice
  • Trade Secret Litigation
  • Trademark and Copyright Litigation
  • Trial
  • White Collar Crime

  • Advertising, Promotions, and Marketing
  • Antitrust and Competition
  • Committee on Foreign Investment in the U.S. (CFIUS)
  • Communications
  • Data, Privacy, and Cybersecurity
  • Export Control and Sanctions
  • FCPA and Anti-Corruption
  • FDA Regulatory, Healthcare, and Consumer Products
  • Federal Trade Commission
  • Fintech and Financial Services
  • Government Contracts
  • National Security and Trade
  • Payments
  • State Attorneys General
  • Strategic Risk and Crisis Management
  • Tariffs, Customs, and Import Compliance

  • Antitrust and Intellectual Property
  • Antitrust Civil Enforcement
  • Antitrust Compliance and Business Strategy
  • Antitrust Criminal Enforcement
  • Antitrust Litigation
  • Antitrust Merger Clearance
  • European Competition Law
  • Third-Party Merger and Non-Merger Antitrust Representation

  • Anti-Money Laundering
  • Foreign Ownership, Control, or Influence (FOCI)
  • Team Telecom

  • AI in Healthcare
  • Animal Health
  • Artificial Intelligence and Machine Learning
  • Aviation
  • Biotech
  • Blockchain and Cryptocurrency
  • Clean Energy
  • Climate and Clean Technologies
  • Communications and Networking
  • Consumer Products and Services
  • Data Storage and Cloud
  • Defense Tech
  • Diagnostics, Life Science Tools, and Deep Tech
  • Digital Health
  • Digital Media and Entertainment
  • Electronic Gaming
  • Fintech and Financial Services
  • FoodTech and AgTech
  • Global Generics
  • Internet
  • Life Sciences
  • Medical Devices
  • Mobile Devices
  • Mobility
  • NewSpace
  • Quantum Computing
  • Semiconductors
  • Software

  • Offices
  • Country Desks
  • Events
  • Pro Bono
  • Community
  • Our Diversity
  • Sustainability
  • Our Values
  • Board of Directors
  • Management Team

  • Austin
  • Boston
  • Boulder
  • Brussels
  • Century City
  • Hong Kong
  • London
  • Los Angeles
  • New York
  • Palo Alto
  • Salt Lake City
  • San Diego
  • San Francisco
  • Seattle
  • Shanghai
  • Washington, D.C.
  • Wilmington, DE

  • Law Students
  • Judicial Clerks
  • Experienced Attorneys
  • Patent Agents
  • Business Professionals
  • Alternative Legal Careers
  • Contact Recruiting
NIS2: Preparing for EU’s New Cybersecurity Rules
Alerts
April 19, 2024

The European Union (EU) has revised its Cybersecurity Directive (NIS2). The new rules will apply to a wide range of companies in many sectors, create new cybersecurity obligations, and impose high fines for noncompliance. EU countries have until October 17, 2024, to transpose the new rules. As the deadline approaches, companies should assess the impact on their cybersecurity strategy. This alert summarizes the key obligations for businesses.

EU Cybersecurity Framework

In December 2020, the EU Commission published its proposal to repeal the NIS Directive as part of the EU Cybersecurity Strategy. The aim of this strategy is to boost the EU’s cyber resilience. Other initiatives include i) new cybersecurity rules for software and hardware products (see the Wilson Sonsini client alert regarding the draft Cyber Resilience Act here); ii) new security requirements in the financial sector (Digital Operational Resilience Act); and iii) new standards for protecting and strengthening critical entities against disruptive incidents (Directive on the resilience of critical entities).

Scope of Application

NIS2 has an extended scope compared to the previous NIS Directive. It applies to “essential” and “important” entities that provide their services or carry out their business activities in the EU. The list of types of entities that are in scope is extensive (see this detailed overview of the scope of NIS2 published by the Belgian Centre for Cybersecurity) and includes:

  • companies active in sectors of high criticality such as digital services including cloud services and data center providers, airlines, banks, distribution and transmission system operators, entities carrying out research and development activities of medicinal products, and manufacturers of medical devices that are vital during a public health emergency; and
  • companies active in other critical sectors such as social networking platforms, manufacturers of electrical equipment and medical devices, and food production, processing, and distribution companies.

