The NIS2 Directive raises the common level of cybersecurity in the European Union and expands sectors, responsibilities and requirements with respect to the previous framework.
For companies, the important thing is to review whether the sector, size, services provided or supply chain can place them within the direct or indirect scope.
Although the European text is the base reference, the specific application must be reviewed together with national regulations and possible publications in the BOE.
What a company should review
- Cybersecurity governance and management responsibility.
- Risk, continuity and incident management.
- Supplier and supply chain control.
- Need for evidence: policies, records, decisions and reviews.
How we work at Blue Moon
The practical recommendation is not to approach each standard as an isolated folder. ISO 27001, ENS, NIS2, DORA, data protection and secure development share assets, risks, controls, suppliers, incidents and evidence.
We can review whether this rule affects your company and turn it into a clear, prioritized and acceptable roadmap.
Request diagnosis →