Corporate law

The NIS-2 Directive: New Obligations for Companies

Find out if you could be affected by NIS 2

The EU's NIS-2 Directive (Directive on Security of Network and Information Systems) marks a significant step toward strengthening cybersecurity in Europe. Companies in Austria must prepare for a variety of new requirements that will have far-reaching impacts on their security strategy and compliance processes.

NIS 2 Directive

Table of Contents

What is the NIS-2 Directive?

The NIS 2 Directive replaces the previous NIS Directive from 2016 and significantly expands the scope. The goal is to better protect critical and important sectors against cyberattacks and to create a uniform level of protection throughout Europe. The directive now also includes companies that are not considered operators of critical infrastructures, but nevertheless have essential significance for the economy and society.

Who specifically falls under the NIS-2 Directive?

The directive distinguishes between essential entities and important entities:

  • Essential entities: These include organizations operating in critical sectors such as energy supply, water management, healthcare, digital infrastructure, and finance. Their services are essential for the functioning of society, which is why particularly strict security requirements apply.

  • Important entities: This includes companies that are not classified as critical, but nevertheless have significant importance for the economy or society. Examples include manufacturers of medical devices, providers of cloud services, or research centers.

The classification is based on specific criteria such as company size, market share, or the importance of the services. Smaller enterprises (SMEs) are generally exempt unless they provide essential services or operate in particularly high-risk sectors.

Obligations for companies

The NIS 2 Directive establishes a set of requirements that companies must implement. The most important obligations include:

  • Risk management: Companies must implement measures to identify, assess, and mitigate risks. These include technical and organizational safeguards, such as firewalls, intrusion detection systems, or employee training.

  • Reporting obligations: Security incidents that have a significant impact on service provision must be reported within 24 hours. Companies are required to submit a detailed report on the incident within 72 hours.

  • Responsibilities of management: The NIS-2 Directive emphasizes the role of management. They bear the responsibility for ensuring that the requirements are met and can be held personally liable for violations.

  • Access controls and supply chain security: Companies must ensure that all partners and suppliers also comply with security standards in order to avoid vulnerabilities in the supply chain.

  • Emergency plans and recoverability: The development of emergency plans and the ability to recover after an incident are essential. This includes tests and exercises to ensure the effectiveness of the plans.

Implementation in Austria

Austria – like the other member states – should have transposed the requirements of the NIS 2 Directive by October 17, 2024. Although a corresponding national NISG 2024 draft already exists, it has not yet been passed. Despite this failure, it is clear that the NISG 2024 will definitely come. Companies that fall within the scope of the directive should therefore begin preparations now.

Consequences of non-compliance

Failure to comply with the requirements of the NIS 2 Directive can have significant legal and financial consequences. Fines of up to 10 million euros or 2 % of global annual revenue may be imposed. In addition, management may be held personally liable.

Conclusion

The NIS 2 Directive presents companies in Austria with new challenges, but also offers the opportunity to sustainably improve cybersecurity standards. Companies should start implementation early to avoid legal risks and security gaps. We are happy to support you with the analysis and implementation of the NIS 2 requirements. For further information and individual consultation, please contact Anela Blöch at the phone number 01 3912345 or by email office@atb.law available.

More articles

finfluencer

Finfluencers and tipsters

Liability traps for financial service providers
Picture of Roman Taudes
Roman Taudes
Multi-Level Marketing Lawyer Vienna

Multilevel Marketing (MLM)

What is allowed and what is illegal?
Picture of Roman Taudes
Roman Taudes