RISI
EU flags outside the European Commission Berlaymont building in Brussels

EU Cybersecurity Regulations › NIS2

NIS2 — The EU Network and Information Security Directive 2

Directive (EU) 2022/2555 · in force since 16 January 2023 · transposition deadline 17 October 2024

Last reviewed:

Photo: Guillaume Périgois on Unsplash

What NIS2 is

The Network and Information Security Directive 2 (Directive (EU) 2022/2555, NIS2) is the European Union's cross-sector cybersecurity law. It was adopted on 14 December 2022, entered into force on 16 January 2023, and member states were required to transpose it into national law by 17 October 2024. NIS2 repeals and replaces the original NIS Directive (2016/1148) and significantly expands its scope, harmonises enforcement, and tightens incident-reporting and supply-chain obligations.

NIS2 sits at the centre of a broader EU cybersecurity framework alongside the CER Directive (2022/2557) for physical resilience of critical entities, the DORA Regulation (2022/2554) for the financial sector, the Cyber Resilience Act (2024/2847) for product security, and the EU Cybersecurity Act (2019/881) establishing ENISA. On 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of the Digital Cybersecurity Package, intended to simplify compliance for around 28,700 companies — including 6,200 micro and small enterprises — without changing the directive's substantive obligations.

Who is in scope

NIS2 applies to medium-sized and large enterprises operating in the sectors listed in Annexes I and II of the directive, plus a set of entity types that are always in scope regardless of size (electronic communications, trust services, TLD/DNS, entities designated as critical under the CER Directive, and any entity whose disruption would threaten public safety or critical societal functions).

Essential vs. important entities

Entities in Annex I sectors above the size threshold are classified as essential entities and face proactive, ex-ante supervision. Entities in Annex II sectors (or in Annex I but below the large-enterprise threshold) are classified as important entities and face reactive, ex-post supervision. The split drives the penalty ceiling and the intensity of regulator oversight.

Annex I — sectors of high criticality (essential)

  1. Energy — electricity, district heating & cooling, oil, gas, hydrogen
  2. Transport — air, rail, water, road
  3. Banking
  4. Financial market infrastructures
  5. Health, including pharmaceutical and critical medical device manufacture
  6. Drinking water
  7. Waste water
  8. Digital infrastructure — IXPs, DNS, TLD registries, cloud, data centres, CDNs, trust services, public electronic communications
  9. ICT service management — managed service providers, managed security service providers
  10. Public administration — central and regional
  11. Space

Annex II — other critical sectors (important)

  1. Postal and courier services
  2. Waste management
  3. Manufacture, production and distribution of chemicals
  4. Production, processing and distribution of food
  5. Manufacturing — medical devices, computer/electronic/optical products, electrical equipment, machinery, motor vehicles and trailers, other transport equipment
  6. Digital providers — online marketplaces, online search engines, social networking platforms
  7. Research organisations

The 10 Article 21 cybersecurity measures

Article 21(2) lists ten minimum categories of technical, operational and organisational measures every essential and important entity must implement. The list is not exhaustive — entities must take an all-hazards, risk-based approach — but these ten items anchor every national implementing law:

  1. policies on risk analysis and information system security
  2. incident handling
  3. business continuity, such as backup management and disaster recovery, and crisis management
  4. supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
  5. security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure
  6. policies and procedures to assess the effectiveness of cybersecurity risk-management measures
  7. basic cyber hygiene practices and cybersecurity training
  8. policies and procedures regarding the use of cryptography and, where appropriate, encryption
  9. human resources security, access control policies and asset management
  10. the use of multi-factor authentication or continuous authentication solutions, secured voice, video and text communications, and secured emergency communication systems within the entity, where appropriate

Verbatim from Article 21(2). Commission Implementing Regulation (EU) 2024/2690 (17 October 2024) translates these ten categories into detailed technical requirements for entities in the digital-infrastructure and ICT-service-management sectors; ENISA's Technical Implementation Guidance on Cybersecurity Risk-Management Measures (June 2025, 170 pages) maps them into 13 thematic areas with concrete evidence examples that other national regulators are increasingly treating as the de-facto baseline.

Incident-reporting timeline

Article 23 imposes a three-stage incident-notification regime triggered by any significant incident — one that has caused or is capable of causing severe operational disruption or financial loss, or material/non-material damage to others.

StageDeadlineWhat must be sent
Early warning≤ 24 hours from awarenessInitial flag to the CSIRT or competent authority indicating whether the incident is suspected to be caused by unlawful or malicious acts, and any cross-border impact.
Incident notification≤ 72 hours from awarenessUpdate with an initial assessment of severity, impact, and known indicators of compromise.
Intermediate reportOn requestStatus update if and when the CSIRT or competent authority asks for one.
Final report≤ 1 month from incident notificationDetailed description, root cause, mitigation, cross-border implications.

Trust service providers under eIDAS face a tighter 24-hour notification window (not 72 hours) for incidents affecting their trust services.

Penalties and enforcement

Article 34 sets the floor for administrative fines. National laws can — and several do — set higher ceilings.

Entity typeMaximum fine (higher of)Supervision style
Essential (Annex I, large)€10 000 000 or 2% of total worldwide annual turnoverProactive (ex-ante) — regular audits, on-site inspections, security scans
Important (Annex II, or smaller Annex I)€7 000 000 or 1.4% of total worldwide annual turnoverReactive (ex-post) — triggered by indication of non-compliance

Beyond fines, Articles 32 and 33 empower competent authorities to issue binding instructions, order entities to inform affected customers of significant cyber threats, designate a monitoring officer with full access, and — for essential entities — suspend a certification or authorisation and impose a temporary ban on managerial responsibility on natural persons exercising managerial functions.

