NIS2 Directive
Directive (EU) 2022/2555 — Measures for a High Common Level of Cybersecurity Across the Union
Standard Introduction
The NIS2 Directive (Network and Information Security Directive 2) is an EU-wide cybersecurity legislation that establishes a high common level of cybersecurity across all member states. Adopted in November 2022 with a transposition deadline of October 2024, it significantly expands the scope of the original NIS Directive to cover 18 critical sectors and an estimated 160,000+ entities.
NIS2 introduces stricter requirements including management accountability, harmonized incident reporting timelines, and substantial penalties for non-compliance. It represents the EU’s most comprehensive cybersecurity legislation, mandating baseline security measures and creating a cooperative framework through CSIRTs and the EU Cybersecurity Agency (ENISA).
Expanded Scope
Covers 18 critical sectors and an estimated 160,000+ entities across the EU — significantly broader than the original NIS Directive, including digital infrastructure, public administration, and space.
Management Accountability
Holds management bodies personally liable for cybersecurity compliance. Executives can face temporary bans from management positions for repeated violations involving gross negligence.
Incident Reporting
Mandates early warning to national CSIRT within 24 hours of becoming aware of a significant incident, full notification within 72 hours, and a final report within one month.
list_alt Key Requirements
- Risk management measures covering at least 10 domains
- Supply chain security and vulnerability management
- Incident reporting within 24/72-hour timelines
- Management body training and accountability
- Use of encryption and multi-factor authentication
- Business continuity and crisis management plans
- Cybersecurity risk assessment and policies
- Essential vs Important entity classification
Who Needs to Comply?
Medium-sized and large organizations (50+ employees or EUR 10M+ turnover) in 18 critical sectors across EU member states, classified as either essential or important entities. Also applies to certain smaller entities providing critical services.
Key Requirements
Cybersecurity Risk Management
Implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. Measures must cover at least 10 domains including incident handling, supply chain, and cryptography.
Incident Reporting Obligations
Report significant incidents to the national CSIRT or competent authority: early warning within 24 hours, incident notification within 72 hours, and a final report within one month including root cause analysis.
Supply Chain Security
Assess and address cybersecurity risks in supply chains and supplier relationships. Consider the vulnerabilities of each direct supplier and the overall quality of their security practices.
Management Body Obligations
Management bodies must approve cybersecurity measures, oversee implementation, and undergo regular cybersecurity training. They can be held personally liable for infringements.
Registration & Cooperation
Entities must register with relevant national authorities. Cooperate with CSIRTs and competent authorities during incidents and share relevant threat intelligence.
Implementation Roadmap
Scope & entity classification
Determine whether your organization falls within NIS2 by mapping your activities to the 18 covered sectors and applying the size thresholds that generally bring in medium and large entities. Classify yourself as an essential or important entity, since this drives supervision intensity and penalty ceilings. Confirm the transposition status in each member state where you operate, because obligations flow from national law implementing the directive rather than from NIS2 directly.
Gap analysis against Article 21 & reporting
Assess your current cybersecurity posture against the Article 21 risk-management measures, including risk analysis, incident handling, business continuity, supply-chain security, encryption, access control, and vulnerability management. Evaluate your incident-detection and reporting capability against the 24-hour early-warning, 72-hour notification, and one-month final-report timelines. Review management-body oversight and identify where accountability and training are missing.
Implement risk-management measures
Deploy the technical and organizational measures required by Article 21, using an all-hazards approach proportionate to your risk exposure. Establish incident-response runbooks aligned to the reporting timelines, harden the supply chain through supplier assessments and contractual controls, and formalize management-body approval and training. Where useful, map controls to ISO 27001 to reduce duplication and evidence effort.
Monitor, report & maintain
Operate continuous monitoring and rehearse the 24h/72h/1-month reporting workflow so notifications reach the CSIRT or competent authority on time. Keep risk assessments, supplier reviews, and business-continuity plans current, and re-brief the management body as threats and obligations evolve. Maintain audit-ready evidence, since essential entities face proactive supervision and both tiers can be inspected.
Compliance Checklist
checklist Scope & governance
checklist Article 21 risk-management measures
checklist Incident reporting
Penalties & Enforcement
Essential entities face fines up to EUR 10 million or 2% of global annual turnover. Important entities face fines up to EUR 7 million or 1.4% of global annual turnover. Management can be held personally liable, with potential temporary bans from holding management positions.
Frequently Asked Questions
Who must comply with NIS2?
expand_more
NIS2 covers medium and large organizations operating in 18 sectors, split into essential entities such as energy, transport, banking, health, and digital infrastructure, and important entities such as postal services, waste management, manufacturing, and digital providers. Size thresholds generally bring in entities with at least 50 staff or €10 million turnover, though some are in scope regardless of size. Whether you are essential or important affects supervision and penalty levels.
What are the Article 21 risk-management measures?
expand_more
Article 21 requires an all-hazards set of technical and organizational measures proportionate to risk. These include risk analysis and security policies, incident handling, business continuity and backup, supply-chain security, secure development and vulnerability handling, cryptography and encryption, access control, and cyber-hygiene and training. The goal is to manage risks to network and information systems across the whole organization and its suppliers.
What are the incident reporting timelines?
expand_more
Entities must submit an early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident. A fuller incident notification with an initial assessment is due within 72 hours. A final report must follow no later than one month after the notification, describing root cause, mitigation, and impact.
What is the management body's accountability and liability?
expand_more
NIS2 makes the management body directly responsible for approving and overseeing the cybersecurity risk-management measures. Members must follow training and are expected to ensure the organization meets its obligations. National transposition can attach personal liability to senior management for failures, making board-level engagement essential rather than optional.
How does NIS2 relate to NIS1 and DORA?
expand_more
NIS2 repeals and replaces NIS1, widening the sectors and entities in scope, strengthening the security and reporting requirements, and harmonizing supervision and penalties across the EU. DORA is a sector-specific regulation for financial entities and, as the more specific rule, generally takes precedence for those firms on matters it covers. Financial organizations should map where DORA applies and where NIS2 still governs.
What penalties can be imposed under NIS2?
expand_more
Penalties are tiered by entity type. Essential entities can face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4% of turnover. Authorities can also impose binding instructions, and in some cases restrict management responsibilities for essential entities.
How does NIS2 relate to ISO 27001?
expand_more
ISO 27001 is not mandatory under NIS2, but its information-security management system maps closely to the Article 21 measures. An existing certification provides much of the risk assessment, access control, continuity, and supplier-security evidence NIS2 expects. Organizations often use ISO 27001 as a backbone and then add the NIS2-specific reporting and governance obligations on top.
What is the transposition status of NIS2?
expand_more
The directive set a national transposition deadline of 17 October 2024, by which member states were to bring implementing laws into force. Because NIS2 is a directive, your concrete obligations come from national law, and timing and detail have varied between member states. Confirm the current status in each country where you operate to identify the exact rules that apply to you.
Official Documentation
NIS2 Directive (EU) 2022/2555
PDF • EUR-Lex • Full Directive Text
NIS2 Official Journal
External Link • eur-lex.europa.eu • Legislative Text
ENISA NIS Directive Resources
External Link • enisa.europa.eu • Implementation Guidance