# directive-nis2.eu > Independent European platform for NIS2 compliance — Directive (EU) 2022/2555. Sells assessment toolkits, policy packs, board packs and per-country transposition packs. Operated by Cryptaguard SRL (Belgium, VAT BE 1007.610.660). Not affiliated with the European Commission, ENISA, or any national competent authority. ## Key facts about NIS2 - Directive (EU) 2022/2555, adopted 14 December 2022, published 27 December 2022, entered into force 16 January 2023. - Repealed Directive (EU) 2016/1148 (NIS1) with effect from 18 October 2024. - National transposition deadline: 17 October 2024. It is a DIRECTIVE, so each of the 27 member states legislates its own scope, registration procedure, competent authority and penalty scale. - Covers 18 sectors across Annex I (11 sectors, high criticality) and Annex II (7 sectors). - Two entity classes: essential and important, with different supervisory regimes (ex ante vs ex post). - Article 20: management bodies must approve and oversee risk-management measures, follow training, and are liable for infringements. - Article 21(2): ten minimum cybersecurity risk-management measures, (a) to (j). - Article 23: incident reporting — 24h early warning, 72h notification, 1 month final report. - Article 32(6): competent authorities may temporarily ban individuals from management functions in essential entities. - Article 34: fines up to EUR 10,000,000 or 2% of worldwide annual turnover for essential entities; EUR 7,000,000 or 1.4% for important entities. ## Regulatory reference pages - [What is NIS2? Directive (EU) 2022/2555 explained](https://directive-nis2.eu/what-is-nis2): Reference page on NIS2. Directive (EU) 2022/2555 replaced Directive (EU) 2016/1148 (NIS1), repealed 18 October 2024. Two entity classes: essential and important, with different supervisory regimes (ex ante vs ex post). Article 21 lists ten minimum cybersecurity risk-management measures. Article 23 sets incident reporting: 24h early warning, 72h notification, 1 month final report. Article 20 makes management bodies personally accountable. Article 34 caps fines at €10m or 2% of worldwide turnover for essential entities, €7m or 1.4% for important entities. - [The ten article 21 measures — NIS2 risk management](https://directive-nis2.eu/article-21-measures): The ten minimum measures of NIS2 article 21(2): (a) risk analysis and information system security policies; (b) incident handling; (c) business continuity, backup management and crisis management; (d) supply chain security; (e) security in acquisition, development and maintenance; (f) policies to assess effectiveness of risk-management measures; (g) basic cyber hygiene and security training; (h) cryptography and encryption policies; (i) human resources security, access control and asset management; (j) multi-factor authentication, secured communications and emergency communication systems. - [NIS2 incident reporting: 24h, 72h and one month](https://directive-nis2.eu/incident-reporting): NIS2 article 23 incident reporting. An incident is significant if it causes or is capable of causing severe operational disruption or financial loss, or affects other natural or legal persons by causing considerable material or non-material damage. Chain: early warning to CSIRT or competent authority within 24 hours of becoming aware; incident notification within 72 hours including initial assessment, severity, impact and indicators of compromise; intermediate report on request; final report within one month covering detailed description, threat type, root cause, mitigation and cross-border impact. - [NIS2 scope: the 18 sectors of Annexes I and II](https://directive-nis2.eu/nis2-sectors): NIS2 covers 18 sectors. Annex I (high criticality, 11 sectors): energy; transport; banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure; ICT service management (B2B); public administration; space. Annex II (other critical, 7 sectors): postal and courier services; waste management; manufacture, production and distribution of chemicals; production, processing and distribution of food; manufacturing of medical devices, computers, electronics, machinery, motor vehicles; digital providers (online marketplaces, search engines, social networking platforms); research organisations. Size-cap rule: medium-sized (50+ staff or >€10m turnover) and large entities are in scope by default. - [NIS2 transposition tracker — all 27 member states](https://directive-nis2.eu/transposition): Transposition tracker for NIS2 across all 27 EU member states. NIS2 is a directive, not a regulation: it required national transposition by 17 October 2024, and each member state legislates its own scope extensions, registration procedure, competent authority, supervisory regime and penalty scale. This page tracks, per member state: transposition status, national law reference, competent authority, CSIRT, registration channel and incident reporting portal. In January 2025 the European Commission opened infringement procedures against member states that had missed the deadline. - [NIS2 penalties and management liability](https://directive-nis2.eu/penalties): NIS2 penalties. Article 34: essential entities face administrative fines up to €10,000,000 or 2% of total worldwide annual turnover, whichever is higher; important entities up to €7,000,000 or 1.4%. Article 20 makes