NIS2: Europe’s Most Extensive Cybersecurity Directive to Date
nis2directive.eu
nis2directive.eu
As far as I can read in there as well the proposal hasn't been approved/ratified yet, so I don't know what fool is going to pay someone to prepare for a directive that isn't even official yet.
The directive is here https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/6893...
The legal documents are here https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A...
For those of you already familiar with NIS, this update increases the scope to more industries (e.g. waste management) but also reduces the work needed in some cases.
The article has some details, e.g the 10 minimum measures ( https://nis2directive.eu/nis2-requirements/ ) but I'm not too happy with them.
On the good side, the main concrete thing I see in that list is MFA.
But all the other things in there seem ways to keep some consultants busy writing vague documents, not real steps forward to a secure organizations.
https://www.europarl.europa.eu/RegData/etudes/BRIE/2021/6893...
Unlike GDPR, if you work on some random product or website this most likely does not apply to you.
And it only affects corporations and other entities in a few select sectors of critical importance to society.