Directive NIS2 European Union
Cart 0

NIS2 glossary


15 terms, each with its article reference. Short definition first, then what it means in practice.

NIS2 glossary terms with article references
Term Reference Definition
Essential entity Art. 3(1) An entity in an Annex I sector that exceeds the ceilings for medium-sized enterprises, plus specific categories listed regardless of size.
Important entity Art. 3(2) An entity in scope that does not qualify as essential — typically medium-sized enterprises and entities in Annex II sectors.
Significant incident Art. 23(3) An incident that has caused or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage to others.
Early warning Art. 23(4)(a) The first filing, due within 24 hours of becoming aware of a significant incident.
Size-cap rule Art. 2(1) The rule that brings medium-sized and large enterprises in Annex I and II sectors into scope by default.
CSIRT Art. 10 Computer Security Incident Response Team — the national body designated by each member state to receive incident notifications and provide assistance.
Competent authority Art. 8 The national authority responsible for supervising NIS2 compliance and enforcing it.
Lex specialis Art. 4 The principle by which a sector-specific EU act displaces the equivalent NIS2 provisions when it is at least equivalent in effect.
Management body Art. 20 The governing organ of an entity, which must approve cybersecurity risk-management measures, oversee their implementation and follow training.
Supply chain security Art. 21(2)(d) The obligation to address security in relationships with direct suppliers and service providers.
Coordinated vulnerability disclosure Art. 12 The process by which a reporter discloses a vulnerability to a vendor in a way that allows a fix before public disclosure.
TLPT (threat-led penetration testing) DORA art. 26 Adversary-simulation testing against live production systems, mandated by DORA for significant financial entities.
Registration Art. 3(4) · Art. 27 The duty to notify your national authority that you are an entity in scope, with specified identifying information.
Ex ante supervision Art. 32 Proactive supervision applied to essential entities, without needing any indication of non-compliance.
Basic cyber hygiene practices Art. 21(2)(g) The baseline practices every entity must implement, alongside cybersecurity training.
Cart 0