Directive (EU) 2022/2555 — NIS2: measures for a high common level of cybersecurity across the Union
Legally binding: EU law, a TSI-mandated specification or international treaty law.
Issuing body: European Parliament & Council · Version: Directive (EU) 2022/2555 · Published: 2022-12-14
Link verified August 5, 2026
Scope
The EU's horizontal cybersecurity directive: it classifies operators — including railway undertakings and infrastructure managers, listed under transport as essential entities — imposes cybersecurity risk-management measures and management accountability, and sets staged incident-notification obligations with significant sanctions.
NIS2 is the reason cybersecurity moved from the IT department to the boardroom of every sizeable rail organisation. Annex I lists rail transport — infrastructure managers and railway undertakings — among the sectors of high criticality, making them essential or important entities depending on size; that triggers the Article 21 risk-management baseline (governance, supply-chain security, incident handling, business continuity, encryption, vulnerability handling) and the 24h/72h/one-month incident-reporting cascade of Article 23, with management bodies personally accountable for approving and overseeing the measures. For the technical layer the sector pairs NIS2 with TS 50701 / prEN 50701 and the IEC 62443 series: the directive says what outcomes are mandatory, the standards say how a railway control system is engineered and operated to achieve them. National transpositions apply from October 2024.

