NIS2 vs NIS1 — what changed
| Dimension | NIS1 (Directive 2016/1148) | NIS2 (Directive 2022/2555) |
|---|---|---|
| Sectors | 7 sectors of Operators of Essential Services + a handful of Digital Service Providers | 18 sectors across Annex I (11) and Annex II (7), including public administration and space |
| Identification of entities | Member-state-by-member-state designation of OESs — wildly inconsistent | Size-cap rule (medium-sized and large) → automatic in-scope, no per-entity designation needed |
| Risk-management baseline | High-level: "appropriate technical and organisational measures" | Article 21(2) names 10 minimum categories incl. supply chain, MFA, encryption |
| Reporting timeline | "Without undue delay" — interpreted variably (anything from days to weeks) | 24h early warning · 72h notification · 1 month final report |
| Penalties | Set entirely by member states — "effective, proportionate, dissuasive" | EU-wide floor: €10M/2% (essential) · €7M/1.4% (important) |
| Governance | Not addressed | Management-body approval, oversight, personal liability, mandatory training (Article 20) |
| Supply-chain security | Not addressed | Required as one of the 10 measures, plus coordinated EU-level supply-chain risk assessments (Article 22) |
| Enforcement | Largely reactive | Proactive supervision for essential entities (audits, scans, monitoring officer) |
NIS2 vs DORA — the financial-sector overlap
DORA (Digital Operational Resilience Act, Regulation (EU) 2022/2554) is lex specialis for the financial sector. Where DORA covers the same ground as NIS2 — risk management, incident reporting, third-party risk — financial entities discharge their NIS2 obligations by complying with DORA, not in addition to it. Practical differences:
- DORA applies as a regulation (directly binding, uniform across the EU). NIS2 applies as a directive (transposed differently in each member state).
- DORA's reporting timeline mirrors NIS2's (24h, 72h, 1mo) but with sector-specific templates issued by the European Supervisory Authorities (EBA, EIOPA, ESMA).
- DORA introduces an oversight regime for critical ICT third-party providers — hyperscalers, major SaaS — that has no NIS2 equivalent.
- NIS2 still applies to financial entities for issues outside DORA's scope (e.g. physical incidents not affecting ICT systems).
NIS2 vs CER — cyber and physical resilience
The CER Directive (Critical Entities Resilience, Directive (EU) 2022/2557) was adopted on the same day as NIS2 and has the same transposition deadline. It is the physical-security counterpart: where NIS2 covers cybersecurity, CER covers everything else (natural hazards, terrorism, sabotage, insider threats, public-health emergencies).
- An entity designated as a critical entity under CER is automatically an essential entity under NIS2, regardless of size.
- CER sectors overlap heavily with NIS2 Annex I: energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, public administration, space, food.
- Member states must designate critical entities by 17 July 2026, applying common criteria set out in CER. The list partially drives NIS2 supervisory priorities.