{
  "node_id": "eu-nis2-critical-infrastructure-operators",
  "title": "Directive (EU) 2022/2555 of the European Parliament and of the Council of 16 December 2022 on measures for a high common level of cybersecurity across the Union, amending Directive (EU) 2016/1148 and repealing Directive (EU) 2016/1148",
  "domain": "Industrial IoT & Energy",
  "version": "1.0.1",
  "last_updated": "2026-04-30",
  "bluf": "The EU NIS2 Directive establishes binding cybersecurity and incident reporting requirements for essential and important entities operating critical infrastructure in sectors including energy, transport, health, and digital infrastructure. It mandates risk management measures, supply chain security, and cooperation among Member States’ supervisory authorities under Article 21 and Article 23.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "eu-cyber-resilience-act-iot-2024-products",
    "etsi-en-303-645-iot-cybersecurity-2020",
    "api-std-1164-scada-pipeline-security",
    "eu-data-act-2023-iot-data-sharing-obligations"
  ],
  "primary_citations_count": 5
}