NIS2 is the European Union's cybersecurity law for organisations that run critical services. It sets minimum standards for how you manage security risk, report incidents, and govern cybersecurity at board level. Its full name is Directive (EU) 2022/2555, and it replaced the original NIS Directive from 2016.
One detail decides how you should read everything else on this page. NIS2 is a directive, not a regulation, so it does not apply to you directly. It applies through your own country's law, and those laws differ.
- Directive (EU) 2022/2555, in force since January 2023
- A directive, not a regulation. It binds you through your national law, not on its own
- 27 national versions that differ on sectors, deadlines and reporting routes
- 18 sectors across Annex I and Annex II, covering medium and large organisations
- Ten risk management measures under Article 21, plus reporting duties under Article 23
- Board accountability under Article 20, with fines reaching 10 million euro or 2% of global turnover
What Is NIS2?
NIS2 is an EU cybersecurity directive that sets mandatory security and incident reporting requirements for organisations in critical and important sectors. It stands for the Network and Information Security Directive 2, and it is the successor to the EU's first attempt at common cybersecurity rules in 2016.
The Directive covers four things: how you manage security risk, how you report incidents, how your leadership governs cybersecurity, and how you handle risk introduced by your suppliers. It applies across 18 sectors and captures an estimated 160,000 organisations, roughly eight times the reach of the law it replaced.
Why NIS2 Is a Directive, Not a Regulation
NIS2 is a directive. GDPR is a regulation. That distinction sounds like lawyer trivia and it is not.
A regulation applies directly in every Member State from the day it takes effect, with identical text everywhere. A directive does not apply to you at all. It tells 27 governments to write their own laws achieving the result it describes, then gives them a deadline to do it.
You therefore cannot comply with NIS2 itself. You comply with the Dutch Cyberbeveiligingswet, or with Poland's amended Act on the National Cybersecurity System. Those laws set your registration deadline, name your supervising authority, and tell you which portal to file an incident report on. The Directive names none of them.
This misunderstanding derails more NIS2 programmes than anything else. A team reads the Directive, builds a control set against Article 21, then finds that their national law added sectors the annexes never listed, or set a registration deadline that expired months earlier.
Practical test: if someone hands you a NIS2 compliance plan that never names a national law, an authority or a registration portal, it was written from the Directive text and it is incomplete.
NIS2 Is Really 27 National Laws
Every national law has to deliver at least what the Directive requires. Above that floor, Member States can go further, and most of them have. Six things vary enough to change your project plan.
Which entities are covered
Several Member States pulled in sectors or entity types the annexes never listed. Your Annex I or Annex II reading can be correct and still miss you.
Registration route and deadline
Some countries expect self-registration within weeks of the law taking effect. Others identify entities themselves and write to them.
Where incidents get reported
Each country runs its own portal and CSIRT. The 24 and 72 hour clocks are fixed by the Directive, but the destination is national.
Who supervises you
Some states appointed a single national authority. Others split supervision across sector regulators, so a utility and a hospital answer to different bodies.
How penalties are calculated
The Directive sets ceilings. National law decides the bands beneath them and how far personal liability for directors reaches.
When obligations actually start
Entry into force and the date duties bite are not always the same. A few laws phase in registration; others start everything on day one.
The gaps are wide. The Dutch Cyberbeveiligingswet applies from 15 August 2026, nearly two years after the EU deadline, and it grants no general grace period: registration, the duty of care and incident reporting all begin immediately. Ireland still had not finished transposing when the European Commission referred it to the Court of Justice on 8 July 2026. If you operate in several Member States, you have been running on a different compliance clock in each of them.
Country guides
We track the law, the authority, the registration route and the deadline for every Member State.
How Transposition Actually Went
Member States had 21 months to write NIS2 into national law. Most of them missed it, and the delay is still working its way through the system.
In Force
NIS2 entered into force on 16 January 2023, starting the clock for Member States to transpose it.
Deadline Missed
The transposition deadline fell on 17 October 2024. In November the Commission opened infringement proceedings against 23 Member States.
Escalation
Reasoned opinions went to 19 Member States in May 2025. Ireland was referred to the Court of Justice on 8 July 2026.
A late national law is not extra time. Several transposing laws apply the moment they enter force, with no phase-in. Organisations that waited for their government now have weeks to do what others had two years for.
Which EU Cyber Law Applies to You?
NIS2 is one of several EU rules that land on the same security team, and they overlap enough to cause real confusion about which one governs what.
DORA
The Digital Operational Resilience Act covers banks, insurers, investment firms and their critical ICT providers. Where DORA applies, it takes precedence over NIS2 for ICT risk management as the more specific law.
CER Directive
NIS2's sibling. It covers largely the same sectors but addresses physical threats such as sabotage and natural hazards rather than cyber risk. Many organisations fall under both.