Member States will maintain a list of essential and important entities, subject to a review at least every two years.

Overview of Main New Obligations

The previous NIS Directive required in-scope organizations to take appropriate and proportionate technical and organizational measures to protect their network and information systems from security threats. It also imposed security incident notification obligations. For more information on the NIS Directive, see the Wilson Sonsini alert here.

NIS2 lists new cybersecurity measures that organizations need to implement, and amends the incident reporting obligations:

  • Cybersecurity Risk Management Requirements. Companies must implement new cybersecurity risk management measures. Such measures include e.g., i) the adoption of policies (e.g., incident handling policies, policies on risk analysis and information system security); ii) the implementation of cybersecurity training; iii) the adoption of backup management and disaster recovery processes; and iv) the use of encryption and multi-factor authentication, where appropriate. Such measures must be proportionate to the likelihood of an incident occurring, the risk involved, and the severity of an incident’s potential impact.
  • Reporting Obligations. Companies must notify significant incidents to the national “Cyber Security Incident Response Team” (CSIRT) designated by each EU member state. A “significant” incident refers to any cyber-related event that either i) causes, or has potential to cause, severe operational disruption of the service or financial losses for a concerned company; or ii) affects, or has potential to affect, other natural or legal persons by causing considerable material or nonmaterial losses.

Under NIS2, companies must file an early warning within 24 hours after becoming aware of a significant incident and update it through an incident notification within the next 48 hours with further details including an impact assessment. Companies must submit a final incident report to the CSIRT within one month of the submission of the incident notification that should flesh out additional information (e.g., detailed description of the incident, its severity and impact, likely root causes, and mitigation measures).

One-Stop-Shop

Certain essential and important entities (e.g., cloud computing service providers, data center service providers, certain digital providers), established in multiple EU countries will benefit from a one-stop-shop mechanism. Those companies will generally only have to comply with the laws of the country of their main establishment, instead of abiding by the requirements applicable in several jurisdictions. The European Union Agency for Cybersecurity (ENISA) will maintain a confidential registry of these entities.

Sanctions

Companies that infringe reporting or cybersecurity risk management obligations may face the following fines: i) essential entities: up to €10,000,000 or 2.0 percent of their worldwide annual turnover (whichever is greater); and ii) important entities: up to €7,000,000 or 1.4 percent of the worldwide annual turnover (whichever is greater).

Next Steps

EU member states must transpose NIS2 into national law by October 17, 2024, and apply their national laws as of October 18, 2024. Requirements are likely to vary across EU member states, as they may adopt or maintain differing provisions ensuring a higher level of cybersecurity. The UK Government also announced that it will introduce similar obligations in an update to its NIS Regulations.1 Companies should carefully assess local requirements in their jurisdictions and adapt their cybersecurity strategies as needed.

For more information, please contact Cédric Burton, Laura De Boel, or another member of the firm's privacy and cybersecurity practice.

Laura Brodahl, Carol Evrard, Joanna Jużak, Matthew Nuding, Sebastian Thess, and Hattie Watson contributed to the preparation of this Wilson Sonsini Alert.


[1]Cyber laws updated to boost UK’s resilience against online attacks, UK Government, Press Release (November 30, 2022): https://www.gov.uk/government/news/cyber-laws-updated-to-boost-uks-resilience-against-online-attacks. 

Contributors

  • Laura De Boel
  • Laura Brodahl
  • Carol Evrard
  • Sebastian Andre Thess
  • people
  • insights
  • about us
  • careers
  • Binder
  • Alumni
  • Mailing List Signup
  • Client FTP Portal
  • Privacy Policy
  • Terms of Use
  • Accessibility
WSGR logo
Twitter
LinkedIn
Facebook
Instagram
Youtube
Copyright © 2026 Wilson Sonsini Goodrich & Rosati. All Rights Reserved.