Knowledge & orientation

NIS2 – Knowledge & orientation
for your organisation

The NIS2 Directive has applied since 18 October 2024. Member States transpose it into national law, which turns cybersecurity measures and reporting obligations into a binding legal requirement for thousands of organisations across the EU – no longer an option.

Our FAQs are a neutral knowledge base to smooth your path through the regulatory requirements. We have translated the complex requirements of the EU directive into practical answers, so that you can concentrate on what matters: the resilience of your organisation.

Applies since 18 October 2024
27 FAQs + glossary
Transposition deadline 17 October 2024 – national laws differ
Last updated: 9 June 2026
Editorial team: Philipp Minten, co-founder – organisation & compliance
What this guide covers
6 chapters — from the scope check to the 30-day action plan
01
Scope & sectors
Check whether your organisation counts as an essential or an important entity.
02
Core duties in plain language
Governance, risk management and the staged reporting obligations, explained clearly.
03
Pragmatic implementation
Concrete technical measures such as MFA, backup and supply chain security.
04
National transposition & SMEs
Registration runs through national portals – form and deadline differ from one Member State to the next.
05
Governance & liability
Why NIS2 becomes a board matter and which training duties apply.
06
30-day start plan
From the first stocktake to securing the supply chain.

Scope & applicability

Check whether and how NIS2 applies to your organisation.

NIS2 (EU Directive 2022/2555) is the revised European framework for cybersecurity in critical sectors. It replaces the NIS Directive of 2016 and significantly widens both the range of organisations covered and the substance of the requirements. Across the EU, the NIS2 Directive came into force on 16 January 2023 and had to be transposed into national law by 17 October 2024 – it covers 18 sectors in every Member State.

The directive places two core duties on the entities it covers: first, concrete risk management measures under Article 21 (among them incident handling, supply chain security, MFA and business continuity) and second, staged reporting obligations under Article 23 – an early warning within 24 hours, a full notification within 72 hours and a final report after one month.

What is new compared with NIS1: responsibility sits explicitly with management – managing directors and boards can be held personally liable for breaches. Article 34 sets a minimum fine ceiling for essential entities of at least EUR 10 million or 2 % of worldwide annual turnover, and Member States may set higher amounts.

Medium-sized and large organisations are typically covered when they operate in one of the 18 NIS2 sectors. An organisation counts as medium-sized if it has at least 50 staff or at least EUR 10 million in annual turnover. It counts as large if it has at least 250 staff, or at least EUR 50 million in turnover with a balance sheet total above EUR 43 million.

In addition, some entities fall under NIS2 regardless of their size – qualified trust service providers, TLD name registries, DNS resolver operators and providers of public communications networks.

For group structures: subsidiaries are usually assessed in their own right. A sound classification requires (1) a sector match, (2) size and group logic, (3) national special rules. The European Commission maintains an overview of national transposition that shows which country has transposed the directive and where the authority responsible for you is named.

NIS2 covers 18 sectors in total, across two annexes with different supervisory regimes.

Annex I (11 sectors, high criticality): Energy (electricity, district heating and cooling, oil, gas, hydrogen), transport (air, rail, water, road), banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure (for example IXPs, DNS, TLD registries, cloud, data centres, CDNs, trust services, telecommunications), ICT service management B2B (in particular MSPs and MSSPs), public administration and space.

Annex II (7 sectors, other critical sectors): Postal and courier services, waste management, chemicals, food, manufacturing (among others medical devices, computers and electronics, machinery, motor vehicles), digital providers (online marketplaces, search engines, social networks) and research organisations.

Annex I entities are subject to stricter supervision and higher fine ceilings. For certain digital infrastructure providers NIS2 applies regardless of the size of the organisation. Sector membership alone is not enough – the size thresholds and any special rules always have to be checked separately.

NIS2 divides the entities it covers into two categories that differ in their fine ceilings and in the intensity of supervision.

Essential entities are usually large organisations with 250 staff or more (or from EUR 50 million annual turnover and above EUR 43 million balance sheet total) in Annex I sectors, plus certain entities regardless of size – qualified trust service providers, TLD name registries and DNS resolver operators. They are subject to proactive supervision: the competent authority can demand inspections and evidence at any time.

