NIS2 Directive
NIS2 Directive — the centre of gravity
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union. NIS2 replaces the 2016 NIS Directive, widening scope (from ~7 sectors to 18) and hardening obligations. Learn this one first — the rest of the ecosystem is defined in relation to it.
Purpose
Raise the cybersecurity baseline of the organisations society depends on, and knit 27 national systems into one cooperative EU framework (strategies, CSIRTs, cross-border cooperation, coordinated vulnerability disclosure).
Who is in scope (Art. 2, Annexes I–II)
Two categories, mainly by sector + size:
- Essential entities — large entities (250+ staff or €50M+ turnover) in Annex I “high-criticality” sectors: energy; transport; banking; financial market infrastructures; health; drinking water; waste water; digital infrastructure (DNS, TLDs, cloud, data centres, CDNs, trust services, public e-comms); ICT service management (MSPs/MSSPs); public administration; space.
- Important entities — medium entities (50+ staff or €10M+ turnover) in Annex I, and medium/large in Annex II “other critical sectors”: postal & courier; waste management; chemicals; food; manufacturing (medical devices, computers/electronics, machinery, motor vehicles, other transport equipment); digital providers (online marketplaces, search engines, social networks); research.
Size-cap exceptions — some entities are in scope regardless of size: qualified
trust service providers, TLD registries and DNS providers, sole providers of a critical
service, central-government public administration. CER critical entities are
automatically NIS2-essential. Member States may expand scope (Art. 2(2)) — several
did (see 30-national/).
Core obligations
Governance (Art. 20)
Management bodies must approve the risk-management measures, oversee implementation and take training — and can be held personally liable (national mechanisms vary: personal fines, temporary management bans).
Risk-management measures (Art. 21) — the “ten measures”
An all-hazards, proportionate baseline: (1) risk-analysis & information-system security policies; (2) incident handling; (3) business continuity, backups, crisis management; (4) supply-chain security; (5) security in acquisition/development/maintenance incl. vulnerability handling & disclosure; (6) effectiveness measurement; (7) cyber hygiene & training; (8) cryptography/encryption; (9) HR security, access control, asset management; (10) MFA/continuous authentication and secured/emergency communications. For digital-infrastructure-type entities, Implementing Regulation (EU) 2024/2690 specifies technical requirements and the significant-incident thresholds.
Incident reporting (Art. 23) — the 24/72/one-month cascade
For significant incidents, to the CSIRT/competent authority: early warning ≤ 24h (flag suspected malicious cause / cross-border impact); notification ≤ 72h (severity, impact, IoCs); intermediate/progress reports on request or at one month if ongoing; final report ≤ 1 month (root cause, mitigation, cross-border impact). Service recipients informed where relevant; voluntary reporting of near-misses enabled.
Registration (Arts. 3, 27) & jurisdiction (Art. 26)
States keep registries of essential/important entities (national self-registration portals, national deadlines). Jurisdiction defaults to the state of establishment; for cloud/DNS/data-centre/CDN/MSP/MSSP/marketplace/search/social providers it follows the main establishment (where risk-management decisions are predominantly taken). Non-EU providers designate an EU representative.
Supervision & penalties (Arts. 31–36)
- Essential: proactive (ex-ante) supervision — audits, inspections, binding instructions. Fines up to €10M or 2% of worldwide turnover (higher of). Ultima ratio: suspension of authorisations, temporary management bans.
- Important: reactive (ex-post) supervision. Fines up to €7M or 1.4%. Most states adopted these ceilings verbatim.
National dimension (why 30-national/ exists)
NIS2 also obliges states: national cyber strategy (Art. 7), competent authorities &
single points of contact (Art. 8), CSIRTs (Art. 10), national large-scale incident
response plan (Art. 9), participation in the Cooperation Group, CSIRTs Network and
EU-CyCLONe. Transposition was due 17 Oct 2024; only Belgium, Croatia, Italy and
Lithuania met it. By mid-2026, 22 of 27 states had adopted transposing laws; France,
Ireland, Luxembourg, the Netherlands and Spain remained in procedure, with 4 CJEU
referrals. Per-country detail: 30-national/.
Interplay
DORA displaces NIS2 for financial entities; CER critical entities are auto-essential; GDPR breach reporting runs in parallel; CRA governs the products NIS2 entities buy (supply-chain security connects them).
Pending changes
- Targeted amendments (proposed 20 Jan 2026): jurisdictional clarity, “small mid-cap”
relief, streamlined ransomware data, stronger ENISA role; 12-month transposition once
adopted →
20-proposals/nis2-amendments-2026.md. - Digital Omnibus: Art. 23 reporting to flow through the Single Entry Point →
20-proposals/digital-omnibus-sep.md.
Sources
- Text: https://eur-lex.europa.eu/eli/dir/2022/2555/oj
- Impl. Reg. 2024/2690: https://eur-lex.europa.eu/eli/reg_impl/2024/2690/oj
- Commission NIS2 / transposition tracker: https://digital-strategy.ec.europa.eu/en/policies/nis-transposition
- ENISA: https://www.enisa.europa.eu/topics/cybersecurity-policy/nis-directive-2