NIS2 — The EU Cybersecurity Directive
Last verified2026-10 — national transposition and the proposed 2026 amendments are moving targets; check the law of the member state you care about.
What is this?NIS2 (Directive (EU) 2022/2555) is the EU law that sets minimum cybersecurity obligations for organisations providing essential services: energy, transport, health, banking, water, digital infrastructure, cloud, managed service providers, manufacturing and more. It replaced the original NIS Directive (2016/1148) with a much wider scope, specific security measures, strict incident-reporting deadlines, fines, and personal accountability for management.
Why It Matters
tens of thousands of organisations across the EU fall in scope, up from a few thousand under NIS1, including many mid-sized companies and IT service providers that never had cyber regulation before.
boards must approve and oversee cybersecurity measures and can be held personally responsible. That turns security from an IT topic into a governance topic.
in-scope entities must manage supplier security, so even companies outside scope get NIS2 requirements through contracts.
for any EU role, or any role supplying EU customers, expect "how would you prepare a company for NIS2?" or "what are the NIS2 reporting deadlines?"
Timeline and Current Status
-
Adoptedother14 Dec 2022
- Directive (EU) 2022/2555 published; in force 16 January 2023
-
Transposition deadlineother17 Oct 2024
- Member states had to turn it into national law; applies from 18 October 2024
-
Implementing Regulation (EU) 2024/2690otherOct 2024
- Detailed technical measures and incident thresholds for digital-infrastructure and ICT providers
-
Entity listsother17 Apr 2025
- Member states establish the lists of essential and important entities
-
InfringementsattackNov 2024 – Jul 2026
- Commission opened proceedings against late member states; in July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice
-
Proposed amendmentsdefendJan 2026
- Commission proposed targeted changes alongside a revised Cybersecurity Act; adoption expected late 2026 or 2027
Because NIS2 is a directive, it applies through each member state's national law, which can add requirements and sets its own authority, registration process and details. Always check the national transposition (for example Belgium's NIS2 law, Germany's NIS2 implementation act, Italy's Legislative Decree 138/2024).
The January 2026 proposal (not yet law as of this writing) would, among other things: let a Commission implementing act harmonise the Article 21 technical requirements so member states can't add their own; allow compliance to be shown through an EU cybersecurity certification scheme; add structured ransomware reporting (including whether a ransom was demanded and paid); require national post-quantum migration plans (critical uses by 2030); add a "small mid-cap" category; and adjust scope (adding EU digital identity and business wallet providers and submarine cable operators, removing micro and small DNS providers).
Who Is in Scope
The size-cap rule
By default NIS2 applies to medium and large organisations (roughly 50+ employees, or more than €10 million annual turnover and balance sheet) that operate in a listed sector and provide services in the EU. Some entities are in scope regardless of size: providers of public electronic communications networks or services, qualified trust service providers, top-level domain registries, DNS service providers, public administration bodies, and any entity a member state designates as the sole provider of a critical service.
Sectors
- Energy (electricity, district heating and cooling, oil, gas, hydrogen)
- Transport (air, rail, water, road)
- Banking and financial market infrastructure
- Health
- Drinking water and waste water
- Digital infrastructure (internet exchange points, DNS, TLD registries, cloud computing, data centres, content delivery networks, trust services, public electronic communications)
- ICT service management, business-to-business (managed service providers and managed security service providers)
- Public administration
- Space
- Postal and courier services
- Waste management
- Manufacture, production and distribution of chemicals
- Production, processing and distribution of food
- Manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment)
- Digital providers (online marketplaces, search engines, social networking platforms)
- Research organisations
Essential versus important entities
| Essential entities | Important entities | |
|---|---|---|
| Typically | Large entities in Annex I sectors, plus certain entities regardless of size | Other in-scope entities (medium Annex I, medium and large Annex II) |
| Supervision | Proactive (ex ante): audits, inspections and checks without a prior incident | Reactive (ex post): after evidence or an incident suggests non-compliance |
| Maximum fine | €10 million or 2% of worldwide annual turnover, whichever is higher | €7 million or 1.4% of worldwide annual turnover, whichever is higher |
The security obligations are the same for both; the difference is how closely they are supervised and how large the fines can be.
Financial entities covered by DORA (the Digital Operational Resilience Act, applying since 17 January 2025) follow DORA's more specific rules for ICT risk and incident reporting instead of the overlapping NIS2 provisions.
🎯On the job. Scoping errors cut both ways: a mid-sized managed service provider often doesn't realise it's in scope (ICT service management is Annex I), while large groups forget they must register in every member state where they provide services. Write down the analysis — sector, size, entity type, countries — because the supervisor may ask how you concluded it.
What NIS2 Requires
Article 20 — governance
- The management body must approve the cybersecurity risk-management measures and oversee their implementation.
- Management can be held liable for infringements; for essential entities, national law can allow a temporary ban on a person exercising managerial functions.
- Members of management bodies must follow training, and entities are encouraged to train all employees regularly.
Article 21 — cybersecurity risk-management measures
An all-hazards approach (protecting systems and their physical environment from any incident, not only attacks), proportionate to the entity's size and risk, including at least:
- Policies on risk analysis and information-system security.
- Incident handling.
- Business continuity: backup management, disaster recovery and crisis management.
- Supply-chain security, including the security of relationships with direct suppliers and service providers.
- Security in network and information system acquisition, development and maintenance, including vulnerability handling and disclosure.
- Policies and procedures to assess the effectiveness of these measures.
