NIS2 is Directive (EU) 2022/2555, the EU framework for cybersecurity capabilities, cooperation, risk-management measures, incident reporting, supervision and enforcement across critical sectors. It entered into force in January 2023, had a national transposition deadline of 17 October 2024 and repealed NIS1 from 18 October 2024. Organisations must check the applicable Member-State law because transposition and procedures are national and remain uneven.
The Commission describes NIS2 as covering 18 critical sectors. Scope is not determined by sector alone: entity type, size, special inclusion rules, establishment and jurisdiction matter.
Who is in scope?
Article 2 generally applies to public or private entity types listed in Annex I or II that qualify as medium-sized enterprises under the EU SME recommendation or exceed the medium-sized ceilings. The analysis must consider the recommendation's rules, not only a standalone headcount or revenue number.
Article 2 also brings specified entity types into scope regardless of size—for example, certain electronic communications, trust, DNS, TLD, domain-registration, public-administration and sole-provider or particularly critical cases. Member States can identify additional entities under the Directive's criteria.
Annex I high-criticality sectors cover energy, transport, banking, financial-market infrastructures, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration and space. Annex II includes postal and courier services, waste management, certain chemicals, food, manufacturing, digital providers and research. Use the detailed entity-type descriptions, definitions and national law rather than a sector label.
Essential and important entities
Article 3 classifies covered organisations as essential or important using entity type, size and special status. Broadly, large Annex I entity types are essential, while covered medium Annex I entities and Annex II entities are generally important, subject to the detailed rules and special categories.
Both categories must address Articles 20, 21 and 23. The main distinction lies in supervision and enforcement: essential entities are subject to a more proactive supervisory regime, while important entities are generally supervised ex post when evidence indicates possible non-compliance. National implementation controls the practical process.
Management-body duties
Article 20(1) requires Member States to ensure that management bodies of essential and important entities approve the measures taken to comply with Article 21, oversee their implementation and can be held liable for infringements by the entities of Article 21. How that possible management-body liability operates is subject to national implementation, including the Directive's express reservation for national liability rules applicable to public institutions and relevant officials. Article 20(2) separately addresses management-body training. Organisations should document decisions, challenge, resources, exceptions, training and follow-up.
This is serious accountability, but “every director is automatically personally fined” is not an accurate statement of the Directive. Enforcement measures, procedures and responsible natural persons depend on the relevant provisions and national law.
Article 21 cybersecurity measures
Measures must be appropriate and proportionate, take an all-hazards approach, and consider risk exposure, entity size, likelihood and severity, and societal and economic impact. Article 21(2) requires at least these areas:
- risk-analysis and information-system-security policies;
- incident handling;
- business continuity, backup management, disaster recovery and crisis management;
- supply-chain security concerning direct suppliers and service providers;
- secure acquisition, development and maintenance, including vulnerability handling and disclosure;
- assessment of measure effectiveness;
- cyber hygiene and training;
- cryptography and, where appropriate, encryption;
- human-resources security, access control and asset management; and
- appropriate multifactor or continuous authentication, secured communications and emergency communications.
The list is a minimum set of risk areas, not a claim that ten documents or products produce compliance. Commission implementing acts and ENISA guidance add detail for specified digital and ICT entity types; national and sector rules may also matter.
Article 23 significant-incident reporting
An incident is significant under Article 23 when it has caused or is capable of causing severe operational disruption or financial loss for the entity, or considerable material or non-material damage to other persons.
For significant incidents, the Directive establishes staged reporting:
- early warning without undue delay and within 24 hours after awareness, for every reporting essential or important entity;
- ordinarily, incident notification without undue delay and within 72 hours after awareness, updating initial information and providing an initial assessment where available;
- intermediate reporting when requested; and
- a final report no later than one month after the incident notification.
If the incident is ongoing at the one-month point, a progress report replaces the final report then, and the final report follows within one month after incident handling concludes. The trust-service-provider derogation changes only the ordinary 72-hour incident notification: when a significant incident affects provision of its trust services, that notification is due within 24 hours. It does not replace the 24-hour early warning that applies to every reporting entity. Duties to inform affected service recipients can also apply.
Different rules such as GDPR use different definitions and thresholds. Run coordinated but separate assessments.
Supervision and penalties
Articles 32 and 33 provide supervisory and enforcement powers. Article 34 requires Member States to provide maximum administrative fines of at least the higher of EUR 10 million or 2% of worldwide annual turnover for essential-entity infringements of Article 21 or 23, and at least the higher of EUR 7 million or 1.4% for important entities. These are statutory maxima or minimum required ceilings for national law, not automatic fines. Authorities must consider circumstances and proportionality, and Member States may establish other penalties.
Do not assess exposure from the headline number alone. Supervisory orders, audits, corrective actions, service and customer impact, contracts and overlapping laws can be material.
Relationship with other frameworks
- ISO/IEC 27001: can support an ISMS and evidence but does not establish NIS2 compliance.
- GDPR: personal-data-breach duties can run in parallel with NIS2 significant-incident reporting.
- DORA: sector-specific Union law can displace equivalent NIS2 provisions under Article 4; analyse the activity and rule, not the group label.
- National law: sets competent authorities, registration, procedures and additional detail.
Implementation roadmap
- Analyse each legal entity, service, size relationship and jurisdiction.
- Confirm current national transposition and authority instructions.
- Brief the management body and obtain governance decisions.
- Map existing risk and controls to Article 21 and national requirements.
- prioritise gaps by service impact, legal timing and risk.
- Build and exercise Article 23 assessment and reporting.
- Strengthen supplier, continuity and effectiveness evidence.
- Report residual risk and overdue action to management.
- Monitor legal change, including proposals separately from enacted law.
As of this review, the Commission's January 2026 targeted NIS2 amendments are proposals, not a basis for treating enacted Directive wording as already changed.
For entity-specific scope and implementation, see our NIS2 compliance services.
Sources and review
This guide was substantively reviewed on 8 August 2026. It qualifies scope, transposition status, management accountability, reporting stages and penalty ceilings and distinguishes proposed amendments from current law.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.