NIS2Technical guidanceENISA

ENISA - Technical guidance for NIS2 Implementing Regulation

Guia tecnica de medidas de ciberseguridad para proveedores digitales e infraestructuras.

ENISA - Technical guidance for NIS2 Implementing Regulation

Guia tecnica de medidas de ciberseguridad para proveedores digitales e infraestructuras.


This site uses cookies. Visit our cookies policy page or click the link in any footer for more information and to change your preferences.

Accept all cookies Accept only essential cookies

Supporting NIS2 implementation through actionable guidance

Back to News

Press ReleaseJun 26,2025

The EU Agency for Cybersecurity (ENISA) publishes a technical guideline for the security measures of the NIS2 Implementing Regulation to assist digital infrastructures and managed service providers.

The NIS2 Directive sets out requirements for cybersecurity risk management measures in 18 critical sectors, such as digital infrastructures, energy, transport or health, which have to be transposed into national law. For the NIS2 Digital Infrastructure and the ICT service management sectors these cybersecurity requirements are further elaborated at EU level, by the Commission Implementing regulation 2024/2690 of 17 October 2024. ENISA now publishes a technical guidance to support companies in these sectors with the implementation of this regulation.

Juhan Lepassaar, Executive Director at ENISA stated: “The implementation of NIS2 is a top priority for ENISA. The Agency is pushing for more alignment and simplification. To achieve that, we are developing practical and technical cybersecurity guidance to support the implementation of cybersecurity measures, on their way to improve the cybersecurity maturity in Europe’s critical sectors.”

This ENISA technical guidance was developed in collaboration with the NIS Cooperation group and the Commission, and we collected feedback from the private sector via an open consultation.

The document provides guidance in the following cybersecurity requirements of the NIS2 Implementing Regulation:

  • Policy on the security of network and information systems
  • Risk management policy
  • Incident handling
  • Business continuity and crisis management
  • Supply chain security
  • Security in network and information systems acquisition, development and maintenance
  • Policies and procedures to assess the effectiveness of cybersecurity risk-management measures
  • Basic cyber hygiene practices and security training
  • Cryptography
  • Human resources security
  • Access control
  • Asset management
  • Environmental and physical security

In scope of the NIS implementing regulation and this technical guideline are DNS providers, TLD registries, cloud computing service providers, data centre service providers, content delivery network providers, managed service providers and managed security service providers, providers of online marketplaces, online search engines and social networking services platforms, and trust service providers.

The implementation guidance is not a legally binding document and it is not intended to replace the frameworks, guidance or tools provided by Member States at national level. Companies in scope of the NIS2 should first consult the national authorities in their country, to understand their obligations.

Linking NIS2 security measures to the European Cybersecurity Skills Framework

To support the EU in developing cyber skills, ENISA developed the European Cybersecurity Skills Framework. Developing cybersecurity skills in the workforce is an important challenge for many companies. To implement the NIS2 Directive, companies should define cybersecurity roles and responsibilities. ENISA publishes a guidance document on the skills and the roles of cybersecurity professionals needed to implement the NIS2 measures. Built upon the European Cybersecurity Skills Framework (ECSF), this guidance offers a detailed mapping of NIS2 obligations to relevant ECSF role profiles. Each role is mapped to its specific tasks, while practical use cases are also included.

Share this page Facebook Twitter LinkedIn

Image

Visual with a background image of a NIS2-themed book, featuring the ENISA logo and the text: “Turning security measures into clear practical steps. ENISA publishes technical implementation guide.

Contact

For press questions and interviews, please contact:
press@enisa.europa.eu.

Access to the press office

Related topics

Content written for:National / EU authorities | Private Sector

Related content

Cyber hygiene in the health sector illustration with medical staff, hospital, and cybersecurity icons, by ENISA

Cyber Hygiene in the Health Sector

16 September, 2025

This booklet, developed by ENISA, provides clear and targeted guidance with practical steps that health entities can take to:

-  Safeguard sensitive data

- Minimise exposure to common cyber threats-

Cover page of an ENISA report titled 'Cybersecurity Roles and Skills for NIS2 Essential and Important Entities', featuring a person typing on a laptop with floating digital icons representing cybersecurity roles. The report is dated June 2025 and maps NIS2 obligations to the ECSF.

Cybersecurity roles and skills for NIS2 Essential and Important Entities

26 June, 2025

ENISA in line with articles 6 and 10 of the Cybersecurity Act , prepared this guidance document on the skills and roles for the cybersecurity professionals needed to meet these legal requirements effectively.

Cover of the publication titled “NIS 2 Implementation Guidance,” featuring hand icons related to cybersecurity and the NIS 2 logo in the centre, with “June 2025” noted at the bottom.

NIS2 Technical Implementation Guidance

26 June, 2025

This report provides technical guidance to support the implementation of the NIS2 Directive for several types of entities in the NIS2 digital infrastructure, ICT service management and digital providers sectors.

Publication cover for Handbook for Cyber Stress Tests - Skyline image with different metrics visual

Handbook for Cyber Stress Tests

15 May, 2025

ENISA developed this handbook as guidance for national or sectorial authorities overseeing cybersecurity and resilience of critical sectors, at the national level, regional or EU level under NIS 2 Directive.

BROWSE ALL PUBLICATIONS

ENISA Telecom Security Forum 2022

2022Jun 29

10th ENISA eHealth Security Conference

2025Sep 16

8th E.DSO/EE-ISAC/ENCS/ENISA Cybersecurity Forum

2025Oct 30

5th ENISA-ERA Conference on Cybersecurity in Railways

2025Dec 1

BROWSE ALL EVENTS

eHealth security in the spotlight: A good practice guide for a robust and resilient EU health sector

News Item16 September, 2025

Unveiled on the sidelines of the 10th edition of the eHealth Security conference, the European Union Agency for Cybersecurity (ENISA) publishes a good practice guide to support entities of the health sector in strengthening their digital security.

Putting EU resilience to the test: ENISA handbook on cyber stress testing

News Item15 May, 2025

The Handbook for Cyber Stress Testing aims to support national authorities in assessing the cybersecurity and resilience of critical sector entities.

From Cyber to Outer Space: A Guide to Securing Commercial Satellite Operations

Press Release26 March, 2025

The European Union Agency for Cybersecurity (ENISA) explores the cybersecurity threat landscape of space to strengthen the resilience of commercial satellites.

Proposed ENISA role to safeguard cybersecurity of health sector

News Item21 January, 2025

The EU Agency for Cybersecurity, ENISA welcomes the EU Action Plan for the cybersecurity of hospitals and healthcare providers proposed on 15 January.

BROWSE ALL NEWS

Subscribe

Stay updated with ENISA! Sign up for email alerts on publications, events, vacancies, and more.

Sign up now

Copy link

Thanks for sharing!

Find any service

AddToAny

More…

A2A