Skip to content

    Directive (EU) 2022/2555 — NIS2: measures for a high common level of cybersecurity across the Union

    DIR-2022-2555Binding lawActiveFree full text

    Legally binding: EU law, a TSI-mandated specification or international treaty law.

    Issuing body: European Parliament & Council · Version: Directive (EU) 2022/2555 · Published: 2022-12-14

    Link verified August 5, 2026

    Scope

    The EU's horizontal cybersecurity directive: it classifies operators — including railway undertakings and infrastructure managers, listed under transport as essential entities — imposes cybersecurity risk-management measures and management accountability, and sets staged incident-notification obligations with significant sanctions.

    NIS2 is the reason cybersecurity moved from the IT department to the boardroom of every sizeable rail organisation. Annex I lists rail transport — infrastructure managers and railway undertakings — among the sectors of high criticality, making them essential or important entities depending on size; that triggers the Article 21 risk-management baseline (governance, supply-chain security, incident handling, business continuity, encryption, vulnerability handling) and the 24h/72h/one-month incident-reporting cascade of Article 23, with management bodies personally accountable for approving and overseeing the measures. For the technical layer the sector pairs NIS2 with TS 50701 / prEN 50701 and the IEC 62443 series: the directive says what outcomes are mandatory, the standards say how a railway control system is engineered and operated to achieve them. National transpositions apply from October 2024.

    More in this category

    All railway standards