verified_user
Standardful
Homechevron_rightStandardschevron_rightNIS2 Directive
ActiveInternational Standardupdate Standard Updated: Oct 2024fact_check Fact checked: Jun 28, 2026

NIS2 Directive

Directive (EU) 2022/2555 — Measures for a High Common Level of Cybersecurity Across the Union

apartmentPublishing Organization:European Union

Standard Introduction

The NIS2 Directive (Network and Information Security Directive 2) is an EU-wide cybersecurity legislation that establishes a high common level of cybersecurity across all member states. Adopted in November 2022 with a transposition deadline of October 2024, it significantly expands the scope of the original NIS Directive to cover 18 critical sectors and an estimated 160,000+ entities.

NIS2 introduces stricter requirements including management accountability, harmonized incident reporting timelines, and substantial penalties for non-compliance. It represents the EU’s most comprehensive cybersecurity legislation, mandating baseline security measures and creating a cooperative framework through CSIRTs and the EU Cybersecurity Agency (ENISA).

expand

Expanded Scope

Covers 18 critical sectors and an estimated 160,000+ entities across the EU — significantly broader than the original NIS Directive, including digital infrastructure, public administration, and space.

person_pin

Management Accountability

Holds management bodies personally liable for cybersecurity compliance. Executives can face temporary bans from management positions for repeated violations involving gross negligence.

report

Incident Reporting

Mandates early warning to national CSIRT within 24 hours of becoming aware of a significant incident, full notification within 72 hours, and a final report within one month.

list_alt Key Requirements

  • Risk management measures covering at least 10 domains
  • Supply chain security and vulnerability management
  • Incident reporting within 24/72-hour timelines
  • Management body training and accountability
  • Use of encryption and multi-factor authentication
  • Business continuity and crisis management plans
  • Cybersecurity risk assessment and policies
  • Essential vs Important entity classification

Who Needs to Comply?

groups

Medium-sized and large organizations (50+ employees or EUR 10M+ turnover) in 18 critical sectors across EU member states, classified as either essential or important entities. Also applies to certain smaller entities providing critical services.

Key Requirements

1

Cybersecurity Risk Management

Implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risks. Measures must cover at least 10 domains including incident handling, supply chain, and cryptography.

2

Incident Reporting Obligations

Report significant incidents to the national CSIRT or competent authority: early warning within 24 hours, incident notification within 72 hours, and a final report within one month including root cause analysis.

3

Supply Chain Security

Assess and address cybersecurity risks in supply chains and supplier relationships. Consider the vulnerabilities of each direct supplier and the overall quality of their security practices.

4

Management Body Obligations

Management bodies must approve cybersecurity measures, oversee implementation, and undergo regular cybersecurity training. They can be held personally liable for infringements.

5

Registration & Cooperation

Entities must register with relevant national authorities. Cooperate with CSIRTs and competent authorities during incidents and share relevant threat intelligence.

Implementation Roadmap

1
Phase 1schedule Duration: 3-5 weeks

Scope & entity classification

Determine whether your organization falls within NIS2 by mapping your activities to the 18 covered sectors and applying the size thresholds that generally bring in medium and large entities. Classify yourself as an essential or important entity, since this drives supervision intensity and penalty ceilings. Confirm the transposition status in each member state where you operate, because obligations flow from national law implementing the directive rather than from NIS2 directly.

2
Phase 2schedule Duration: 4-6 weeks

Gap analysis against Article 21 & reporting

Assess your current cybersecurity posture against the Article 21 risk-management measures, including risk analysis, incident handling, business continuity, supply-chain security, encryption, access control, and vulnerability management. Evaluate your incident-detection and reporting capability against the 24-hour early-warning, 72-hour notification, and one-month final-report timelines. Review management-body oversight and identify where accountability and training are missing.

3
Phase 3schedule Duration: 3-6 months

Implement risk-management measures

Deploy the technical and organizational measures required by Article 21, using an all-hazards approach proportionate to your risk exposure. Establish incident-response runbooks aligned to the reporting timelines, harden the supply chain through supplier assessments and contractual controls, and formalize management-body approval and training. Where useful, map controls to ISO 27001 to reduce duplication and evidence effort.