Cyber Resilience Act
The CRA governs the security of products with digital elements. It applies to what you sell, not to how you run your own operations. If you manufacture connected products, you need both.
GDPR
A single breach can trigger obligations under both laws on different clocks and to different authorities. GDPR gives you 72 hours to the data protection authority; NIS2 wants an early warning to your CSIRT within 24.
ISO 27001
A certification, not a law. It maps well onto the Article 21 measures and makes useful evidence, but no auditor can certify you as NIS2 compliant. Only your national authority supervises that.
NIS (2016)
Repealed and replaced by NIS2 in October 2024. If your programme still references the original NIS Directive or national laws built on it, it is out of date.
Does NIS2 Apply to You?
Three things decide it: your sector, your size, and whether you provide services in the EU. In broad terms NIS2 covers medium and large organisations across the 18 sectors in Annexes I and II, which means 50 or more staff, or turnover and balance sheet above 10 million euro. A set of exceptions captures smaller organisations regardless of size, including DNS providers, TLD registries and trust service providers.
Your national law can widen this, which is why the annexes are a starting point rather than an answer. We keep the full breakdown, including the sector lists and the entity classification rules, on a separate page with a checker that walks you through it.
Check whether NIS2 applies to your company
What NIS2 Requires
Article 21 lists ten risk management measures that every in-scope organisation must implement, covering risk analysis, incident handling, business continuity, supply chain security, vulnerability handling, effectiveness testing, training, cryptography, access control and multi-factor authentication. Article 23 sets the reporting clocks at 24 hours for an early warning, 72 hours for a full notification and one month for a final report. Article 20 makes your management body personally accountable for approving and overseeing the lot.
The measures have to be proportionate to your risk, your size and the impact a disruption would have, so two organisations in the same sector can land on visibly different standards.
See the ten requirements in detail and score your readiness
What Changed From NIS1
The 2016 NIS Directive was the EU's first common cybersecurity framework, and it had four problems. Member States identified in-scope operators case by case, so the same sector faced different rules depending on the country. The scope left out much of the digital economy. Reporting timelines were vague. Penalties were low enough to ignore.
NIS2 replaced case-by-case identification with a size-cap rule, widened coverage from 7 sectors to 18, fixed the reporting clocks in law, added supply chain obligations, and put management bodies personally on the hook.
Read the full NIS vs NIS2 comparison
NIS2 Terms, Decoded
The Directive uses a handful of terms in ways that are not obvious from ordinary English.
- Transposition. The process by which a Member State writes an EU directive into its own national law. Until your country transposes, there is no national text to comply with.
- Essential entity. A large organisation in an Annex I sector. Faces proactive supervision, meaning audits and inspections can arrive without an incident.
- Important entity. Medium organisations in Annex I, plus medium and large in Annex II. Same duties, but supervision is reactive.
- Significant incident. One that has caused or could cause severe operational disruption or financial loss to you, or considerable damage to others. This is the trigger for the 24 hour clock.
- Competent authority. The national body that supervises NIS2 compliance in your sector and country. Not always the same body as your CSIRT.
- CSIRT. Computer Security Incident Response Team. The national body that receives your incident reports and coordinates the response.
- Size-cap rule. The default test that brings medium and large enterprises into scope automatically, replacing the case-by-case identification used under NIS1.
Frequently Asked Questions
NIS2 stands for the second Network and Information Security Directive, formally Directive (EU) 2022/2555. It replaced the original NIS Directive from 2016 and applies across all 27 EU Member States through their national transposing laws.
NIS2 is a directive. A regulation such as GDPR applies directly and identically in every Member State. A directive instructs each Member State to write its own law achieving the same result, which is why NIS2 exists in 27 national versions that differ on sectors, registration deadlines, reporting portals and supervising authorities.
No. The Directive sets a common floor that every national law has to meet, and Member States are free to go beyond it. In practice they differ on which entities are covered, how and when you register, which portal receives incident reports, who supervises you, and how penalties are calculated. Transposition dates also vary by years, so obligations start at different times in different countries.
It can. NIS2 reaches organisations established outside the EU where they provide covered services inside it. Certain digital providers in that position must designate a representative in a Member State, which then becomes the country whose law and authority apply to them. The UK is not bound by NIS2 and is reforming its own NIS Regulations separately.
No, though it helps. ISO 27001 is a voluntary standard and its controls map closely onto the Article 21 measures, so certification is strong evidence that several of them are in place. It does not cover the Article 23 reporting duties, the Article 20 governance obligations, or national registration, and no certification body can declare you NIS2 compliant. Only your national authority supervises that.
DORA is a regulation covering digital operational resilience in the financial sector, and it applies directly without national transposition. NIS2 is a broader directive covering 18 sectors. Where both could apply to a financial entity, DORA governs ICT risk management as the more specific law, though the organisation may still have NIS2 duties for activities DORA does not reach.