Directive NIS2 European Union
Cart 0
What NIS2 is, and what it replaced

A directive, not a regulation


A directive, not a regulation

This distinction determines how you should organise your entire compliance effort, so it is worth being precise about it.

A regulation applies directly and identically in every member state. DORA is a regulation: a bank in Dublin and a bank in Athens read the same text and owe the same duties.

A directive binds member states as to the result to be achieved, and leaves them to legislate the means. NIS2 is a directive. What binds your organisation is not Directive (EU) 2022/2555 — it is the national law that transposed it.

What follows in practice

Some things are fixed by the directive and will not differ:

  • The ten minimum measures of article 21(2)
  • The reporting deadlines of article 23 — 24 hours, 72 hours, one month
  • The management body duties of article 20
  • The fine ceilings of article 34

Other things are national and differ substantially: the registration procedure and portal, whether scope was extended below the directive's thresholds, whether regional and local public bodies are covered, the intensity of supervision, and how an authority calibrates a fine within the ceilings.

So: build the security programme once, centrally. Treat registration, supervision and reporting channels as a per-country matter with a named owner. Groups that invert this — one compliance relationship, six security programmes — spend far more and end up less defensible.

Cart 0