What is NIS2?
NIS2 stands for Network and Information Systems Directive 2 and is the EU’s directive for information security. The goal of NIS2 is to strengthen information security for critical services in the EU and EEA areas against increasing threats and cyberattacks.
The NIS2 Directive introduces stricter requirements for digital security and applies to more sectors and organizations than the original NIS Directive. In Norway, the Digital Security Act and the Digital Security Regulations entered into force on October 1, 2025. This legislation implements the NIS1 Directive. NIS2 has not yet been implemented into Norwegian law, and work on its national implementation is ongoing alongside the CER Directive.
NIS2 includes, among other things, the following requirements:
-
Companies must ensure training and good information flow about cybersecurity.
-
Stricter requirements for supplier management and security throughout the supply chain.
-
The requirements for incident reporting and handling will be expanded.
-
Management must be involved in decisions related to cybersecurity.
The target group for NIS2 is companies and public services that provide critical services. Selected target groups include sectors such as energy, transport, finance, health, drinking and wastewater, digital infrastructure, public administration, and ICT services.
Companies that want to deliver contracts in these areas must be NIS2-compliant to provide services.
Sicra and NIS2
In the context of Sicra, NIS2 means that we have been working early on to become NIS2-compliant ourselves. Sicra has already reached the finish line in that regard.
Sicra also offers a CISO-for-hire service. Part of this service includes helping companies become NIS2-compliant.
Services
NIS2 and ISO27001
CISO-for-hire
Related words: Artificial intelligence (AI), Artificial general intelligence (AGI), AI Act, IEC 62443, IT-GRC (IT Governance, Risk and Compliance), Azure, Azure Policy, Bluetree, Cybersecurity, Compliance, Governance, Cyber Kill Chain, Cyber insurance, Data breach, Decryption, Encryption, DORA, Expert systems (AI), GDPR, ISO 27001, CISO-for-Hire, CISOaaS, CISO as a service, NSM, MDR, SLA, Supply chain, Pentesting, PLC, Purdue, PQC (Post-quantum cryptography), UPS (Uninterruptible power supply), Security classification, Security management, SOC, Threat intelligence, Security audits, Threat modeling, Best practice, Zeek, Zero Trust, Machine learning (AI), Neural networks and deep learning (AI).