Governance, risk & compliance
EU NIS2 Directive 2024
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union.
In force since 16 January 2023 and applied from 18 October 2024 (the member-state transposition deadline); replaces NIS1. Applies to essential and important entities across 18 sectors including energy, transport, health, digital infrastructure, ICT services, and more (medium-sized+ enterprises).
Requires risk management measures, MFA, encryption, incident reporting (24h early warning, 72h full notification), supply chain security, business continuity, and board-level accountability. Fines up to 10M EUR or 2% of global turnover.
Management personally liable for compliance failures.
Assessment tiers & levels Lavawall supports
Lavawall assesses EU NIS2 Directive at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Essential Entity | Entities in highly critical sectors (energy, transport, banking, health, digital infrastructure, public admin, space). Subject to proactive supervision by national authorities. | Yes |
| Important Entity | Entities in other critical sectors (postal, waste, chemicals, food, manufacturing, digital providers, research). Subject to reactive supervision (after incidents or evidence of non-compliance). | — |
How Lavawall® helps you get to EU NIS2 Directive compliance
Most of EU NIS2 Directive comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to EU NIS2 Directive, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against EU NIS2 Directive in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Lavawall® supports EU NIS2 Directive as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.
At a glance
- Framework
- EU NIS2 Directive 2024
- Category
- Security
- Region
- EU
- Levels
- 2 assessment tiers
Map this framework freeTalk to our team