Management-body accountability

Article 20 places direct responsibility on the management body. Boards and senior managers must approve the cybersecurity risk-management measures, oversee their implementation, and can be held personally liable for infringements. Members of the management body are also required to follow training on a regular basis to acquire sufficient knowledge to identify risks and assess cybersecurity risk-management practices. Comparable training must be offered to employees.

This is the most consequential cultural shift in NIS2: cybersecurity is reframed as a board-level fiduciary duty rather than a delegated IT function. Several member states (Belgium, Germany, Italy) have legislated the personal-liability principle explicitly, including the possibility of temporary bans on serving as a director after serious non-compliance by essential entities.

Implementation timeline

  • 14 December 2022 — Directive (EU) 2022/2555 adopted by the European Parliament and the Council.
  • 16 January 2023 — entry into force, twenty days after publication in the Official Journal (L 333, 27 December 2022).
  • 17 October 2024 — transposition deadline; member states' national laws must apply from 18 October 2024.
  • 18 October 2024 — NIS1 Directive 2016/1148 repealed.
  • 17 October 2024 — Commission Implementing Regulation (EU) 2024/2690 published, fixing technical and methodological requirements for the Article 21 measures applicable to digital-infrastructure and ICT-service-management entities.
  • 17 April 2025 — Commission opens infringement proceedings against 23 member states for failure to fully transpose on time.
  • 26 June 2025 — ENISA publishes its Technical Implementation Guidance on Cybersecurity Risk-Management Measures (170 pages) plus the NIS2 Obligations <> ECSF Role Profiles mapping.
  • 20 January 2026 — Commission proposes targeted amendments to NIS2 as part of the Digital Cybersecurity Package, aiming to simplify compliance and reduce administrative burden particularly on micro and small enterprises in scope.

Frequently asked questions

Short, sourced answers to the questions readers most often arrive with.

What is the NIS2 Directive?

NIS2 is Directive (EU) 2022/2555 — the European Union's horizontal cybersecurity law. It replaces the 2016 NIS1 Directive, expands coverage to 18 sectors and roughly 160,000 entities EU-wide, and sets common minimum requirements for risk management, incident reporting, supply-chain security, and management-body accountability.

When did NIS2 come into force?

NIS2 was adopted on 14 December 2022 and entered into force on 16 January 2023. EU member states had to transpose it into national law by 17 October 2024; national rules apply from 18 October 2024, when NIS1 was repealed.

Who has to comply with NIS2?

Medium and large enterprises operating in the sectors listed in Annexes I and II of the directive, plus a defined group of entities that are always in scope regardless of size — including providers of public electronic communications, trust services, TLD/DNS registries, and entities designated as critical under the CER Directive. National laws may extend scope further.

What is the difference between essential and important entities?

Essential entities (Annex I sectors above the large-enterprise threshold) face proactive, ex-ante supervision: regular audits, on-site inspections, and security scans. Important entities (Annex II, or smaller Annex I entities) face reactive, ex-post supervision triggered by indications of non-compliance. The split also drives the penalty ceiling: €10M / 2% turnover for essential, €7M / 1.4% for important.

What are the penalties for non-compliance with NIS2?

Article 34 sets EU-wide minimum maximums: at least €10,000,000 or 2% of global annual turnover (whichever is higher) for essential entities, and at least €7,000,000 or 1.4% of global annual turnover for important entities. National laws can set higher ceilings, and several do. Beyond fines, regulators can suspend certifications and temporarily ban natural persons from managerial positions.

What is the difference between NIS2 and NIS1?

NIS2 covers 18 sectors instead of NIS1's 7, replaces case-by-case national designations with an automatic size-cap rule, names ten minimum cybersecurity measures (Article 21), imposes a strict 24-hour / 72-hour / one-month reporting timeline, sets EU-wide minimum penalty ceilings, and introduces direct personal liability for management bodies. NIS1 left almost all of these decisions to each member state.

What is the 24-hour rule in NIS2?

Article 23 requires an early warning to the national CSIRT or competent authority within 24 hours of becoming aware of a significant incident, followed by a full incident notification within 72 hours and a final report within one month. Trust service providers face a tighter 24-hour final notification window under eIDAS rules.

How does NIS2 differ from DORA?

DORA (Regulation (EU) 2022/2554) is lex specialis for the financial sector and applies directly from 17 January 2025 without national transposition. Where DORA covers the same ground as NIS2 — risk management, incident reporting, third-party risk — financial entities meet their NIS2 obligations by complying with DORA. DORA also introduces an oversight regime for critical ICT third-party providers (hyperscalers, major SaaS) that has no NIS2 equivalent.

Does NIS2 apply to companies outside the EU?

Yes, where the company offers services in the EU. Non-EU providers of services covered by NIS2 — particularly DNS service providers, TLD name registries, cloud computing service providers, content delivery networks, managed service providers, and providers of online marketplaces, search engines and social networking platforms — must designate an EU representative under Article 26 and are subject to the jurisdiction of the member state where the representative is established.

What are the ten Article 21 cybersecurity measures?

Article 21(2) names ten minimum measure categories every essential and important entity must implement: (a) risk-analysis and information-system security policies, (b) incident handling, (c) business continuity and crisis management, (d) supply-chain security, (e) secure acquisition, development and maintenance including vulnerability handling, (f) policies to assess the effectiveness of risk-management measures, (g) basic cyber hygiene and training, (h) cryptography and encryption policies, (i) human-resources security, access control and asset management, and (j) multi-factor or continuous authentication and secured communications.

Authoritative sources