management bodies approve risk-management measures, oversee implementation and follow training, and holds them liable for infringements. Article 32(6) allows competent authorities to temporarily prohibit a natural person from exercising managerial functions in an essential entity. Article 32 also allows suspension of certifications or authorisations. ## Comparisons - [NIS2 vs DORA: which applies to your organisation](https://directive-nis2.eu/nis2-vs-dora): NIS2 versus DORA. DORA (Regulation (EU) 2022/2554) applies from 17 January 2025 to 20 categories of financial entity. NIS2 article 4 makes DORA lex specialis: where DORA covers ICT risk management and incident reporting for a financial entity, DORA provisions apply instead of the NIS2 equivalents. Financial entities remain subject to NIS2 for matters DORA does not cover. DORA is a regulation (directly applicable, uniform), NIS2 is a directive (27 national transpositions, divergent). ## Free interactive tools - [Free NIS2 scope check — are you in scope?](https://directive-nis2.eu/tools/scope-check): Free interactive tool. Determines whether an organisation falls within NIS2 scope, and whether it qualifies as an essential or important entity, from sector (Annex I or II), headcount, turnover and member state. No registration required, runs entirely in the browser. - [Free NIS2 penalty exposure calculator](https://directive-nis2.eu/tools/penalty-calculator): Free interactive tool. Computes maximum NIS2 administrative fine exposure under article 34 from worldwide annual turnover and entity class: essential entities the higher of €10m or 2% of turnover, important entities the higher of €7m or 1.4%. Runs entirely in the browser. ## Products - [NIS2 toolkits, policy packs and country packs](https://directive-nis2.eu/catalogue): Product catalogue. Assessment toolkits per article 21 measure (Excel maturity scoring 0-4 plus PDF methodology), policy and procedure packs (editable Word), board packs (PowerPoint and Word for article 20 management accountability), incident reporting templates aligned with the article 23 24h/72h/1-month chain, and per-country transposition packs covering national law, competent authority and registration channel. All prices excluding VAT; VAT added at checkout by country, reverse charge available with a valid EU VAT number. ## About - [About directive-nis2.eu](https://directive-nis2.eu/about): About page. directive-nis2.eu is operated by Cryptaguard SRL, a Belgian company (VAT BE 1007.610.660) based in Sint-Pieters-Leeuw. Independent private platform, not affiliated with the European Commission, ENISA or any national competent authority. ## Sector pages (18 sectors of Annexes I and II) - [NIS2 for Energy — scope, obligations and traps](https://directive-nis2.eu/sectors/energy): Energy is sector 1 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Electricity; District heating and cooling; Oil; Gas; Hydrogen. Covered entities: Electricity undertakings, DSOs and TSOs, producers, nominated electricity market operators, electricity market participants, operators of recharging points; district heating and cooling operators; oil pipeline and production operators, central stockholding entities; gas supply undertakings, DSOs, TSOs, storage and LNG system operators, refining and treatment facilities; hydrogen producers, storage and transmission operators. Overlapping regimes: Directive (EU) 2022/2557 (CER) for physical resilience; network codes on cybersecurity for electricity under Regulation (EU) 2019/943. - [NIS2 for Transport — scope, obligations and traps](https://directive-nis2.eu/sectors/transport): Transport is sector 2 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Air; Rail; Water; Road. Covered entities: Air carriers, airport managing bodies, air traffic management; infrastructure managers and railway undertakings; inland, sea and coastal passenger and freight water transport companies, port managing bodies, vessel traffic services; road authorities and operators of intelligent transport systems. Overlapping regimes: EASA Part-IS for aviation; the CER directive; ISPS for maritime port facility security. - [NIS2 for Banking — scope, obligations and traps](https://directive-nis2.eu/sectors/banking): Banking is sector 3 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Credit institutions. Covered entities: Credit institutions as defined in Regulation (EU) No 575/2013. Overlapping regimes: DORA (Regulation (EU) 2022/2554) takes precedence for ICT risk management and ICT incident reporting. - [NIS2 for Financial market infrastructures — scope, obligations and traps](https://directive-nis2.eu/sectors/financial-market-infrastructures): Financial market infrastructures is sector 4 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Trading venues; Central counterparties. Covered entities: Operators of trading venues and central counterparties (CCPs). Overlapping regimes: DORA; EMIR for CCPs; MiFID II for trading venues. - [NIS2 for Health — scope, obligations and traps](https://directive-nis2.eu/sectors/health): Health is sector 5 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Healthcare providers; EU reference laboratories; R&D of medicinal products; Manufacture of basic pharmaceutical products; Medical devices critical during a public health emergency. Covered entities: Healthcare providers, EU