NIS-2: What laboratories need to know

A guide for laboratories: what the NIS-2 Directive means for you.

A guide for laboratories: NIS-2 and what you need to know now

Share:

Many laboratories are now part of critical infrastructure

The EU’s NIS-2 Directive (Network and Information Security Directive 2) entered into force in January 2023 and has significant implications for organisations considered part of critical infrastructure, including many laboratories.

What is the NIS-2 Directive?

The NIS-2 Directive succeeds the first EU NIS Directive and aims to strengthen cybersecurity and resilience across the EU. It expands IT security requirements and obliges organisations to improve the security of their systems so they can effectively defend against cyberattacks and other threats.

More organisations are now in scope:

In addition to sectors already covered by NIS-1, such as energy, transport, healthcare, finance, water management and digital infrastructure, the rules cover providers of public electronic communications services, more digital services such as social platforms, wastewater and waste management, manufacturing of critical products, postal and courier services, public administration at central and regional level, and space.

(Source: https://digital-strategy.ec.europa.eu/de/policies/nis2-directive)

Why does the NIS-2 Directive affect laboratories?

Laboratories are environments where numerous instruments, software applications and processes interact, increasing the risk of data loss, theft or tampering. They often have heterogeneous IT infrastructure that includes measuring instruments, enterprise systems such as ERP and CRM, and standard software such as Excel alongside the LIMS. This diversity of interconnected systems greatly increases the attack surface for potential threats .

Affected laboratories must therefore act and prepare for NIS-2 now at the latest: with the adoption of the Directive, data security becomes a legal requirement.

What should laboratories do now?

  1. Assess your current security position: Carry out a comprehensive risk assessment and identify vulnerabilities in your IT infrastructure.
  2. Train your employees: Human error accounts for a large proportion of security risks, making regular training essential.
  3. Review your LIMS and software suppliers: Ensure your current LIMS and software tools meet the NIS-2 Directive’s security requirements. If necessary, contact your provider about required upgrades or adjustments. Ask suppliers to document their information and, where appropriate, insist on independent certification such as ISO 27001.

For an example of this documentation for a LIMS, see our document NIS-2 Annex 3 (classification: public)

Summary

The NIS-2 Directive presents new challenges for laboratories, but also an opportunity to improve IT security sustainably. With LDB, you are well equipped to meet the new requirements while improving your laboratory’s efficiency.

Further information and support:

NIS-2 checklist

Find out whether the NIS-2 Directive applies to your laboratory:

  • 1

    Number of employees

    > 50

  • 2

    Annual turnover

    > €10 million

  • 3

    Industry

    You operate in one of 18 defined sectors:

    • Energy
      • Electricity supply
      • District heating and cooling
      • Fuel and heating oil
      • Gas
    • Transport
      • Air transport
      • Rail transport
      • Shipping
      • Road transport
      • Postal and courier services
    • Finance and insurance
      • Banking
      • Financial market infrastructure
    • Health
      • Services
      • Reference laboratories
      • R&D
      • Pharmaceuticals (NACE C, Division 21)
      • Medical devices
    • Water and wastewater
      • Drinking water
      • Wastewater
    • Information technology and telecommunications
      • IXPs
      • DNS
      • TLD
      • Cloud providers
      • Data centre services
      • CDNs
      • TSP
      • Electronic communications and services
      • Managed services and security services
    • Space
      • Ground infrastructure
    • Chemicals
      • Manufacturing
      • Trade
      • Production
    • Research
      • Research institutions
    • Manufacturing industry
      • Medical and diagnostic products
      • Computing, electrical equipment and optics (NACE C, Divisions 26 and 27)
      • Machinery (NACE C 28)
      • Motor vehicles and parts (NACE C 29)
      • Other transport equipment (NACE C 30)
    • Digital services
      • Marketplaces
      • Search engines
      • Social networks
    • Food
      • Wholesale
      • Production
      • Processing
    • Waste disposal
      • Waste management

Our customers

Certified to

LDB LIMS is ISO 27001-certified laboratory software

Preferred LIMS partner

VUP - Verband unabhängiger Prüflabore

We use our own cookies and third-party cookies so that we can display the website to you and better understand how you use it, in order to improve the services we offer.