4
Phase 4schedule Duration: Ongoing

Monitor, report & maintain

Operate continuous monitoring and rehearse the 24h/72h/1-month reporting workflow so notifications reach the CSIRT or competent authority on time. Keep risk assessments, supplier reviews, and business-continuity plans current, and re-brief the management body as threats and obligations evolve. Maintain audit-ready evidence, since essential entities face proactive supervision and both tiers can be inspected.

Compliance Checklist

0 / 13

checklist Scope & governance

checklist Article 21 risk-management measures

checklist Incident reporting

Penalties & Enforcement

warning

Essential entities face fines up to EUR 10 million or 2% of global annual turnover. Important entities face fines up to EUR 7 million or 1.4% of global annual turnover. Management can be held personally liable, with potential temporary bans from holding management positions.

Frequently Asked Questions

Who must comply with NIS2?

expand_more

NIS2 covers medium and large organizations operating in 18 sectors, split into essential entities such as energy, transport, banking, health, and digital infrastructure, and important entities such as postal services, waste management, manufacturing, and digital providers. Size thresholds generally bring in entities with at least 50 staff or €10 million turnover, though some are in scope regardless of size. Whether you are essential or important affects supervision and penalty levels.

What are the Article 21 risk-management measures?

expand_more

Article 21 requires an all-hazards set of technical and organizational measures proportionate to risk. These include risk analysis and security policies, incident handling, business continuity and backup, supply-chain security, secure development and vulnerability handling, cryptography and encryption, access control, and cyber-hygiene and training. The goal is to manage risks to network and information systems across the whole organization and its suppliers.

What are the incident reporting timelines?

expand_more

Entities must submit an early warning to the CSIRT or competent authority within 24 hours of becoming aware of a significant incident. A fuller incident notification with an initial assessment is due within 72 hours. A final report must follow no later than one month after the notification, describing root cause, mitigation, and impact.

What is the management body's accountability and liability?

expand_more

NIS2 makes the management body directly responsible for approving and overseeing the cybersecurity risk-management measures. Members must follow training and are expected to ensure the organization meets its obligations. National transposition can attach personal liability to senior management for failures, making board-level engagement essential rather than optional.

How does NIS2 relate to NIS1 and DORA?

expand_more

NIS2 repeals and replaces NIS1, widening the sectors and entities in scope, strengthening the security and reporting requirements, and harmonizing supervision and penalties across the EU. DORA is a sector-specific regulation for financial entities and, as the more specific rule, generally takes precedence for those firms on matters it covers. Financial organizations should map where DORA applies and where NIS2 still governs.

What penalties can be imposed under NIS2?

expand_more

Penalties are tiered by entity type. Essential entities can face fines of up to €10 million or 2% of total worldwide annual turnover, whichever is higher. Important entities face up to €7 million or 1.4% of turnover. Authorities can also impose binding instructions, and in some cases restrict management responsibilities for essential entities.

How does NIS2 relate to ISO 27001?

expand_more

ISO 27001 is not mandatory under NIS2, but its information-security management system maps closely to the Article 21 measures. An existing certification provides much of the risk assessment, access control, continuity, and supplier-security evidence NIS2 expects. Organizations often use ISO 27001 as a backbone and then add the NIS2-specific reporting and governance obligations on top.

What is the transposition status of NIS2?

expand_more

The directive set a national transposition deadline of 17 October 2024, by which member states were to bring implementing laws into force. Because NIS2 is a directive, your concrete obligations come from national law, and timing and detail have varied between member states. Confirm the current status in each country where you operate to identify the exact rules that apply to you.

Official Documentation

View All

Implementation Timeline

gavel
Jul 2016
Original NIS Directive (NIS1) adopted
drafts
Dec 2020
European Commission proposes NIS2
how_to_vote
Nov 2022
NIS2 Directive adopted by Parliament and Council
event
Jan 2023
NIS2 enters into force
check_circle
Oct 2024
Member State transposition deadline
warning
May 2025
Commission sends reasoned opinion to 19 non-compliant states

Related Categories