Directive NIS2 European Union
Cart 0
What NIS2 is, and what it replaced

From NIS1 to NIS2


From NIS1 to NIS2

The first Network and Information Security Directive, Directive (EU) 2016/1148, covered a few hundred operators of essential services per member state and left member states wide discretion over who those operators were. The result was uneven: a hospital in scope in one country and outside it across the border, with no obvious justification.

NIS2 — Directive (EU) 2022/2555 — replaced it. It was adopted on 14 December 2022, published on 27 December 2022, entered into force on 16 January 2023, and repealed NIS1 with effect from 18 October 2024.

What changed materially

  • Scope widened from a handful of sectors to eighteen, and from a few hundred entities per country to roughly 160,000 across the Union.
  • Identification became automatic. Under NIS1, member states designated operators individually. Under NIS2, you are in scope if you meet the sector and size tests — nobody has to tell you.
  • Management became accountable. Article 20 obliges management bodies to approve measures, oversee implementation and follow training, and makes them liable.
  • Reporting became specific. A three-stage chain with hard deadlines replaced the vaguer NIS1 obligation.
  • Supervision was differentiated between essential entities (ex ante) and important entities (ex post).

The practical consequence of automatic identification is the one most often missed: an organisation can be in scope, and in breach, without ever having received a letter.

Cart 0