NIS2

Directive European Union · 2022

NIS2 is the EU's second-generation network and information security directive, widening the scope of regulated 'essential' and 'important' entities across eighteen sectors, imposing baseline risk-management measures, holding management personally accountable, and putting incident reporting on a strict clock — an early warning within 24 hours, an incident notification within 72, and a final report within a month. It regulates how organizations run security, not how they expose it, but its reporting clock is only survivable with the operational instrumentation an API contract can carry.

Horizontal regime. It binds companies by what they do with data, software or customers, not by the sector they sit in. The industries below are where it creates specific, additional duties — not the limit of who has to comply.

Countries

Where this binds. Each links to the providers apis.io has catalogued there.

Regions

Industries

Each links to that industry as a scored cohort — so the question "how ready is this sector for the regime that governs it?" becomes one you can actually look at.