Glossary
/
Standards & Regulation

NIS2 Directive

Also known as:
Directive (EU) 2022/2555 · Network and Information Security Directive 2

The NIS2 Directive (EU 2022/2555) is the European Union's cybersecurity law for essential and important entities. Rail infrastructure managers and railway undertakings fall under the transport sector, with obligations for risk management, incident reporting and management accountability, enforced through national legislation.

How it works

NIS2 replaces the original 2016 NIS Directive and broadens its scope. Covered entities must implement risk-management measures covering areas such as incident handling, supply-chain security, business continuity, network security and access control. Significant incidents must be reported to national authorities within 24 hours (early warning) and 72 hours (notification), with a final report within one month.

Management bodies are directly accountable and can be held liable for non-compliance; penalties for essential entities can reach €10 million or 2% of global turnover.

Why it matters for security

For European rail, NIS2 turns OT security from good practice into a legal requirement with personal accountability for executives. Operators need visibility into their OT networks, the ability to detect and report incidents quickly, and evidence that risk-management measures are in place across signaling, rolling stock and fixed installations.

Related solution

Supporting compliance with the NIS2 Directive in rail

Visibility, detection and reporting evidence across signaling, rolling stock and fixed installations.

See the solution →

Related terms

Ready to protect your rail?

Our specialists will help you back on track

Talk with an Expert