It expanded the old NIS regime to more sectors and stronger supervision.
NIS2 regulates cybersecurity risk management and incident reporting for essential and important entities across critical sectors; the exam trap is confusing which sectors are essential versus important.