Three significant pieces of EU legislation enter into force today:
- NIS2 Directive (EU) 2022/2555: greatly expands the sectors and organisations covered by EU cyber security rules, introduces management accountability, and sets 24-hour early warning and 72-hour incident notification deadlines. Member States must transpose it by 17 October 2024.
- Digital Operational Resilience Act (DORA) (EU) 2022/2554: a directly applicable regulation for the financial sector covering ICT risk management, incident reporting, resilience testing and ICT third-party risk, including mandatory contract terms. It applies from 17 January 2025.
- Critical Entities Resilience (CER) Directive (EU) 2022/2557: the physical, all-hazards companion to NIS2.
Why UK organisations should care: if you operate in the EU, provide services there, or supply EU-regulated clients (especially financial entities and managed service providers), these requirements are likely to reach you directly or through contracts.
Now is the time to scope your exposure and compare your current controls against NIS2 Article 21 and DORA’s ICT risk requirements.
Source: Directive (EU) 2022/2555 (NIS2) (EUR-Lex)
This update is general information, not legal advice. If you would like help assessing the impact on your information security or privacy programme, contact us.