You are on United States website. Change region to view location-specific content:
Global
English
Select another region
Choose region and language
- Americas
- Asia-Pacific
- Europe, Middle East and Africa
- Worldwide
Europe’s Network and Information Systems Directive (NIS 2) aims to enhance and standardize a high level of cybersecurity across the European Union. This mandate places new security and reporting requirements on key sectors, including energy, transportation, health care, banking and other critical infrastructure industries.
Non-compliance with NIS 2 can result in heavy fines, regulatory investigations, and legal action. Beyond the financial impact, it can damage an organization’s reputation and erode customer trust. Managed service providers may also face added pressure, as clients look to them to ensure systems and data stay compliant.
Acronis helps organizations meet core NIS 2 requirements with natively integrated protection with compliance-enabling solutions. See some of the ways Acronis can help you meet NIS 2 requirements.
See how Acronis helps you comply with NIS 2
Looking for help?
NIS 2 Directive is cracking down on organizations of all sizes. The standard categorizes businesses into two groups: Essential entities and Important entities.
Essential entities are highlight critical sectors, including energy (electricity, oil, gas, etc.), transport (air, rail, water, road), banking, financial market infrastructures, health care, digital infrastructure (IXPs, DNS service providers, TLD name registries, cloud computing services, data centers) and public administration.
Important entities are other integral industries such as postal and courier services, waste management, chemical manufacturing, food production, manufacturing (of certain critical products), digital providers (online marketplaces, search engines, social networking services) and research.
NIS 2 explicitly includes MSPs within its scope, recognizing their critical role in the supply chain of essential services. This means MSPs operating in the EU (or providing services to EU clients) must:
NIS 2 mandates comprehensive cybersecurity risk management measures, falling into four main areas:
Generally, no. NIS 2 compliance is not mandatory for micro and small businesses (fewer than 50 employees and less than €10 million in annual revenue).
However, it can become mandatory for them in specific exceptions:
Therefore, while most micro and small businesses are exempt, it's crucial for any business, regardless of size, to assess its role within critical supply chains and its direct impact on essential services to determine if NIS 2 might apply to them or their clients.
Sorry, your browser is not supported.
It seems that our new website is incompatible with your current browser's version. Don’t worry, this is easily fixed! To view our complete website, simply update your browser now or continue anyway.