Skip to main content

NIS 1 Directive.

NIS 1 (Directive 2016/1148) was the EU's first cross-sector cybersecurity directive, covering operators of essential services and digital service providers. Replaced by NIS 2 in October 2024 because scope was too narrow, enforcement uneven and incident reporting toothless. Cited here mainly so you know what the "old regime" your colleagues still half-remember actually was.

By Christophe Mazzola, Practicing CISO · Founder of Cyber AcademyEU regulationsAll entries

The Cyber Academy take

NIS 1 (Directive 2016/1148) was the EU's first cross-sector cybersecurity directive, covering operators of essential services and digital service providers. Replaced by NIS 2 in October 2024 because scope was too narrow, enforcement uneven and incident reporting toothless. Cited here mainly so you know what the "old regime" your colleagues still half-remember actually was.

What NIS 1 set out to do

The NIS 1 Directive was the European Union's first attempt to put a common cybersecurity floor under the sectors that keep a country running. Before it, member states approached the security of critical infrastructure on their own terms, with no shared baseline and no coordinated way to handle incidents that crossed borders. NIS 1 changed that by asking every member state to identify the operators whose disruption would have a serious knock-on effect, hold them to security and incident-reporting obligations, and stand up the national machinery to supervise them. In France that machinery was ANSSI, and the operators it designated were already familiar with the heavier OIV regime that predated the directive.

Because it was a directive and not a regulation, NIS 1 did not apply directly. Each member state had to transpose it into national law, which is where much of the unevenness came from. Two states could read the same text and end up with different lists of regulated entities, different reporting thresholds, and very different appetites for enforcement. That patchwork is the single biggest reason the regime was eventually rebuilt.

Two categories: essential services and digital service providers

NIS 1 split the regulated world into two groups, and the distinction matters because the obligations and the supervision were not symmetrical.

NIS 1 categories
AspectOperators of essential servicesDigital service providers
Who they wereEnergy, transport, banking, financial market infrastructure, health, drinking water, digital infrastructureOnline marketplaces, search engines, cloud computing services
How they were caughtIdentified case by case by each member state against criteriaIn scope automatically, with a lighter touch
SupervisionProactive: authorities could audit and demand evidenceMostly reactive: action after an incident
Security expectationAppropriate, proportionate technical and organisational measuresSimilar measures, but a lighter regulatory regime

Operators of essential services were the heart of the directive. Member states had to name them, and once named they carried real obligations to manage risk and to notify significant incidents to the national authority or CSIRT. Digital service providers were treated more lightly on the theory that they already operated across borders and competed on resilience, so a harmonised but lighter regime would avoid fragmenting the single market.

Why it was replaced

The honest verdict on NIS 1 is that it proved the concept but under-delivered. Three weaknesses came up repeatedly. The scope was too narrow, leaving whole sectors and most medium-sized organisations outside any obligation even when their failure would hurt. Enforcement was uneven, because transposition left each member state to decide who was in scope and how hard to push, so a company could be regulated in one country and untouched next door. And incident reporting was effectively toothless, with thresholds and timelines that varied so much that the cross-border visibility the directive was meant to create never really materialised.

NIS 2 was the answer to all three. It widened scope to far more sectors and to a size-based criterion, replaced the OES/DSP split with essential and important entities, tightened incident reporting into clearer stages, and put real management accountability and sanctions behind the obligations. For a practitioner today, NIS 1 is mainly context: it explains the shape of the rules you now live under and the reflexes your organisation built before the rebuild.

Frequently asked questions

01Is NIS 1 still in force?

No. NIS 1 was repealed and replaced by the NIS 2 Directive, which became applicable in October 2024. Obligations now flow from NIS 2 and its national transposition, not from the 2016 directive.

02What is the difference between an OES and a DSP under NIS 1?

Operators of essential services were identified case by case by member states in critical sectors and faced proactive supervision. Digital service providers, such as cloud providers and online marketplaces, were in scope more automatically and supervised under a lighter, mostly reactive regime.

03Why was NIS 1 considered too weak?

Its scope was narrow, transposition left enforcement uneven between member states, and incident-reporting rules varied so much that cross-border visibility never worked as intended. NIS 2 was written specifically to fix those three gaps.

04If my organisation complied with NIS 1, does that cover NIS 2?

Not by default. NIS 2 broadens scope, raises expectations on risk management and reporting, and adds management accountability. A NIS 1 programme is a useful starting point but needs a gap analysis against NIS 2.

05How does NIS 1 relate to GDPR?

They are separate. GDPR protects personal data and is enforced by data protection authorities. NIS 1 was about the operational security and resilience of essential and digital services. An incident can trigger both regimes at once.

Need more than a definition?

Book a free 20-minute discovery call. We map the cohort that turns this term into an audit-ready practice.