{"id":43,"date":"2025-12-04T10:03:58","date_gmt":"2025-12-04T08:03:58","guid":{"rendered":"https:\/\/upcloud.com\/global\/us\/2025\/12\/04\/security-requirements-nis2-directive\/"},"modified":"2025-12-04T10:03:58","modified_gmt":"2025-12-04T08:03:58","slug":"security-requirements-nis2-directive","status":"publish","type":"post","link":"https:\/\/upcloud.com\/global\/blog\/security-requirements-nis2-directive\/","title":{"rendered":"Security Requirements under NIS2 Directive"},"content":{"rendered":"\n<p>Directive (EU) 2022\/2555, also known as <a href=\"https:\/\/eur-lex.europa.eu\/eli\/dir\/2022\/2555\/2022-12-27\/eng\" target=\"_blank\" rel=\"noopener\">NIS2 Directive<\/a>, is the European Union\u2019s updated framework for cybersecurity, replacing the original NIS Directive.&nbsp;<\/p>\n\n\n\n<p>This new directive expands the scope of covered entities to include more industries, and aims to enhance Member States\u2019 capability to protect network and information systems, their users, and other affected individuals from cyber incidents and threats.&nbsp;<\/p>\n\n\n\n<p>In Finland, the directive was transposed into national legislation through <a href=\"https:\/\/www.finlex.fi\/fi\/lainsaadanto\/saadoskokoelma\/2025\/124?highlightId=591693&amp;highlightParams=%7B%22type%22%3A%22BASIC%22%2C%22search%22%3A%22kyberturvallisuuslaki%22%7D&amp;language=fin#OT1_OT4\" target=\"_blank\" rel=\"noopener\">Cybersecurity Act (124\/2025)<\/a>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Key requirements<\/strong><\/h2>\n\n\n\n<p>NIS2 brings several requirements for cloud service providers concerning cybersecurity risk and incident management. While these security focused requirements are not new to cloud providers, they are no longer based on voluntary standards and certifications \u2013 they are mandatory legal requirements.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Risk Analysis: <\/strong>Companies must conduct thorough risk analyses to identify and evaluate all potential cybersecurity threats.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Security Measures:<\/strong> Companies must implement appropriate security measures to protect data and systems, including business continuity plans, supply chain security controls, vulnerability handling and disclosure processes, penetration testing, security training for staff, application of cryptography, and access control measures.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Incident Reporting: <\/strong>Companies must have processes in place to detect, manage, and report cybersecurity incidents. The national cybersecurity authority must be notified of any significant cybersecurity incidents. NIS2 sets strict deadlines for the notification, requiring companies to be prepared for incident handling.\u00a0<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Ensuring security and compliance at UpCloud<\/strong><\/h2>\n\n\n\n<p>UpCloud is responsible for meeting the requirements of the NIS2 Directive while also supporting customers in their compliance efforts.&nbsp;<\/p>\n\n\n\n<p>Our ISO 27001-certified Information Security Management System (ISMS) provides the foundation, with established policies for risk management and incident handling to ensure security incidents are effectively prevented, managed, and communicated to both authorities and customers when required. We provide annual employee training on ISMS and data privacy, and enforce strict access controls for internal systems and premises.\u00a0<\/p>\n\n\n\n<p>We have embedded security requirements to our software development and supply chain management through dedicated policies and onboarding processes, safeguarding our products from development through delivery. We offer our customers additional product security features, such as multifactor authentication, encryption,w and backups.&nbsp;<\/p>\n\n\n\n<p>The effectiveness of these measures is verified with annual audits and penetration testing. Through this approach, UpCloud maintains continuous compliance with NIS2 and provides a secure and resilient environment for our customers.<\/p>\n\n\n\n<p>Read more about security on our <a href=\"https:\/\/upcloud.com\/global\/security-privacy\/\">Security &amp; Privacy <\/a>page. Or <a href=\"https:\/\/upcloud.com\/global\/contact\/#form\">reach out to our team<\/a> to further discuss.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Directive (EU) 2022\/2555, also known as NIS2 Directive, is the European Union\u2019s updated framework for cybersecurity, replacing the original NIS Directive.&nbsp; This new directive expands [&hellip;]<\/p>\n","protected":false},"author":109,"featured_media":71434,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"715,655,19,496,148,322","_relevanssi_noindex_reason":"Blocked by a filter function","footnotes":""},"categories":[10,16],"tags":[],"class_list":["post-43","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-security","category-upcloud-insights"],"acf":[],"_links":{"self":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/43","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/users\/109"}],"replies":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/comments?post=43"}],"version-history":[{"count":0,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/posts\/43\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/media?parent=43"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/categories?post=43"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/upcloud.com\/global\/wp-json\/wp\/v2\/tags?post=43"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}