Directive NIS2 European Union
Cart 0
Directive (EU) 2022/2555

What is NIS2?


A directive on measures for a high common level of cybersecurity across the Union. It replaced NIS1, widened the scope from a few hundred operators to roughly 160,000 entities, and made senior management personally accountable.

The short version

NIS2 sets a minimum cybersecurity baseline for organisations that the EU considers critical to the functioning of the internal market. It does three things NIS1 did not: it widens the sectors in scope, it removes most of the national discretion over who is covered, and it attaches consequences to the people at the top rather than only to the organisation.

It is a directive, and that matters

This is the single most misunderstood point. NIS2 is a directive, not a regulation. It does not apply to you directly — the national law that transposes it does. Member states had until to transpose, and each one has:

  • designated its own competent authority and CSIRT;
  • set its own registration procedure and deadlines;
  • decided whether to extend scope beyond the directive's floor;
  • written its own penalty scale within the article 34 ceilings.

In practice this means a group operating in six member states faces six registration procedures, six reporting portals and six supervisory relationships — on top of one common security baseline. That gap is what our transposition tracker and country packs exist to close.

Who is in scope

Scope is the intersection of sector and size. The sector must appear in Annex I (eleven high-criticality sectors) or Annex II (seven further sectors). The size test then applies: medium-sized enterprises — 50 or more staff, or turnover and balance sheet total above €10 million — and large enterprises are in scope by default.

Some entities are in scope regardless of size, including sole DNS service providers, TLD name registries, trust service providers, providers of public electronic communications networks or services, and certain public administration entities.

See all 18 sectors and the size thresholds →

Essential or important

Entities in scope are classified as essential or important. The obligations are largely the same; the supervision is not. Essential entities face ex ante supervision — authorities may inspect proactively. Important entities face ex post supervision — authorities act on evidence of non-compliance. The maximum fines also differ.

What you actually have to do

Article 21(2) lists ten minimum risk-management measures. They are written as outcomes, not as controls, which is why most organisations map them onto an existing framework such as ISO/IEC 27001:2022 rather than starting from scratch.

The ten measures, one by one →

Reporting incidents

Article 23 sets a three-stage chain that starts the moment you become aware of a significant incident: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within one month.

The full reporting chain →

Management accountability

Article 20 is what changed the conversation in boardrooms. Management bodies must approve the risk-management measures, oversee their implementation, and follow training. They can be held liable for infringements, and under article 32(6) a competent authority can temporarily prohibit an individual from exercising managerial functions in an essential entity.

Penalties and personal liability →

If you are a financial entity

DORA takes precedence. Article 4 of NIS2 makes DORA lex specialis for ICT risk management and incident reporting by financial entities — where DORA covers the ground, DORA applies instead.

How NIS2 and DORA interact →

Common questions

Does NIS2 apply to us if we are not established in the EU?
It can. Entities established outside the Union fall in scope where they provide services within it, and certain provider categories — DNS service providers, TLD name registries, cloud computing and data centre providers, content delivery networks, managed service providers, online marketplaces, search engines and social networking platforms — must designate a representative established in a member state where they offer services. Establishment of the service, not the nationality of the company, drives jurisdiction.
We are already ISO/IEC 27001 certified. Are we NIS2 compliant?
No. Certification is strong evidence for several of the ten article 21(2) measures, but it is not equivalence. NIS2 adds duties that ISO/IEC 27001 does not cover: registration with your national competent authority, the article 23 reporting deadlines of 24 hours, 72 hours and one month, and the article 20 obligation for management bodies to approve measures, oversee implementation and follow training.
Our member state has not finished transposing NIS2. Should we wait?
No. The security baseline in article 21 is fixed by the directive and will not change; only procedural details such as registration forms and reporting portals depend on national law. Organisations that waited for their national text are now compressing an 18-month programme into whatever time remains. The European Commission opened infringement procedures in 2025 against member states that missed the 17 October 2024 deadline, which means national deadlines are arriving late but arriving.
What counts as a significant incident under article 23?
An incident is significant if it has caused or is capable of causing severe operational disruption of the services or financial loss for the entity concerned, or if it has affected or is capable of affecting other natural or legal persons by causing considerable material or non-material damage. The 24-hour clock starts when you become aware of the incident, not when it began.
What is the difference between an essential and an important entity?
The security obligations are substantially the same. Supervision and penalties differ. Essential entities are subject to ex ante supervision: authorities may carry out inspections and audits proactively. Important entities are subject to ex post supervision: authorities act on evidence of non-compliance. Maximum administrative fines are EUR 10,000,000 or 2% of worldwide annual turnover for essential entities, and EUR 7,000,000 or 1.4% for important entities, whichever is higher in each case.
Can directors be held personally liable?
Yes. Article 20 requires management bodies to approve cybersecurity risk-management measures, oversee their implementation, and follow training. Member states must ensure they can be held liable for infringements. Article 32(6) additionally allows competent authorities to request a temporary prohibition on any natural person exercising managerial functions at chief executive officer or legal representative level in an essential entity.

Check your position in six questions

Free, no registration, runs entirely in your browser.

Check if you are in scope

Cart 0