Important entities are typically medium-sized organisations (50–249 staff or EUR 10–50 million turnover) in Annex I sectors, as well as large organisations in Annex II sectors. They are subject to ex post supervision – the competent authority normally acts only on concrete indications of a breach.

Fine ceilings under Article 34: essential entities at least EUR 10 million or 2 % of worldwide annual turnover; important entities at least EUR 7 million or 1.4 %. The higher amount applies, and Member States may set higher ceilings.

For organisations with roughly 50 to 500 staff the first question is: does our activity or industry put us in a NIS2 sector, and do we meet the size logic? The critical thresholds: medium-sized organisations from 50 staff or from EUR 10 million turnover; large organisations from 250 staff or from EUR 50 million turnover.

A pragmatic approach: (1) match your activity and the services you offer against the NIS2 sectors, (2) check the size and, where relevant, the group logic – subsidiaries usually have to be assessed in their own right, (3) clarify whether the organisation could be caught as a critical digital or ICT service provider or as part of a critical value chain, (4) document the result internally (date, assumptions, sources).

Many national authorities publish a free self-check, and the European Commission maintains an overview of national transposition that gives a first orientation but does not replace the legally binding self-classification. Recommendation: document the result of the check in writing and review it once a year. Organisations that have missed a national registration deadline should register without delay.

Duties & measures

The concrete requirements of Article 21 NIS2, explained clearly.

The core consists of three inseparable areas:

  • (1) Governance and accountability: Management approves the measures and oversees them
  • (2) Risk management measures (Article 21): Concrete technical and organisational measures
  • (3) Reporting of significant incidents (Article 23): Staged reporting obligations

Without governance there are no priorities, without measures there is no resilience, and without reporting there is no timely handling of incidents.

Article 21 NIS2 defines ten minimum areas for risk management measures, to be implemented in proportion to the risk and to the size of the organisation:

  • Risk analysis and security policies (written, approved by management)
  • Incident handling (detection, classification, response, documentation)
  • Business continuity and disaster recovery (including tested backups)
  • Supply chain security (supplier risk assessment and minimum requirements)
  • Secure development and operation including vulnerability handling (patch management with SLAs)
  • Measuring the effectiveness of the measures in place
  • Basic cyber hygiene and staff training
  • Cryptography and encryption where appropriate
  • Asset and access management together with HR security
  • MFA and secure internal communications

The key concept is proportionality: the depth required depends on the risk, the size of the organisation and the possible impact of an outage. The starting point is always a documented risk analysis – it determines which areas have to be tackled at once and where a step-by-step build-up is defensible. Organisations typically start with three priorities: a documented risk analysis, a tested incident process and a working backup restore. These areas form the base and are most often decisive in real security incidents.

NIS2 does not make ISO 27001 certification mandatory; it requires appropriate and proportionate security measures. Organisations can take their bearings from recognised standards such as ISO 27001, the German IT-Grundschutz standard, SOC 2 or NIST CSF – there is no certification duty.

In practice a certification can still be useful: it structures the implementation and produces auditable evidence and makes communication with customers, suppliers and authorities easier.

What matters is the real effectiveness of the measures and working governance – not the certificate. Organisations already certified to ISO 27001 have a good starting position but have to check whether NIS2-specific requirements – in particular reporting deadlines and supply chain security – are fully covered. Anyone not yet certified should start pragmatically and plan certification as a medium-term goal. A documented justification for the choice considerably improves auditability.

NIS2 requires appropriate, proportionate measures. That means risk, size of the organisation, likelihood of occurrence and potential damage all influence how deeply and how broadly the measures are implemented.

In practice proportionality is a logic of documentation and decision-making: why do we prioritise X over Y, which risks do we accept temporarily, which have to be mitigated at once.

An example: an organisation with 60 staff and a manageable IT estate does not have to implement the same depth of measures as a group operating critical infrastructure – but it does have to address the same areas in principle. What matters is that every prioritisation rests on a documented risk assessment and can be justified. In an audit the competent authority does not check whether every conceivable measure has been implemented, but whether the decisions taken are proportionate to risk, documented and effective. A clean justification of proportionality is therefore itself a central piece of audit evidence.

