What is NIS2?
A directive on measures for a high common level of cybersecurity across the Union. It replaced NIS1, widened the scope from a few hundred operators to roughly 160,000 entities, and made senior management personally accountable.
The short version
NIS2 sets a minimum cybersecurity baseline for organisations that the EU considers critical to the functioning of the internal market. It does three things NIS1 did not: it widens the sectors in scope, it removes most of the national discretion over who is covered, and it attaches consequences to the people at the top rather than only to the organisation.
It is a directive, and that matters
This is the single most misunderstood point. NIS2 is a directive, not a regulation. It does not apply to you directly — the national law that transposes it does. Member states had until to transpose, and each one has:
- designated its own competent authority and CSIRT;
- set its own registration procedure and deadlines;
- decided whether to extend scope beyond the directive's floor;
- written its own penalty scale within the article 34 ceilings.
In practice this means a group operating in six member states faces six registration procedures, six reporting portals and six supervisory relationships — on top of one common security baseline. That gap is what our transposition tracker and country packs exist to close.
Who is in scope
Scope is the intersection of sector and size. The sector must appear in Annex I (eleven high-criticality sectors) or Annex II (seven further sectors). The size test then applies: medium-sized enterprises — 50 or more staff, or turnover and balance sheet total above €10 million — and large enterprises are in scope by default.
Some entities are in scope regardless of size, including sole DNS service providers, TLD name registries, trust service providers, providers of public electronic communications networks or services, and certain public administration entities.
See all 18 sectors and the size thresholds →
Essential or important
Entities in scope are classified as essential or important. The obligations are largely the same; the supervision is not. Essential entities face ex ante supervision — authorities may inspect proactively. Important entities face ex post supervision — authorities act on evidence of non-compliance. The maximum fines also differ.
What you actually have to do
Article 21(2) lists ten minimum risk-management measures. They are written as outcomes, not as controls, which is why most organisations map them onto an existing framework such as ISO/IEC 27001:2022 rather than starting from scratch.
The ten measures, one by one →
Reporting incidents
Article 23 sets a three-stage chain that starts the moment you become aware of a significant incident: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.
Management accountability
Article 20 is what changed the conversation in boardrooms. Management bodies must approve the risk-management measures, oversee their implementation, and follow training. They can be held liable for infringements, and under article 32(6) a competent authority can temporarily prohibit an individual from exercising managerial functions in an essential entity.
Penalties and personal liability →
If you are a financial entity
DORA takes precedence. Article 4 of NIS2 makes DORA lex specialis for ICT risk management and incident reporting by financial entities — where DORA covers the ground, DORA applies instead.
Common questions
Does NIS2 apply to us if we are not established in the EU?
We are already ISO/IEC 27001 certified. Are we NIS2 compliant?
Our member state has not finished transposing NIS2. Should we wait?
What counts as a significant incident under article 23?
What is the difference between an essential and an important entity?
Can directors be held personally liable?
Check your position in six questions
Free, no registration, runs entirely in your browser.