NIS2 / GDPR / HIPAA
These are laws and regulations — not optional guidance.
What it is
NIS2 is an EU directive raising cybersecurity requirements for "essential" and "important" entities across critical sectors, with governance and incident-reporting duties and national-law transposition. GDPR is the EU regulation governing protection of personal data, with strict obligations and significant fines. HIPAA is the US regime whose Security Rule protects electronic health information (ePHI).
Certifiable?
No — these are legal obligations. Frameworks above help you demonstrate compliance, but you comply with the law itself.
Where it's used
NIS2 & GDPR — EU (and anyone handling EU personal data). HIPAA — US healthcare and its business associates.
Effort level
N/A — legal obligations don't scale by choice; scope depends on the law.
Typical trigger
You fall within scope by sector, data type, or market — compliance is mandatory, not chosen.
Related frameworks
ISO 27001 / SOC 2 / CIS controls provide much of the evidence, but never replace legal counsel.
Why it matters
NIS2, GDPR, and HIPAA are laws — not optional frameworks. Non-compliance carries significant fines, legal liability, and operational restrictions. Technical frameworks help you build the controls, but the law defines what you must achieve.
When is it needed?
Immediately upon falling within scope. NIS2 if you're an essential or important entity in the EU. GDPR if you process EU personal data. HIPAA if you handle US electronic health information. These aren't chosen — they apply by operation of law.
Use cases
- Any company processing EU personal data (GDPR)
- Essential and important entities in EU member states (NIS2)
- US healthcare providers and business associates (HIPAA)
- Cross-border data processing operations
- SaaS platforms serving regulated customers
Who asks for it?
- Data protection authorities (GDPR enforcement)
- National competent authorities for NIS2
- US Department of Health and Human Services (HIPAA)
- Data subjects exercising their rights
- Business partners requiring compliance warranties
Benefits
- Compliance avoids severe financial penalties
- Demonstrates accountability to data subjects and patients
- Creates competitive advantage in privacy-conscious markets
- Structured incident reporting improves response maturity
- Aligns organizational security with legal obligations
- Builds trust with customers and regulators
Legal requirements
Yes — these are legally binding obligations. GDPR: fines up to 4% of global annual turnover or €20M. NIS2: significant fines and management liability. HIPAA: fines up to $1.5M per violation category per year, plus criminal penalties.
Key control areas
Want to see how Compscan maps your environment to NIS2 / GDPR / HIPAA?