- Legal basis
- Directive (EU) 2022/2555, made binding through the transposing law of each Member State
- Applicable since
- 18 October 2024
- Who is covered?
- Essential and important entities in critical sectors
- Fines
- At least EUR 10 million or 2 % of total worldwide annual turnover
- Updated
- June 2026
- Editorial team
- Compliance Compass
What is NIS2?
NIS2 (short for Network and Information Security 2) is the revised EU cybersecurity directive. It replaces the original NIS Directive of 2016 and widens the circle of organisations covered considerably. The aim is a consistently high level of cybersecurity across the whole European Union.
A directive does not apply of itself. What binds you is your National transposition act. The directive itself has applied since 18 October 2024 and Member States had to transpose it by 17 October 2024. From that point cybersecurity measures stopped being a voluntary option for the organisations covered and became a legal duty. Unlike an EU regulation, a directive does not reach organisations directly – only the national transposing act makes the requirements binding on them.
Who does NIS2 apply to?
NIS2 distinguishes between essential entities (for example energy, health, banking, transport, digital infrastructure) and important entities (for example post, waste management, chemicals, food, manufacturing, digital providers). As a rule of thumb, an organisation is covered from 50 employees or EUR 10 million annual turnover in one of the regulated sectors – in some areas regardless of size. Entities in scope have to register with the authority designated in their country, listed under National cybersecurity authorities and the deadline for doing so is fixed in national law rather than by the directive. In several Member States the first deadline has already passed, and an expired deadline does not remove the obligation.
What duties does NIS2 bring?
- Risk management: systematically identifying, assessing and treating cyber risks.
- Technical measures: multi-factor authentication, backups, encryption and access controls, among others.
- Reporting obligations: an early warning within 24 hours, a notification within 72 hours and a final report within one month.
- Governance: the management body carries personal responsibility and has to approve and oversee the measures.
- Supply chain security: risks arising from service providers and suppliers have to be taken into account as well.
The ten minimum measures under Article 21 NIS2
Article 21 of the directive sets out a fixed catalogue. Every entity in scope has to cover all ten points demonstrably – an omission is not an oversight but a breach. The table below sums up what sits behind the often unwieldy terms.
| Measure | Short description |
|---|---|
| Risk analysis & security policies | Written policies that identify and assess cyber risks systematically. |
| Incident handling | Defined processes for detecting, containing and remedying incidents. |
| Business continuity & crisis management | Backup management, disaster recovery and keeping operations running. |
| Supply chain security | Assessing the security of service providers and direct suppliers. |
| Security in acquisition & development | Secure acquisition, development and maintenance of IT systems, including vulnerability management. |
| Effectiveness assessment | Policies for checking whether the risk management measures actually work. |
| Cyber hygiene & training | Basic security practice and regular training for staff. |
| Cryptography & encryption | Policies on the use of encryption wherever it makes sense. |
| Access control & asset management | Human resources security, access policies and an inventory of the assets worth protecting. |
| MFA & secured communications | Multi-factor authentication plus secured voice, video and emergency communications. |
What fines are possible?
For breaches, Article 34 sets a minimum ceiling for essential entities of EUR 10 million or 2 % of total worldwide annual turnover whichever is higher, and for important entities of EUR 7 million or 1.4 %. Member States may set higher amounts. On top of that, the management body can be held personally responsible.
What you actually have to do
Theory does not help much here. The following steps are the order in which you actually work through NIS2 – from the question of whether it applies to you at all, to the point where you can put your measures in front of an inspector in black and white:
- Clarify whether you are in scope. Check by sector, headcount and turnover whether you count as an essential or an important entity.
- Register with your national authority. Find the portal and the deadline that apply in your Member State, and catch up on registration without delay if that date has already passed.
- Record assets and risks. Inventory your IT systems and assess the risks that weigh on them.
- Implement the Article 21 catalogue. Close the ten minimum measures from the table above – and document every single one.
- Set up the reporting chain. Decide today who sends the 24-hour early warning to your national authority in an emergency.
Our detailed NIS2 guide shows how to do this step by step, including a 30-day start plan.
An everyday example: A mid-sized machinery manufacturer with 120 employees counts as an important entity. If ransomware encrypts its production control system, the clock starts: an early warning has to reach the national authority within 24 hours, a more concrete notification with a first assessment follows after 72 hours, and the final report is due one month later at the latest – if management neglects risk management or reporting, it is personally liable and substantial fines are possible. Preparation beats damage control.
Further reading: Directive (EU) 2022/2555 in full on EUR-Lex
Frequently asked questions
What is NIS2 in simple terms?
NIS2 is the revised EU cybersecurity directive, Directive (EU) 2022/2555. It entered into force on 16 January 2023 and has applied since 18 October 2024, and each Member State makes it binding through its own transposing law. It obliges thousands of organisations in critical sectors to run risk management, to report significant incidents to their national authority and to anchor responsibility for this personally at management level. The aim is a consistently high level of cybersecurity across the whole EU.
Who does NIS2 apply to?
NIS2 covers essential and important entities in sectors such as energy, health, transport, banking, digital infrastructure, waste management, food and manufacturing. As a rule of thumb it applies to organisations with 50 or more employees or an annual turnover of at least EUR 10 million in a regulated sector, and in some areas regardless of size. Registration is handled nationally, so the body you register with and the deadline that binds you depend on the Member State in which you are established.
Which deadlines apply after a security incident?
For a significant incident NIS2 sets a three-stage reporting chain to the national authority, counted from the moment you become aware of it: an early warning within 24 hours, a more concrete notification with a first assessment within 72 hours, and a final report after one month at the latest. Article 34 sets minimum ceilings for fines: at least EUR 10 million or 2 % of total worldwide annual turnover for essential entities, and Member States may go higher.