- Basic cyber hygiene practices and cybersecurity training.
- Policies on cryptography and, where appropriate, encryption.
- Human resources security, access control policies and asset management.
- Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communications where appropriate.
For digital-infrastructure and ICT providers, Implementing Regulation (EU) 2024/2690 spells these out in detail. For everyone else, frameworks such as ISO/IEC 27001 and NIST CSF are the usual way to implement them; see compliance frameworks.
Article 23 — incident reporting
A significant incident is one that has caused or can cause severe operational disruption or financial loss to the entity, or considerable damage to other people or organisations.
-
Become aware of a significant incidentattackT = 0
- The clock starts at awareness, not at the start of the attack
-
Early warning to CSIRT / authoritydefendwithin 24 h
- Is it suspected to be malicious? Could it have cross-border impact?
-
Incident notificationdefendwithin 72 h
- Update the early warning: initial assessment, severity, impact, indicators of compromise
-
Intermediate reportdefendon request
- Status updates when the authority asks
-
Final reportdefendwithin 1 month of the notification
- Detailed description, severity and impact, root cause / threat type, mitigations, cross-border impact
- If still ongoing: a progress report, then a final report within a month of handling it
Entities must also inform recipients of their services, without undue delay, about significant incidents likely to affect them and about measures those recipients can take. Personal-data breaches still need a separate GDPR notification to the data-protection authority (72 hours).
Other obligations
with the national authority (name, sector, contacts, IP ranges, member states served).
audits, security scans, information requests, binding instructions.
each member state designates a CSIRT as coordinator; ENISA (the EU cybersecurity agency) runs the European vulnerability database.
voluntary cybersecurity information-sharing arrangements between entities are encouraged.
In practiceWhat a 24-hour early warning contains. It's deliberately short — you don't need the root cause yet:
NIS2 early warning — [Entity name, registration ID] Submitted: 2026-10-04 09:40 CET
Incident detected: 2026-10-03 11:15 CET (awareness of significance: 2026-10-03 16:00 CET)
Services affected: online customer portal, payment processing (partially unavailable)
Suspected unlawful or malicious act: YES — ransomware note found on file servers
Possible cross-border impact: YES — customers in DE and AT use the affected portal
Contact: CISO, +49 …, incident@entity.eu Next update: incident notification by 2026-10-06 16:00 CET🎯On the job. Pre-define "significant" with concrete thresholds (for example: a critical service down for more than 4 hours, or confirmed data exfiltration, or more than N customers affected), so the person on call can start the 24-hour clock without a meeting.
Security Angle — Making NIS2 Real
A practical programme for a newly in-scope company:
confirm sector, size, essential or important status, every member state you operate in, and register.
board approval of the security programme, named accountable executive, board training on record.
map current controls to Article 21 (ISO 27001 Annex A is a good base) and prioritise gaps.
define "significant incident" thresholds in advance, pre-fill reporting templates, name who decides and who submits, and rehearse the 24-hour early warning in a tabletop. The 24-hour clock is the part companies most often fail.
inventory critical suppliers, add security clauses and notification duties to contracts, assess the highest-risk ones.
keep records that measures are implemented and effective; supervisors will ask.
Common pitfalls: treating NIS2 as an IT project without board involvement, discovering during an incident that nobody knows which authority to notify, and forgetting that managed service providers are themselves in scope.
Interview Questions
NIS2 is the EU directive setting cybersecurity obligations for essential and important services, applying since October 2024 through national laws. Compared with NIS1 it covers far more sectors and medium-sized companies, uses a size-cap rule instead of member states picking operators, lists ten minimum security measures, sets fixed incident-reporting deadlines, and makes management personally accountable. It also brings managed service providers and much of manufacturing into scope for the first time.
For a significant incident: an early warning within 24 hours of becoming aware, a fuller incident notification within 72 hours with an initial assessment and indicators of compromise, and a final report within one month covering root cause and mitigations. The clock starts at awareness, so companies need significant-incident thresholds and a named decision-maker defined in advance, or the 24 hours is gone before anyone agrees it's reportable. GDPR breach notification runs separately in parallel.
Both have the same security and reporting obligations. Essential entities, typically large organisations in high-criticality sectors, are supervised proactively — authorities can audit them without waiting for an incident — and face fines up to 10 million euros or 2% of worldwide turnover. Important entities are supervised reactively, after evidence of a problem, with fines up to 7 million or 1.4%.
Under Article 20 the management body must approve the cybersecurity risk-management measures, oversee their implementation and take training, and its members can be held liable for failures. For essential entities, national law can even allow temporarily banning someone from management roles. That's deliberate: it moves cybersecurity from an IT budget line to a board responsibility.
Risk analysis and security policies; incident handling; business continuity with backups and crisis management; supply-chain security; security in acquisition, development and maintenance including vulnerability handling; assessing the effectiveness of measures; cyber hygiene and training; cryptography and encryption; HR security, access control and asset management; and MFA plus secured communications. It's all-hazards and proportionate, so ISO 27001 maps onto it well.
Confirm it's in scope — manufacturing is an Annex II sector, so a medium-sized firm is usually an important entity — and register in every relevant member state. Then get board approval and training on record, do a gap analysis against Article 21 using ISO 27001 as the backbone, and above all build incident-reporting readiness with predefined thresholds and a rehearsed 24-hour early warning. For a manufacturer I'd also cover the plant floor, using IEC 62443 to segment and secure the OT network, and push security requirements into supplier contracts.