What does NIS2 actually require?
Key obligations include: Adopt cybersecurity risk-management measures appropriate to the risks posed to network and information systems; Notify the relevant competent authority or CSIRT of significant incidents without undue delay; Provide an early warning within 24 hours and a detailed incident notification within 72 hours of becoming aware; Address supply chain security in risk-management measures; Implement vulnerability handling and disclosure policies; Ensure top-management accountability for cybersecurity risk-management measure approval and oversight.