reference laboratories, entities carrying out R&D of medicinal products, entities manufacturing basic pharmaceutical products and preparations, entities manufacturing medical devices considered critical during a public health emergency. Overlapping regimes: GDPR article 33 for personal data breaches; MDR (Regulation (EU) 2017/745); the CER directive. - [NIS2 for Drinking water — scope, obligations and traps](https://directive-nis2.eu/sectors/drinking-water): Drinking water is sector 6 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Suppliers and distributors of water intended for human consumption. Covered entities: Suppliers and distributors of water intended for human consumption, excluding distributors for whom distribution of water for human consumption is a non-essential part of their general activity. Overlapping regimes: Directive (EU) 2020/2184 on drinking water quality; the CER directive. - [NIS2 for Waste water — scope, obligations and traps](https://directive-nis2.eu/sectors/waste-water): Waste water is sector 7 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Collection, disposal and treatment of urban, domestic and industrial waste water. Covered entities: Undertakings collecting, disposing of or treating urban, domestic or industrial waste water, where that activity is an essential part of their general activity. Overlapping regimes: The CER directive; the Urban Waste Water Treatment Directive. - [NIS2 for Digital infrastructure — scope, obligations and traps](https://directive-nis2.eu/sectors/digital-infrastructure): Digital infrastructure is sector 8 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Internet exchange points; DNS service providers; TLD name registries; Cloud computing service providers; Data centre service providers; Content delivery networks; Trust service providers; Public electronic communications networks and services. Covered entities: IXP operators, DNS service providers excluding root name server operators, TLD name registries, cloud computing service providers, data centre service providers, content delivery network providers, trust service providers, providers of public electronic communications networks and publicly available electronic communications services. Overlapping regimes: eIDAS (Regulation (EU) No 910/2014) for trust service providers; the EECC (Directive (EU) 2018/1972) for telecoms. - [NIS2 for ICT service management (B2B) — scope, obligations and traps](https://directive-nis2.eu/sectors/ict-service-management): ICT service management (B2B) is sector 9 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Managed service providers; Managed security service providers. Covered entities: Managed service providers and managed security service providers. Overlapping regimes: Contractual obligations flowing down from customers subject to NIS2 or DORA. - [NIS2 for Public administration — scope, obligations and traps](https://directive-nis2.eu/sectors/public-administration): Public administration is sector 10 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Central government; Regional government where a member state so provides. Covered entities: Public administration entities of central government as defined by a member state, and public administration entities at regional level where a member state so provides. Overlapping regimes: National public-sector security frameworks; the EU Cybersecurity Regulation for Union institutions. - [NIS2 for Space — scope, obligations and traps](https://directive-nis2.eu/sectors/space): Space is sector 11 of 18, in Annex I of Directive (EU) 2022/2555. Entities that meet the size cap are essential entities, supervised ex ante, with maximum administrative fines of EUR 10,000,000 or 2% of worldwide annual turnover. Sub-sectors: Operators of ground-based infrastructure supporting space-based services. Covered entities: Operators of ground-based infrastructure, owned, managed and operated by member states or private parties, that support the provision of space-based services, excluding providers of public electronic communications networks. Overlapping regimes: The EU Space Programme Regulation; national space legislation. - [NIS2 for Postal and courier services — scope, obligations and traps](https://directive-nis2.eu/sectors/postal-and-courier): Postal and courier services is sector 12 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Postal service providers; Courier services. Covered entities: Postal service providers within the meaning of Directive 97/67/EC, including providers of courier services. Overlapping regimes: Directive 97/67/EC on postal services. - [NIS2 for Waste management — scope, obligations and traps](https://directive-nis2.eu/sectors/waste-management): Waste management is sector 13 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Undertakings carrying out waste management. Covered entities: Undertakings carrying out waste management, excluding those for whom waste management is not their principal economic activity. Overlapping regimes: Directive 2008/98/EC on waste. - [NIS2 for Chemicals — scope, obligations and traps](https://directive-nis2.eu/sectors/chemicals): Chemicals is sector 14 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Manufacture, production and distribution of chemicals. Covered entities: Undertakings carrying out the manufacture of