NIS2 Directive
The NIS2 Directive, Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union, replaced the 2016 NIS Directive and had to be transposed by Member States by 17 October 2024, with national laws entering into force during 2024 and 2025. It widens the range of regulated sectors, harmonises security and reporting obligations, and strengthens supervision and sanctions.
The Directive applies to "essential" and "important" entities in Annex I and II sectors that meet size thresholds (generally medium and large enterprises) or are otherwise designated. The health sector is in Annex I and covers healthcare providers, EU reference laboratories, entities carrying out research and development of medicinal products, manufacturers of basic pharmaceutical products and preparations, and manufacturers of medical devices considered critical during a public health emergency; manufacturers of other medical devices and in vitro diagnostics fall under Annex II. Regulated entities must adopt risk management measures covering policies, incident handling, business continuity, supply chain security, secure development, encryption, access control and multi-factor authentication, and training (Art. 21); management bodies must approve the measures and are personally accountable. Significant incidents must be reported to the national CSIRT or competent authority with an early warning within 24 hours, an incident notification within 72 hours and a final report within one month (Art. 23). Fines reach EUR 10 million or 2% of worldwide turnover for essential entities.
NIS2 operates alongside the GDPR: a cyber incident affecting personal data may require both a NIS2 report and a personal data breach notification, and Art. 21 measures overlap substantially with Art. 32 security of processing. For pharmaceutical, biotech and MedTech companies, NIS2 turns information security from a good practice into a supervised legal duty with board-level accountability; mapping which group entities are in scope in which Member State is the first step, since transposition varies. ISO 27001 certification, which iliomad holds, provides a recognised framework for demonstrating compliance.
