Security
Directive (EU) 2022/2555
NIS2
Network and Information Security Directive 2
More companies that keep society running — energy, food, health, digital — must lock their networks properly and report serious incidents.
Does this hit me?
You should see fewer silent outages in energy, health, and payments. You do not report your own laptop.
Check in the wizardPick a country in the header to see who enforces this at home. Union text is not the last word for directives.
How it rolls in
Jan 2023
Entered into force.
Oct 2024
Transposition deadline.
Why it exists
Ransomware and supply-chain hacks were hitting hospitals and pipelines. The first NIS law was too narrow and too uneven between countries.
What actually changes
- Many more 'essential' and 'important' entities are in scope, including some mid-size firms in listed sectors.
- Management is personally expected to oversee cyber risk.
- Incident reporting on tight clocks.
- Supply-chain and vulnerability handling become explicit duties.
How it hits you
You should see fewer silent outages in energy, health, and payments. You do not report your own laptop.
For citizens
What this does to everyday life
Rights, bills, and what you can ignore. You are usually not the one who files — companies and states are.
Hospitals, trains, power, food
More operators of things you depend on must actually do cybersecurity and report serious incidents. You should notice fewer silent outages — and more honest 'we were hit' notices.
Rights you actually get
- No new personal filing. You remain a patient, passenger, customer.
Costs and trade-offs
- Security spend can appear in bills. That is cheaper than a month-long hospital IT freeze.
What you can do
- If a critical service is down, look for the operator's notice. Consumer and health regulators still handle harm to you.
What you can ignore
- Your home Wi-Fi is not a NIS2 entity.
If something goes wrong
The operator, then the national CSIRT / competent authority. Police for cybercrime against you personally.
More citizen notes across files: For people
Heard this? Not quite.
Claim: Every website owner is now a critical entity.
Scope is sector + size. A bakery website is not a power grid. Cloud, telecoms, and energy are the centre of gravity.
Latest official statements
All EU NewsNo tagged Commission, Parliament or Council statement in the current feeds.
Board one-pager
Board one-pager
Who this is for: EU critical entities and ICT providers. Directive (EU) 2022/2555. National law should already apply (deadline Oct 2024).
Scope
- You are in a NIS2 sector (energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public admin, space, postal, waste, chemicals, food, manufacturing of critical products, digital providers, research — check the national list).
- You meet the size test, or you are a special entity in-scope regardless of size (e.g. certain trust service or DNS providers).
First 90 days
- Week 1: Read your Member State's transposition and registration portal.
- Month 1: Gap Annex I measures: risk, incident, backup, supply chain, crypto, HR security.
- Month 2: Incident severity matrix and 24/7 notice path to the CSIRT.
Penalties: Essential entities: up to €10 million or 2% of worldwide turnover. Important entities: up to €7 million or 1.4%. Management bans possible.
For companies
How to stay on the right side of this file
Practical order of work, not a substitute for counsel. Essential and important entities in listed sectors above size thresholds, plus some special cases regardless of size.
You are probably
In if you are on the national essential or important list — size thresholds catch many mid-market operators.
Effort
Gap analysis weeks. Registration and board sign-off are the first artefacts.
Budget
Security programme, not a one-page policy. Incident retainers and logging cost more than the lawyer.
Roles in this file
The same company can wear more than one hat. Classify before you buy a tool.
Essential entity
Annex I sectors (energy, transport, banking, health, drinking water, digital infrastructure, public admin…).
Full duties, stricter supervision, registration, 24h/72h/1-month incident clocks.
Important entity
Annex II (postal, waste, chemicals, food, manufacturing of critical products, digital providers…).
Same core duties, lighter ex-ante supervision. Do not read ‘important’ as optional.
Are you in scope?
Act now- You are in a NIS2 sector (energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public admin, space, postal, waste, chemicals, food, manufacturing of critical products, digital providers, research — check the national list).
- You meet the size test, or you are a special entity in-scope regardless of size (e.g. certain trust service or DNS providers).
Usually not, if
- Micro companies outside special categories.
- A generic office business with no listed sector.
First moves
- Week 1Read your Member State's transposition and registration portal.CISO + legal
- Month 1Gap Annex I measures: risk, incident, backup, supply chain, crypto, HR security.Security
- Month 2Incident severity matrix and 24/7 notice path to the CSIRT.Ops
- If you are 'important' rather than 'essential', supervision is lighter (ex post) — still implement the measures.
- Use a sector ISAC or a managed SOC if you cannot staff 24/7.
If you skip this
- Not on the national register when you should be.
- Board that cannot show it took the risk.
- Incident clocks missed because Legal first ‘aligned the wording’.
Done looks like
- A named list decision (essential/important/out).
- Incident playbook with the 24-hour first notice.
- Supply-chain clauses for critical ICT.
Keep this evidence
- Registration.
- Risk assessment.
- Incident records.
- Management training attendance.
- Supplier assessments.
Ask vendors
- What is your incident-notice SLA to us, in hours, and who is on the call tree?
Where programmes usually break
- Assuming ISO 27001 certification is automatic NIS2 compliance — map the extra incident and supply-chain duties.
Call counsel when
- You sit on the size threshold.
- Group with entities in several Member States.
- A sector supervisor already asking for the registration file.
Enforcement
Essential entities: up to €10 million or 2% of worldwide turnover. Important entities: up to €7 million or 1.4%. Management bans possible.
National competent authority / CSIRT under the transposition.
Need a stack, not one file? Open the company desk
Professional briefing
Legal architecture and duties
For counsel, compliance, and policy teams. Not advice. The Official Journal still wins.
