NIS2 Directive
The NIS2 Directive (EU 2022/2555) is the European Union's cybersecurity law for essential and important entities. Rail infrastructure managers and railway undertakings fall under the transport sector, with obligations for risk management, incident reporting and management accountability, enforced through national legislation.
How it works
NIS2 replaces the original 2016 NIS Directive and broadens its scope. Covered entities must implement risk-management measures covering areas such as incident handling, supply-chain security, business continuity, network security and access control. Significant incidents must be reported to national authorities within 24 hours (early warning) and 72 hours (notification), with a final report within one month.
Management bodies are directly accountable and can be held liable for non-compliance; penalties for essential entities can reach €10 million or 2% of global turnover.
Why it matters for security
For European rail, NIS2 turns OT security from good practice into a legal requirement with personal accountability for executives. Operators need visibility into their OT networks, the ability to detect and report incidents quickly, and evidence that risk-management measures are in place across signaling, rolling stock and fixed installations.
Related solution
Supporting compliance with the NIS2 Directive in rail
Visibility, detection and reporting evidence across signaling, rolling stock and fixed installations.
See the solution →

