In their recent Law360 article, Goodwin partner Curtis McCluskey and associate Joseph Ndep explain how, a year after the European Union’s updated Network and Information Systems Directive, or NIS2, took effect on October 18, 2024, organizations across the EU are facing mounting pressure to meet new cybersecurity standards. As EU member states implement NIS2 with varying requirements and timelines, organizations operating across borders must understand their obligations and take proactive steps to stay compliant. The NIS2 aims to enhance the cybersecurity compliance of critical public and private sector organizations across the EU. It significantly expands the scope of its predecessor by introducing two categories of regulated organizations: “essential” and “important” entities. Although NIS2 establishes a common baseline for cybersecurity regulation across the EU, national implementation demonstrates that several EU member states are adding their own and, in some cases, stricter requirements.
Read the full analysis: “Navigating Compliance as EU Cybersecurity Rules Evolve” (Law360)
This informational piece, which may be considered advertising under the ethical rules of certain jurisdictions, is provided on the understanding that it does not constitute the rendering of legal advice or other professional advice by Goodwin or its lawyers. Prior results do not guarantee similar outcomes.
Contacts
- /en/people/m/mccluskey-curtis

Curtis McCluskey
Partner - /en/people/n/ndep-joseph

Joseph Ndep
Associate