NIS2 Directive – Directive (EU) 2022/2555 – Recital 77
Recitals
Recital 77
Recital 77
Risk Management Culture for Entities Unofficial title
Responsibility for ensuring the security of network and information system lies, to a great extent, with essential and important entities. A culture of risk management, involving risk assessments and the implementation of cybersecurity risk-management measures appropriate to the risks faced, should be promoted and developed.
https://nis2.digiphile.law/recital/recital-77.html
Text as at 19 September 2026.
This is an unofficial convenience version of the EU NIS2 Directive (Directive (EU) 2022/2555). It is presented “as is” without guarantee of accuracy, completeness or reliability. See the source text for the official version. This site was last updated in September 2026.