NIS2
NIS2 Directive (EU) 2022/2555
Cybersecurity risk management, management accountability and staged incident reporting starting with an early warning within 24 hours.
The law in brief
NIS2 is the EU's cybersecurity law for organizations that keep society and the economy running. It raises the bar on cybersecurity risk management, makes senior management accountable for it, and sets strict timelines for reporting significant incidents.
It is a directive, so it applies through each member state's national law. The obligations are broadly the same everywhere, but registration, supervision and details vary by country.
Who it applies to
- Essential and important entities in the sectors listed in Annexes I and II, including energy, transport, banking, health, drinking water, digital infrastructure, ICT service management, public administration, space, postal services, waste, chemicals, food, manufacturing of critical products, digital providers and research.
- Generally medium and large organizations (50 or more employees, or more than €10 million annual turnover and balance sheet), with some covered regardless of size, such as DNS providers, top-level domain registries and qualified trust service providers.
- It reaches organizations established outside the EU that provide covered services in the EU, which may need a representative.
What it requires
Management accountability
Management bodies must approve the cybersecurity risk-management measures, oversee their implementation and follow training, and can be held liable for infringements.
Cybersecurity risk-management measures
Take appropriate and proportionate technical, operational and organizational measures, covering at least risk analysis, incident handling, business continuity and crisis management, supply chain security, secure development, vulnerability handling, cyber hygiene and training, cryptography, access control and multi-factor authentication.
Report significant incidents in stages
Send the national authority or CSIRT an early warning within 24 hours of becoming aware of a significant incident, an incident notification within 72 hours, and a final report within one month.
Tell recipients of your services
Where a significant incident is likely to affect the service, inform its recipients without undue delay, including measures they can take themselves.
Enforcement and penalties
Member states must allow fines of at least up to €10 million or 2% of worldwide annual turnover, whichever is higher, for essential entities, and up to €7 million or 1.4% for important entities (Art. 34). Authorities can also order audits, suspend certifications and, for essential entities, temporarily ban individuals from management roles (Art. 32). Essential entities are supervised proactively; important entities mainly after the fact.
What's changing
National laws still arriving. Member states had to transpose NIS2 by 17 October 2024, and several did so late. Your duties start under the law of the member state where you are established or provide services. Regulatory Watch reports national transposition and guidance.
What to do first
- Confirm whether you are in scope, by sector and size, in each country where you operate, and register where required.
- Brief and train your management body; it must approve and oversee cybersecurity risk measures.
- Gap-assess against the Article 21 measures, especially supply chain security, multi-factor authentication and incident handling.
- Set up 24-hour, 72-hour and one-month reporting for significant incidents.
- Review supplier contracts for security requirements and incident cooperation.
Checked against the official text on 28 September 2026. Quotations are the operative words of the law, linked to the article they come from; the official text is the authority. This brief is written by the Association for practitioners and is not legal advice.
Recent developments
-
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services. ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted sector and highlights that 73% of incidents affect essential entities under the NIS2 definition.
Effective: 22 September 2026.
Source: ENISA news. NIS2 in the regulations library.
-
ENISA releases NIS360 report showing improved cybersecurity maturity of EU critical sectors
The report tracks implementation of the NIS2 Directive and helps policymakers prioritize resources to boost cyber resilience across the EU. The ENISA NIS360 report released on 28 May 2026 indicates that cybersecurity maturity across EU critical sectors has improved, while sector criticality remains relatively stable. The report identifies a risk zone of sectors with lower maturity but higher criticality, including health, railway, maritime, ICT management services, space, public administrations, drinking water and waste water.
Source: ENISA news. NIS2 in the regulations library.
Sources
- Directive (EU) 2022/2555 EUR-Lex · Official text or regulator