Glossary term
NIS2
Also: NIS2 Directive, Directive (EU) 2022/2555
EU directive on network and information security. Replaces NIS1, widens scope to around 30,000 German companies in 18 sectors, introduces personal management body liability, sets ten minimum cybersecurity measures under Article 21.
NIS2 is the second generation of European cybersecurity regulation. It entered into force on 16 January 2023; the EU transposition deadline was 17 October 2024. Germany transposes via the NIS2-Umsetzungs- und Cybersicherheitsstärkungsgesetz (NIS2UmsuCG), still in legislative process.
Scope: essential entities (energy, transport, banking, health, drinking water, digital infrastructure, ICT services, public administration, space) and important entities (postal, waste, chemicals, food, manufacturing, digital services, research).
Core duties: ten Article 21 minimum measures (risk analysis, incident handling, business continuity, supply-chain security, secure procurement and maintenance, effectiveness review, cyber hygiene, cryptography, personnel security, MFA). Reporting deadlines 24 h / 72 h / 1 month. Fines up to 10 M EUR or 2% of turnover. Personal liability of management body.
Related terms
NIS2 Art. 20
The NIS2 article that makes the management body of an essential or important entity directly account…
DORA
EU regulation on digital operational resilience in the financial sector. Directly applicable since 1…
ISO 27001
International standard for information security management systems. Current version ISO/IEC 27001:20…
AI Act Conformity Assessment
Procedure to demonstrate that a high-risk AI system complies with the EU AI Act before being placed …
AI Act Risk Categories
Four-tier classification under the EU AI Act: prohibited (Art. 5), high-risk (Annex I/III), limited …
Audit-ready decision
A decision whose record is structured, evidence-backed and stakeholder-signed to a level that a thir…
BAIT
BaFin circular that concretises IT requirements for credit institutions. Specifies MaRisk AT 7.2 for…
BCM
Discipline for maintaining critical business processes during disruptions. Standards: ISO 22301, BSI…