- Instrument
- Directive
- Legal basis
- Art 114 TFEU · Directive (EU) 2022/2555
- Application
- Transposition deadline 17 October 2024; Member States apply from 18 October 2024. Late transposition is widespread — check the national statute you actually face, not only the Directive.
NIS2 expands cybersecurity risk-management and incident-reporting duties to ‘essential’ and ‘important’ entities across listed sectors, including many mid-caps that were never NIS1 operators. Management body accountability is explicit. Extra-territorial for certain digital providers offering services in the Union. It is a directive: registration, thresholds, and penalties are national.
How the file is built
Essential vs important
Same risk-management duties in substance; supervision is ex ante for essential, generally ex post for important. Annexes I and II list sectors; size cap (usually medium+) with exceptions for critical small entities.
Risk measures (Art 21)
A closed list: policies, incident handling, business continuity, supply chain, cryptography, HR security, etc. ‘Appropriate and proportionate’ is the standard — document the proportion.
Reporting (Art 23)
Early warning 24h, notification 72h, final report 1 month, to CSIRT/competent authority. Parallel GDPR 72h if personal data is involved.
Operators
| Role | Who | Core duties |
|---|---|---|
| Essential entity | Energy, transport, banking, health, drinking water, digital infrastructure, public admin, etc., above size tests. | Art 21 measures, Art 23 reporting, registration, governance. |
| Important entity | Postal, waste, chemicals, food, manufacturing of listed goods, digital providers, etc. | Same measures; lighter supervision. |
| Management body | Directors. | Approve cybersecurity measures, follow training, can be held liable under national law. |
Scope
Entities providing services or carrying out activities in the Union. Certain non-EU digital providers (cloud, DNS, marketplaces, search, social) must designate an EU representative.
In
- Sectors in Annexes I and II.
- Size: generally medium and large; some entities in-scope regardless of size (e.g. qualified trust providers, TLD registries, certain public bodies).
- Supply-chain security of direct suppliers and service providers.
Out, or narrower than assumed
- Micro and small entities unless listed exceptions apply.
- Entities whose activities are exclusively in national security, intelligence, or the judiciary in specified ways.
- The financial DORA regime carves overlapping financial entities toward DORA as lex specialis for those duties.
Operative provisions
| Anchor | Rule | What it does in practice |
|---|---|---|
| Art 20 | Governance: management body oversight and training. | Cyber is a board minute, not only a CISO slide. |
| Art 21 | Ten categories of risk-management measures, including supply chain and encryption. | ISO 27001 helps but is not an automatic safe harbour. |
| Art 23 | Multi-stage incident reporting. | Incident runbooks must hit 24h/72h clocks with legal characterisation. |
| Art 34 | Fines: at least up to €10m or 2% (essential) and €7m or 1.4% (important) of worldwide turnover. | National law may go higher; personal liability of managers is national. |
Secondary law and guidance
- Commission implementing act on technical measures for certain digital providers (cloud, managed services, marketplaces, search, social).
- ENISA guidance and national CSIRT taxonomies.
- National registration portals — each State has its own.
National layer. The entire operational regime is national: who is in, how to register, which authority, criminal law, and whether gold-plating pulls extra sectors. Cross-border groups need a map of lead authorities.
How it sits with other files
CRA is product security for makers; NIS2 is operator security for essential/important entities. A hospital runs NIS2; the infusion-pump vendor runs CRA.
A ransomware event is often both an Art 23 NIS2 incident and an Art 33 GDPR breach.
Online platforms may be important/essential digital providers and DSA platforms — two reporting trees.
Enforcement and private rights
Who
National competent authorities and CSIRTs; ENISA supports. Peer reviews at Union level.
Tools
Binding instructions, on-site inspections, fines, management bans in national law.
Private rights
Contractual customers will flow down NIS2 measures; direct statutory private rights are limited and national.
Risk register
| Risk | Signal | Control |
|---|---|---|
| Unregistered entity | No national registration though headcount > 250 in a listed sector | Scope opinion + register where required. |
| 24h miss | Incident process owned only by IT, not legal/comms | Joint playbook with a 24h legal trigger. |
| Board vacuum | No training, no approved risk acceptance | Annual management-body training and signed risk appetite. |
Open issues
- Incomplete or late transposition — dual uncertainty of scope.
- How ‘supply chain’ measures bite on non-EU cloud majors.
- Overlap with DORA, CER Directive (physical resilience), and sectoral energy/transport rules.
Primary sources
Cyber duties for essential and important entities. The national list is the on-switch. The board is in the file.
You feel it now
Union deadline was October 2024. Several States were late; supervisors are still standing up lists.
Next
Registration waves and first incident-report drills in 2026.
Where it lands
| Channel | People | Companies |
|---|---|---|
| Outages | You should see fewer ‘systems down’ if tests are real. You do not register. | 24-hour incident notice, registration, supply-chain security. Management liability is the political point of the Directive. |
| National delay | Late transposition does not mean the sector is out. | If you run energy, health, food, water, digital infrastructure or a named important entity, assume in and read the national list. |
Who gains
Customers of essential services if the drills are not paper.
Who pays
Groups that treated NIS2 as an IT policy rewrite.
Files this pulls with it
- DORA — Financial entities: DORA is the lex specialis for ICT. NIS2 still frames the rest of the group.
- Cyber Resilience Act — Product security is CRA; operator security is NIS2. Both can hit a connected-device maker.
- GDPR — A personal-data incident can be both a NIS2 notice and a GDPR breach.
Who pays
Essential and important entities, plus their security vendors.
Who benefits
Anyone who needs hospitals, trains, and payments to stay up.
Read the official text