substances and the distribution of substances or mixtures, and undertakings carrying out the production of articles from substances or mixtures. Overlapping regimes: REACH; Seveso III (Directive 2012/18/EU) for major accident hazards. - [NIS2 for Food — scope, obligations and traps](https://directive-nis2.eu/sectors/food): Food is sector 15 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Production, processing and distribution of food. Covered entities: Food businesses engaged in wholesale distribution and industrial production and processing. Overlapping regimes: Regulation (EC) No 178/2002 on food law; HACCP obligations. - [NIS2 for Manufacturing — scope, obligations and traps](https://directive-nis2.eu/sectors/manufacturing): Manufacturing is sector 16 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Medical devices and in vitro diagnostics; Computer, electronic and optical products; Electrical equipment; Machinery and equipment; Motor vehicles, trailers and semi-trailers; Other transport equipment. Covered entities: Manufacturers of medical devices and in vitro diagnostic medical devices; manufacturers of computer, electronic and optical products; electrical equipment; machinery and equipment n.e.c.; motor vehicles, trailers and semi-trailers; other transport equipment. Overlapping regimes: Cyber Resilience Act; MDR and IVDR; UNECE R155 and R156; the Machinery Regulation. - [NIS2 for Digital providers — scope, obligations and traps](https://directive-nis2.eu/sectors/digital-providers): Digital providers is sector 17 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Online marketplaces; Online search engines; Social networking services platforms. Covered entities: Providers of online marketplaces, online search engines and social networking services platforms. Overlapping regimes: Digital Services Act; Digital Markets Act; GDPR. - [NIS2 for Research organisations — scope, obligations and traps](https://directive-nis2.eu/sectors/research): Research organisations is sector 18 of 18, in Annex II of Directive (EU) 2022/2555. Entities that meet the size cap are important entities, supervised ex post, with maximum administrative fines of EUR 7,000,000 or 1.4% of worldwide annual turnover. Sub-sectors: Research organisations. Covered entities: Organisations whose primary goal is to conduct applied research or experimental development with a view to exploiting the results for commercial purposes, excluding educational institutions. Overlapping regimes: Horizon Europe grant security requirements; export control rules on dual-use research. ## Member state pages (all 27 national transpositions) - [NIS2 in Austria — transposition, authority and registration](https://directive-nis2.eu/nis2/austria): Austria (AT) has partially transposed NIS2. Competent authority: BMI / NISKO. National CSIRT: CERT.at. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Belgium — transposition, authority and registration](https://directive-nis2.eu/nis2/belgium): Belgium (BE) has transposed NIS2. Competent authority: Centre for Cybersecurity Belgium. National CSIRT: CCB / CSIRT.be. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Bulgaria — transposition, authority and registration](https://directive-nis2.eu/nis2/bulgaria): Bulgaria (BG) has partially transposed NIS2. Competent authority: Ministry of e-Government. National CSIRT: CERT Bulgaria. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Cyprus — transposition, authority and registration](https://directive-nis2.eu/nis2/cyprus): Cyprus (CY) has transposed NIS2. Competent authority: Digital Security Authority. National CSIRT: CSIRT-CY. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Czechia — transposition, authority and registration](https://directive-nis2.eu/nis2/czechia): Czechia (CZ) has transposed NIS2. Competent authority: NÚKIB. National CSIRT: GovCERT.CZ. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Germany — transposition, authority and registration](https://directive-nis2.eu/nis2/germany): Germany (DE) has transposed NIS2. Competent authority: BSI. National CSIRT: CERT-Bund. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Denmark — transposition, authority and registration](https://directive-nis2.eu/nis2/denmark): Denmark (DK) has transposed NIS2. Competent authority: Centre for Cyber Security. National CSIRT: CFCS. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Estonia — transposition, authority and registration](https://directive-nis2.eu/nis2/estonia): Estonia (EE) has transposed NIS2. Competent authority: Information System Authority. National CSIRT: CERT-EE. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Spain — transposition, authority and registration](https://directive-nis2.eu/nis2/spain): Spain (ES) has partially transposed NIS2. Competent authority: INCIBE / CCN. National CSIRT: INCIBE-CERT. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Finland — transposition, authority and registration](https://directive-nis2.eu/nis2/finland): Finland (FI) has transposed NIS2. Competent authority: Traficom. National CSIRT: NCSC-FI. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in France — transposition, authority and registration](https://directive-nis2.eu/nis2/france): France (FR) has transposed NIS2. Competent authority: ANSSI. National CSIRT: CERT-FR. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Greece — transposition, authority and registration](https://directive-nis2.eu/nis2/greece): Greece (GR) has transposed NIS2. Competent authority: National Cybersecurity Authority. National CSIRT: NCSA-GR. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Croatia — transposition, authority and registration](https://directive-nis2.eu/nis2/croatia): Croatia (HR) has transposed NIS2. Competent authority: SOA / ZSIS. National CSIRT: CERT.hr. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Hungary — transposition, authority and registration](https://directive-nis2.eu/nis2/hungary): Hungary (HU) has transposed NIS2. Competent authority: SZTFH. National CSIRT: NBSZ NKI. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Ireland — transposition, authority and registration](https://directive-nis2.eu/nis2/ireland): Ireland (IE) has partially transposed NIS2. Competent authority: NCSC Ireland. National CSIRT: CSIRT-IE. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Italy — transposition, authority and registration](https://directive-nis2.eu/nis2/italy): Italy (IT) has transposed NIS2. Competent authority: ACN. National CSIRT: CSIRT Italia. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Lithuania — transposition, authority and registration](https://directive-nis2.eu/nis2/lithuania): Lithuania (LT) has transposed NIS2. Competent authority: NKSC. National CSIRT: CERT-LT. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Luxembourg — transposition, authority and registration](https://directive-nis2.eu/nis2/luxembourg): Luxembourg (LU) has transposed NIS2. Competent authority: ILR / HCPN. National CSIRT: CIRCL / GOVCERT.LU. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Latvia — transposition, authority and registration](https://directive-nis2.eu/nis2/latvia): Latvia (LV) has transposed NIS2. Competent authority: National Cybersecurity Centre. National CSIRT: CERT.LV. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Malta — transposition, authority and registration](https://directive-nis2.eu/nis2/malta): Malta (MT) has partially transposed NIS2. Competent authority: Malta Digital Innovation Auth.. National CSIRT: CSIRTMalta. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Netherlands — transposition, authority and registration](https://directive-nis2.eu/nis2/netherlands): Netherlands (NL) has partially transposed NIS2. Competent authority: RDI / NCTV. National CSIRT: NCSC-NL. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Poland — transposition, authority and registration](https://directive-nis2.eu/nis2/poland): Poland (PL) has partially transposed NIS2. Competent authority: Ministry of Digital Affairs. National CSIRT: CSIRT NASK / GOV / MON. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Portugal — transposition, authority and registration](https://directive-nis2.eu/nis2/portugal): Portugal (PT) has partially transposed NIS2. Competent authority: CNCS. National CSIRT: CERT.PT. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Romania — transposition, authority and registration](https://directive-nis2.eu/nis2/romania): Romania (RO) has transposed NIS2. Competent authority: DNSC. National CSIRT: DNSC. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Sweden — transposition, authority and registration](https://directive-nis2.eu/nis2/sweden): Sweden (SE) has partially transposed NIS2. Competent authority: MSB. National CSIRT: CERT-SE. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Slovenia — transposition, authority and registration](https://directive-nis2.eu/nis2/slovenia): Slovenia (SI) has transposed NIS2. Competent authority: URSIV. National CSIRT: SI-CERT. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. - [NIS2 in Slovakia — transposition, authority and registration](https://directive-nis2.eu/nis2/slovakia): Slovakia (SK) has transposed NIS2. Competent authority: NBU. National CSIRT: SK-CERT. Standard VAT rate applies to purchases from this country. NIS2 obligations derive from the national transposition law, not directly from Directive (EU) 2022/2555. ## Analysis - [The 24-hour clock starts earlier than you think](https://directive-nis2.eu/blog/24-hour-clock): Analysis of the NIS2 article 23 early warning deadline. The 24-hour period runs from the moment the entity becomes AWARE of a significant incident, not from the incident occurring nor from completing the investigation. Significance under article 23(3) includes incidents "capable of causing" severe operational disruption or considerable damage, so contained incidents can be reportable. Practical recommendation: pre-authorise a written significance decision rule that on-call staff can apply without convening a committee, and treat the early warning as a low-cost, reversible filing rather than a final position. - [Good security, no paperwork: the article 20 gap](https://directive-nis2.eu/blog/board-approval-gap): Analysis of NIS2 article 20 management body obligations. Article 20(1) requires management bodies to approve cybersecurity risk-management measures and oversee their implementation, and makes them liable for infringements. Article 20(2) requires members of management bodies to follow training and to offer similar training to employees. Article 32(6) allows competent authorities to temporarily prohibit a natural person at CEO or legal representative level from