Authors
While NIS2 appears to emphasise that EU member states will identify organisations in scope, it requires organisations themselves to determine whether they fall within its scope and self-identify with a relevant EU member state regulator. If they fall within the scope, they must take measures to comply with related cybersecurity requirements by October 2024. Importantly, they must also notify the relevant EU member state regulator that they fall within the scope of NIS2 by April 2025. Digital infrastructure organisations caught by NIS2 will need to notify the relevant EU member state regulator by 17 January 2025.
Authors
