Cybersecurity
Network and Information Systems Directive
Published Reviewed
What is NIS2?
NIS2 requires essential and important entities across critical sectors to manage cybersecurity risk, govern security measures and report significant incidents on defined timelines.
| Jurisdiction | European Union |
|---|---|
| Authority | Directive (EU) 2022/2555 |
| Current status | EU transposition deadline 17 October 2024 |
| Reviewed |
Why it matters operationally
NIS2 widened Europe’s cybersecurity law from a few thousand operators to an estimated hundred thousand essential and important entities across eighteen sectors — and made management personally accountable. Boards must approve the risk measures, follow training, and for essential entities responsible managers can face temporary bans in serious cases (Article 20). Because member states transpose it on different schedules, "where exactly are we in scope" is a live per-country question, not a one-time answer.
Are you aware?
The dates that bind
National NIS2 laws apply — unevenly
Member states had to apply their transpositions from 18 October 2024. Transposition timing varies by member state, which changes when and where you are enforceable — not whether.
The incident-reporting ladder
A significant incident requires an early warning within 24 hours, an incident notification within 72 hours, and a final report within one month (Article 23).
Authorities register who is in scope
National registration duties — for some entity types by 17 January 2025 — put in-scope entities on the authorities’ registers. Silence does not keep you out of scope; it keeps you unprepared.
Where to start
- 1
Determine your classification — essential or important — from sector (Annexes I and II) and size: generally 50+ employees or over €10 million turnover, with size-independent exceptions.
- 2
Put the Article 21 baseline in place: risk analysis, incident handling, business continuity, supply-chain security, encryption, MFA and vulnerability handling.
- 3
Rehearse the 24-hour early warning with a named owner and out-of-hours coverage — the shortest clock in EU cybersecurity law.
Authority links
Read the official sources
The official text is the authority. This guide is only a short orientation for operational planning.
Common questions
Frequently asked questions
Are we essential or important — and does the difference matter?
The security duties are the same; supervision and fines differ. Essential entities face proactive supervision and fines of at least €10 million or 2% of worldwide turnover; important entities at least €7 million or 1.4%, mainly supervised after the fact.
We are below 50 employees — are we out of scope?
Not necessarily. Some entities are in scope regardless of size — qualified trust service providers, TLD registries and DNS service providers among them — and national transpositions can add more. Sector plus size starts the analysis; it does not end it.
What does management accountability actually mean?
Management bodies must approve the cybersecurity risk measures, oversee their implementation and follow training. Members can be held liable for infringements, and for essential entities natural persons with management responsibility can face temporary suspensions in serious cases.
How does NIS2 relate to DORA?
DORA is the more specific law: financial entities covered by DORA follow its incident-reporting and risk rules instead of the NIS2 equivalents. Groups with both financial and non-financial arms commonly live under both regimes at once.
Side by side
Compared against
Operational deep dives
Work through the decision, not just the definition.
Key terms in this guide
A quick self-check
Are you ready?
- Do you know, in writing and per country, whether each of your legal entities is essential, important or out of scope?
- Could you deliver an early warning to the authority within 24 hours of a significant incident — on a Sunday?
- Has your management body approved the current risk measures and completed its training?
- Do your key suppliers meet the security requirements NIS2 expects you to impose on them?
Every question above has a written, evidence-backed answer in a well-run compliance record. If one made you pause, that pause is the gap.