Skip to content
14/14RegulationLegal obligation

NIS2 / GDPR / HIPAA

These are laws and regulations — not optional guidance.

What it is

NIS2 is an EU directive raising cybersecurity requirements for "essential" and "important" entities across critical sectors, with governance and incident-reporting duties and national-law transposition. GDPR is the EU regulation governing protection of personal data, with strict obligations and significant fines. HIPAA is the US regime whose Security Rule protects electronic health information (ePHI).

Certifiable?

No — these are legal obligations. Frameworks above help you demonstrate compliance, but you comply with the law itself.

Where it's used

NIS2 & GDPR — EU (and anyone handling EU personal data). HIPAA — US healthcare and its business associates.

Effort level

N/A — legal obligations don't scale by choice; scope depends on the law.

Typical trigger

You fall within scope by sector, data type, or market — compliance is mandatory, not chosen.

Related frameworks

ISO 27001 / SOC 2 / CIS controls provide much of the evidence, but never replace legal counsel.

Why it matters

NIS2, GDPR, and HIPAA are laws — not optional frameworks. Non-compliance carries significant fines, legal liability, and operational restrictions. Technical frameworks help you build the controls, but the law defines what you must achieve.

When is it needed?

Immediately upon falling within scope. NIS2 if you're an essential or important entity in the EU. GDPR if you process EU personal data. HIPAA if you handle US electronic health information. These aren't chosen — they apply by operation of law.

Use cases

  • Any company processing EU personal data (GDPR)
  • Essential and important entities in EU member states (NIS2)
  • US healthcare providers and business associates (HIPAA)
  • Cross-border data processing operations
  • SaaS platforms serving regulated customers

Who asks for it?

  • Data protection authorities (GDPR enforcement)
  • National competent authorities for NIS2
  • US Department of Health and Human Services (HIPAA)
  • Data subjects exercising their rights
  • Business partners requiring compliance warranties

Benefits

  • Compliance avoids severe financial penalties
  • Demonstrates accountability to data subjects and patients
  • Creates competitive advantage in privacy-conscious markets
  • Structured incident reporting improves response maturity
  • Aligns organizational security with legal obligations
  • Builds trust with customers and regulators

Legal requirements

Yes — these are legally binding obligations. GDPR: fines up to 4% of global annual turnover or €20M. NIS2: significant fines and management liability. HIPAA: fines up to $1.5M per violation category per year, plus criminal penalties.

Key control areas

Data protection by design and default (GDPR)
72-hour breach notification (GDPR/NIS2)
Risk management measures for network and information systems (NIS2)
Supply chain security requirements (NIS2)
Administrative, physical, and technical safeguards (HIPAA)
Access controls and audit trails (HIPAA Security Rule)
Data processing records and impact assessments (GDPR)

Want to see how Compscan maps your environment to NIS2 / GDPR / HIPAA?