Incident management & reporting obligations

Everything on significant incidents, reporting deadlines and report structure.

Under NIS2 an incident counts as significant if it causes or is capable of causing severe operational disruption or considerable financial loss, or if it causes considerable harm to other persons and organisations. What matters is not a data leak alone but the effect on the availability, integrity or confidentiality of the service.

Commission Implementing Regulation (EU) 2024/2690 adds further criteria for certain sectors – for example the number of users affected, the duration of the outage and the geographic spread of the incident.

In practice organisations have to develop an internal classification logic that answers: who decides whether an incident is notifiable? On what criteria? That decision has to be taken before the incident – because the 24-hour clock starts at the moment of awareness and not after internal clarification. A proven tool is a threshold table defined in advance with example scenarios and clear decision paths. This table should be reviewed at least once a year.

For significant incidents NIS2 requires a staged notification process to the competent authority or the CSIRT – which body that is follows from the national law of each Member State. The deadlines run from the moment the organisation becomes aware of the incident:

  • Stage 1 – early warning within 24 hours: A first indication that a significant incident may have occurred, stating suspected causes and any possible cross-border impact
  • Stage 2 – incident notification within 72 hours: An updated report with an assessment of severity, impact and indicators of compromise
  • Stage 3 – intermediate reports: At the request of the authority while the incident is ongoing
  • Stage 4 – final report (no later than 1 month after stage 2): A detailed analysis with the root cause, the mitigation applied and any cross-border effects

Meeting these deadlines requires preparation: without predefined roles, escalation paths and minimal templates, they are hard to keep in a real emergency. Notifications are filed through the national channel; set up your access and rehearse the process during normal operations.

The early warning is not the final detailed report. Its purpose is to signal early to the competent body that a significant incident may have occurred, including an indication of possible causes and potential cross-border impact.

In practice it helps to prepare a minimal template: time of discovery, services affected, first impact, first hypothesis, contact person, next updates.

The final report (no later than one month) contains:

  • A detailed description of severity and impact
  • The suspected root cause or type of threat
  • Mitigation applied and still running
  • Cross-border effects (where relevant)

This requires that during the incident a log is kept, otherwise it is hard to reconstruct afterwards.

NIS2 and the GDPR are two separate frameworks with different protective aims that can apply at the same time to one security incident. The GDPR protects personal data and requires notification to the data protection supervisory authority within 72 hours. NIS2 focuses on the availability and integrity of systems and requires an early warning within just 24 hours.

In a ransomware attack that paralyses systems and exfiltrates data, both duties run in parallel – with different deadlines and to different authorities. NIS2 provides that competent authorities and data protection supervisory authorities cooperate where an incident touches both areas.

In practice: the incident response process has to check from the outset whether GDPR notification duties are triggered in parallel, so that both routes and deadlines stay synchronised. Recommendation: record in the incident log which reporting duties were checked and which decisions were taken on what grounds. That makes it possible to demonstrate without gaps that every deadline was met.

Supply chain & third parties

Supply chain security and handling vulnerabilities at suppliers.

Supply chain security under NIS2 (Article 21(2)(d)) means that the entities covered have to assess and manage the cybersecurity risks of their direct suppliers and service providers systematically – not once, but as a repeatable process. This covers at least:

  • Classifying all suppliers by how critical they are to your own service delivery
  • Defined minimum security requirements in contracts and SLAs
  • A repeatable assessment procedure (questionnaire plus evidence review)
  • Clear incident notification routes between supplier and entity
  • A defined process for deviations and escalation (mitigation, replacement, restriction)

Particularly relevant: if a critical supplier is itself the victim of an attack, your own entity has to be able to judge whether that triggers a reporting duty of its own as well. In practice most organisations start with a criticality list of their ten most important suppliers. For high-risk suppliers an on-site audit or an extended questionnaire is advisable in addition.

