Skip to content

standard

NIS2

EU directive (2022/2555) setting cybersecurity risk-management and incident-reporting rules for critical infrastructure and other essential/important entities.

Known aliases

  • Directive (EU) 2022/2555
  • Network and Information Security 2
  • Network and Information Security Directive 2
  • NIS2 Directive

Relationships

No evidence-backed relationships are recorded.

Current stories

build2 publishersConfirmed

Connected-product makers now have 24 hours to report exploited flaws under the EU Cyber Resilience Act

EU Cyber Resilience Act rules have required connected-product makers to report exploited flaws through ENISA within 24 hours since 11 September 2026. One incident can also start DORA, NIS2 and GDPR clocks, so runbooks need a triage step that splits into parallel filings.

Reality

Evidence64
Adoption
Insufficient
Hype gap+10
Incentives70
Confidence66