Governance, risk & compliance
EU NIS2 Directive 2024
SecurityEU
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union.
Effective October 2024, replaces NIS1. Applies to essential and important entities across 18 sectors including energy, transport, health, digital infrastructure, ICT services, and more (medium-sized+ enterprises).
Requires risk management measures, MFA, encryption, incident reporting (24h early warning, 72h full notification), supply chain security, business continuity, and board-level accountability. Fines up to 10M EUR or 2% of global turnover.
Management personally liable for compliance failures.
Official reference: https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
Assessment tiers & levels Lavawall supports
Lavawall assesses EU NIS2 Directive at every level below, so you can start where you are and step up as your program matures.
| Tier / level | What it covers | Builds on lower |
|---|---|---|
| Essential Entity | Entities in highly critical sectors (energy, transport, banking, health, digital infrastructure, public admin, space). Subject to proactive supervision by national authorities. | Yes |
| Important Entity | Entities in other critical sectors (postal, waste, chemicals, food, manufacturing, digital providers, research). Subject to reactive supervision (after incidents or evidence of non-compliance). | — |
How Lavawall® helps you get to EU NIS2 Directive compliance
Most of EU NIS2 Directive comes down to technical controls you have to run and prove: keeping systems patched, hardening configuration, detecting breaches early, backing up what matters, controlling access, and keeping evidence that all of it actually happened. Lavawall® runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to EU NIS2 Directive, and tracks your posture continuously instead of once a year at audit time.
- Assess your current state against EU NIS2 Directive in the Lavawall GRC module, with the questionnaire and control set built in.
- Remediate the gaps with the same platform — automated patching, configuration fixes, backups, and access review — not a separate project.
- Evidence everything with timestamped, exportable records auditors, insurers, and clients accept.
Related
Ready to tackle EU NIS2 Directive?
Assess, remediate, and stay audit-ready for EU NIS2 Directive — and every other framework you carry — from one Lavawall® console.
Lavawall® supports EU NIS2 Directive as part of a built-in catalogue of compliance frameworks. Framework requirements are summarized for planning purposes; always confirm the current official text before certifying.