exercising managerial functions in an essential entity. Key insight: technical maturity does not evidence compliance with article 20; a documented approval decision, recurring oversight reporting and training records do. - [Supply chain security stops at your direct suppliers — and that is harder than it sounds](https://directive-nis2.eu/blog/supply-chain-direct-suppliers): Analysis of NIS2 article 21(2)(d) supply chain security. The obligation covers security-related aspects of relationships with DIRECT suppliers and service providers, not the entire multi-tier supply chain. Article 21(3) requires entities to take into account each direct supplier's specific vulnerabilities, the overall quality of their products and cybersecurity practices, and their secure development procedures, plus the results of coordinated Union-level security risk assessments under article 22. Practical implication: depth of assessment on a defined direct-supplier population matters more than breadth across tiers, and a returned questionnaire is not evidence without verification. - [One directive, 27 laws: what actually differs between member states](https://directive-nis2.eu/blog/one-directive-27-laws): Analysis of NIS2 national transposition divergence. NIS2 is a directive requiring national transposition by 17 October 2024, so obligations derive from national law rather than directly from Directive (EU) 2022/2555. Uniform across member states: the ten article 21(2) measures, the article 23 reporting deadlines of 24 hours, 72 hours and one month, the article 20 management body duties, and the article 34 fine ceilings. Divergent by member state: registration procedure and portal, scope extensions below the size cap, designation of regional and local public administration, supervisory intensity, penalty calibration within the ceilings, and reporting channel and language. Article 26 sets jurisdiction, generally the member state of establishment, with specific rules placing certain digital providers under the jurisdiction of their main establishment. ## Glossary terms - [Essential entity](https://directive-nis2.eu/glossary/essential-entity): An entity in an Annex I sector that exceeds the ceilings for medium-sized enterprises, plus specific categories listed regardless of size. - [Important entity](https://directive-nis2.eu/glossary/important-entity): An entity in scope that does not qualify as essential — typically medium-sized enterprises and entities in Annex II sectors. - [Significant incident](https://directive-nis2.eu/glossary/significant-incident): An incident that has caused or is capable of causing severe operational disruption or financial loss, or considerable material or non-material damage to others. - [Early warning](https://directive-nis2.eu/glossary/early-warning): The first filing, due within 24 hours of becoming aware of a significant incident. - [Size-cap rule](https://directive-nis2.eu/glossary/size-cap-rule): The rule that brings medium-sized and large enterprises in Annex I and II sectors into scope by default. - [CSIRT](https://directive-nis2.eu/glossary/csirt): Computer Security Incident Response Team — the national body designated by each member state to receive incident notifications and provide assistance. - [Competent authority](https://directive-nis2.eu/glossary/competent-authority): The national authority responsible for supervising NIS2 compliance and enforcing it. - [Lex specialis](https://directive-nis2.eu/glossary/lex-specialis): The principle by which a sector-specific EU act displaces the equivalent NIS2 provisions when it is at least equivalent in effect. - [Management body](https://directive-nis2.eu/glossary/management-body): The governing organ of an entity, which must approve cybersecurity risk-management measures, oversee their implementation and follow training. - [Supply chain security](https://directive-nis2.eu/glossary/supply-chain-security): The obligation to address security in relationships with direct suppliers and service providers. - [Coordinated vulnerability disclosure](https://directive-nis2.eu/glossary/coordinated-vulnerability-disclosure): The process by which a reporter discloses a vulnerability to a vendor in a way that allows a fix before public disclosure. - [TLPT (threat-led penetration testing)](https://directive-nis2.eu/glossary/tlpt): Adversary-simulation testing against live production systems, mandated by DORA for significant financial entities. - [Registration](https://directive-nis2.eu/glossary/register-of-entities): The duty to notify your national authority that you are an entity in scope, with specified identifying information. - [Ex ante supervision](https://directive-nis2.eu/glossary/ex-ante-supervision): Proactive supervision applied to essential entities, without needing any indication of non-compliance. - [Basic cyber hygiene practices](https://directive-nis2.eu/glossary/cyber-hygiene): The baseline practices every entity must implement, alongside cybersecurity training. ## Homepage - [NIS2 compliance for the European Union](https://directive-nis2.eu/): Homepage. NIS2 = Directive (EU) 2022/2555, in force since 16 January 2023, national transposition deadline 17 October 2024. Covers ~160,000 entities across 18 sectors in Annexes I and II. Sells certifications, assessment toolkits, policy packs and per-country transposition packs.