ENISA Strengthens Cybersecurity Framework Under NIS2 Directive

UK Version of GDPR

The European Union Agency for Cybersecurity (ENISA) released implementation guidance supporting Member States and essential entities in transposing the NIS2 Directive.

The NIS2 Directive expands cybersecurity obligations to additional sectors, including cloud providers, data centers, and digital infrastructure services. It mandates stricter incident reporting (within 24 hours of significant incidents), board-level accountability, and risk management measures.

Organizations must implement documented cybersecurity policies, supply-chain risk assessments, business continuity frameworks, and executive oversight structures.

This marks a shift toward executive liability in cybersecurity governance and increases the need for integrated compliance strategies combining GDPR, cybersecurity, and operational resilience.

Source: ENISA – NIS2 Implementation Resources
https://www.enisa.europa.eu

Picture of Dposphere

Dposphere

Recent Post

The UK’s Information Commissioner’s Office has reprimanded ACRO, the Criminal Records Office, following cybersecurity failures involving

The European cybersecurity certification ecosystem is continuing to develop as organizations face growing pressure to demonstrate

The European Union Agency for Cybersecurity (ENISA) announced that it is expanding its role within the