NIS2 names secure acquisition, development and maintenance including the handling and disclosure of vulnerabilities. In practice that covers:

  • The asset reference: which system is affected
  • Prioritisation by impact and exploitability
  • Defined patch SLAs
  • An exception process (where a patch is not immediately possible)
  • Lessons learned

Without this structure, backlogs build up that increase both audit and incident risk.

Governance & roles

Responsibilities, management liability and fine ceilings.

NIS2 anchors cybersecurity explicitly at governance level: under Article 20 NIS2 management bodies – managing directors, the board or comparable bodies – have to approve cybersecurity measures, oversee their implementation and can, for breaches of duty, be held personally liable for those failures. That is a central change compared with NIS1.

In concrete terms that means three duties for management:

  • risk management measures under Article 21 have to be approved and compliance with them ensured
  • Attend cybersecurity training and promote it in the organisation
  • Name a NIS2 contact point and guarantee that incidents are notified on time

For SMEs that means: management has to integrate NIS2 actively into the running of the business. Simply delegating to the IT department without governance involvement of its own does not protect against personal liability. Recommendation: introduce an annual management review that documents that the measures were approved, implemented and reviewed. That record serves as evidence of the governance duty in an inspection.

For breaches of NIS2 duties the directive sets binding minimum fine ceilings that Member States may not fall below; they may set higher amounts. Article 34 names as minimum ceilings:

  • Essential entities: at least EUR 10 million or 2 % of worldwide annual turnover
  • Important entities: at least EUR 7 million or 1.4 % of worldwide annual turnover

The higher amount applies in each case. Fines are not the only instrument, though: for essential entities the competent authority can, in serious cases, also temporarily prohibit individuals from exercising management functions.

On top of that comes personal management liability under Article 20 NIS2: management bodies have to approve the cybersecurity measures and oversee them – where a breach of duty is established, members of management can be held personally liable. The actual level of any sanction depends on severity, duration and the cooperation of the organisation. Authorities can also order entities to inform the public about security breaches where that is in the public interest.

NIS2 is not only an IT task; it requires clear governance. For SMEs a minimum role model:

  • (1) Management as sponsor and decision-maker (priorities, budget, risk acceptance)
  • (2) Security or IT owner (operational implementation of the measures)
  • (3) NIS2 contact point (communication, keeping the register entry current, incident notifications)
  • (4) Deputy (round-the-clock reachability in practice)

Fix responsibilities in writing, make the escalation path clear – and only then roll out controls.

Evidence & auditability

How to document measures and demonstrate effectiveness.

NIS2 is being refined further through guidance, national interpretation and proposed adjustments. Best practice is therefore:

  • (1) Name a policy owner
  • (2) Introduce a quarterly review rhythm
  • (3) Keep a change log
  • (4) Build a link collection of official sources
  • (5) Document lessons learned after incidents and exercises

A last updated date and short change notes increase transparency towards authorities and auditors.

A spreadsheet can help an SME at the start (inventory, list of measures, responsibilities) – but NIS2 asks for more than a list: repeatable processes, notification that meets deadlines, supply chain controls and evidence of effectiveness.

At the latest when you have several sites, many systems or frequent changes, a spreadsheet becomes difficult: version chaos, no audit trail, unclear ownership, manual reminders, fragile evidence.

Recommendation: start pragmatically, but define a target picture early so you do not end up in isolated solutions.

National transposition & SMEs

Deadlines, national registers, registration and practical guidance for mid-sized organisations.

NIS2 is a directive, not a regulation: it does not apply directly. It entered into force on 16 January 2023 and Member States had to transpose it into national law by 17 October 2024. Since then binding requirements apply, among them security requirements and reporting obligations.

Registration deadlines are set nationally and differ from one Member State to the next – check the date that applies to you. Several of these deadlines have already passed.

Important: the NIS2 obligations apply regardless of any registration deadline. Organisations that have not yet registered with their national registration portal should do so without delay – late registration is generally still possible. A missed registration protects neither against the reporting obligations for significant incidents nor against the personal responsibility of management bodies. As transposition progresses, supervisory activity by the national cybersecurity authorities increases – prompt registration and building the minimum measures are therefore strongly recommended.

