- Primary source for the predecessor framework (no longer in force).
References and citations
- Primary source for NIS2 obligations, supervision, and reporting timelines.
- Implementation context and summary of major changes introduced by NIS2.
Understand what changed and how to migrate your program.
Output: a migration plan that reuses NIS1 artefacts where possible and closes NIS2 gaps.
Structured answer sets in this page tree.
Cited legal and guidance references.
NIS2 (Directive (EU) 2022/2555) replaced NIS1 (Directive (EU) 2016/1148) and raised the EU's cybersecurity ambition through wider scope, clearer requirements, stronger governance, and stronger supervision tools. Use this page to map changes into your implementation plan.
NIS2 is broader and more explicit. The biggest practical shift is that compliance must be evidenced with owned controls and repeatable reporting workflows.
Most NIS1 programs are policy-heavy. NIS2 expects measurable controls, effectiveness testing, and evidence readiness.
You can reuse many artefacts - but you must tighten ownership, metrics, and reporting workflows.
Research Copilot can take EU Cybersecurity Law NIS2 vs NIS1 from how this topic compares with adjacent regulations or standards to a reusable workflow inside Sorena. Teams working on EU Cybersecurity Law can keep owners, evidence, and next steps aligned without copying this guide into separate documents.
Start from EU Cybersecurity Law NIS2 vs NIS1 and answer scope, timing, and interpretation questions with cited outputs.
Review your current process, evidence gaps, and next steps for EU Cybersecurity Law NIS2 vs NIS1.