First, confirm scope: does the organisation fall under NIS2 by sector and size? The binding answer comes from national law, and the European Commission maintains an overview of national transposition as an entry point. Once scope is confirmed, we recommend a pragmatic five-step start:

  • (1) Define the scope: Which sites, subsidiaries and services are affected
  • (2) Assign responsibilities: Management as sponsor, a security owner for operational implementation, a NIS2 contact point for communication with the authority
  • (3) Prepare the national registration: A verified electronic identity for the organisation usually takes lead time
  • (4) Secure core resilience: Test backup restore, create minimal incident templates
  • (5) Prioritise the supply chain: Identify the most critical suppliers, formulate minimum requirements

These five steps create a workable starting position before the full build-up of measures under Article 21 begins. Timing: scope and registration in the first four weeks; steps 4 and 5 can run in parallel in weeks 2 to 8. In parallel, produce the first risk analysis – it is the basis for every further measure under Article 21.

Registration is national, not European: there is no EU-wide register. Each Member State names the authority that keeps its register, and you will find yours through the Commission overview of national transposition which lists the state of play country by country.

Plan for lead time: registration often requires a verified electronic identity for the organisation, and obtaining one takes additional time.

Registers typically ask for company master data, your own classification as an essential or important entity, and contact details. Decide internally who administers the account and who acts as the NIS2 contact point.

The European Commission publishes an overview of the NIS2 Directive as a starting point.

Registration: the directive itself sets no registration deadline. That date comes from national law and in many Member States it has already passed – check the date that applies to you and complete your entry in the national registration portal without delay.

Incident notifications (staged):

  • First notification within 24 hours
  • Further notification within 72 hours
  • Final report no later than one month

These deadlines only hold if roles, communication routes and minimal templates are defined in advance.

Official bodies give no blanket figures, because NIS2 has to be implemented in a risk-based and proportionate way. Typical cost drivers in an SME:

  • Internal capacity (IT and security)
  • Building policies and processes
  • Producing evidence
  • Exercises (incident and BCM)
  • Supplier assessments

Important: funding programmes, where they exist at all, are national and differ from country to country. The directive itself provides no funding. It makes sense to plan the effort in waves: minimum capabilities first, then a step-by-step increase in maturity.

Three particularly useful official routes:

  • (1) Your national cybersecurity authority: Most publish guidance, checklists and introductory material for the organisations they supervise
  • (2) ENISA: The EU agency for cybersecurity publishes technical guidance and reports on the state of cybersecurity in the Union
  • (3) The European Commission: It keeps an overview of the state of transposition in every Member State, alongside the text of the directive itself

Tip: keep an internal NIS2 source list (your national authority, the national act, the directive) and review it once a quarter.

Pragmatic start plan

In 30 days to a NIS2 baseline

From the first stocktake to securing your supply chain – structured and realistic.

1
Step 1
Scope & applicability
Clarify your NIS2 sector, check the size logic, take subsidiaries into account. Document the result internally.
2
Step 2
National registration
Obtain a verified electronic identity for the organisation, set up the account and complete the entry in your national register. The deadline comes from national law.
3
Step 3
Assets & services
Identify critical services and assets, prioritise them and move them into an inventory – the basis for every further measure.
4
Step 4
Incident roles
Define roles (owner, contact point, deputy), fix communication routes and create minimal templates.
5
Step 5
Backup & recovery
Review backup processes, run a restore test and document business continuity scenarios.
6
Step 6
Supply chain
Identify critical suppliers, define minimum requirements and run or schedule the first assessments.
7
Step 7
Baseline policies
Create the minimum policies: password and access rules, incident process, acceptable use policy.
8
Step 8
Awareness & training
Start the first training measures – management and IT first. Basics: phishing, passwords, incident detection.
Terms

Compliance Glossary

59 technical terms on NIS2, the GDPR and cybersecurity – explained clearly and gathered in one place.

To the full glossary →
Compliance Compass
Knowledge is not enough – act now.

Compliance Compass automates every NIS2 requirement – from risk analysis to incident reporting. Compliant in 4–8 weeks.