NIS2 (Directive (EU) 2022/2555) is the European Union's landmark cybersecurity legislation — the most significant overhaul of European network and information security rules in nearly a decade. With national transposition deadlines passed and enforcement now active across member states, organisations in scope must comply or face fines up to EUR 10 million and personal liability for management. This guide covers everything from determining whether NIS2 applies to you to implementing the required security measures.
Key Takeaways
- NIS2 covers 18 sectors and applies to medium and large enterprises (50+ employees or EUR 10M+ turnover).
- Organisations must implement 10 minimum security measures covering risk management, incident handling, supply chain security, and more.
- Cyber incidents must be reported within 24 hours (early warning) and 72 hours (incident notification).
- Fines reach EUR 10 million or 2% of global turnover for essential entities.
- Management bodies are personally liable — directors must approve, oversee, and undergo cybersecurity training.
- NIS2 complements GDPR and works alongside DORA (financial sector) and the Cyber Resilience Act (products).
Table of Contents
- What Is NIS2?
- Why Was NIS2 Introduced?
- NIS2 vs NIS1: What Changed?
- Who Must Comply with NIS2?
- Essential vs Important Entities
- The 10 Minimum Security Measures
- Incident Reporting Requirements
- Management Liability
- Penalties and Enforcement
- Supply Chain Security
- NIS2 Compliance Roadmap
- NIS2 and ISO 27001
- NIS2 and Other EU Regulations
- National Transposition Status
- FAQ
- Conclusion
What Is NIS2?
Directive (EU) 2022/2555, known as the Network and Information Security Directive 2 (NIS2), is the EU's comprehensive cybersecurity framework. It establishes a common baseline of security requirements across all 27 member states and replaces the original NIS Directive from 2016.
NIS2 was adopted on 14 December 2022, entered into force on 16 January 2023, and member states were required to transpose it into national law by 17 October 2024. Organisations falling within its scope must now comply with the requirements set out in their national implementing legislation.
The directive has four core objectives:
- Strengthen cybersecurity resilience across critical and important sectors
- Harmonise security requirements to eliminate fragmentation between member states
- Improve incident detection and response through mandatory reporting and cooperation
- Enhance supply chain security by extending obligations to critical service providers
Key statistic: According to ENISA's 2024 Threat Landscape report, ransomware attacks increased by over 150% in the past five years, with critical infrastructure being the primary target. NIS2 is the EU's direct regulatory response to this escalation.
Why Was NIS2 Introduced?
The original NIS Directive (2016/1148) was groundbreaking as the EU's first cybersecurity law, but it had significant limitations:
- Inconsistent transposition — member states implemented the directive differently, creating a patchwork of requirements
- Narrow scope — only 7 sectors covered, leaving major industries unregulated
- Weak enforcement — no harmonised penalties; some countries imposed minimal fines
- No management accountability — cybersecurity was treated as an IT issue, not a board-level responsibility
- Limited supply chain coverage — the weakest link in many organisations' security was unaddressed
The COVID-19 pandemic and the surge in ransomware attacks on hospitals, energy providers, and government agencies made clear that a stronger, broader framework was urgently needed.
NIS2 vs NIS1: What Changed?
| Aspect | NIS1 (2016) | NIS2 (2022) |
|---|---|---|
| Sectors covered | ~7 sectors | 18 sectors (Annex I + Annex II) |
| Entity classification | Operators of essential services (OES), digital service providers | Essential entities + important entities |
| Size criteria | Member state discretion | Harmonised EU-wide thresholds (50+ employees or EUR 10M+) |
| Security measures | General requirements | 10 specific minimum measures (Article 21) |
| Incident reporting | Variable by country | Standardised: 24h / 72h / 1 month |
| Penalties | Set by each member state | Harmonised minimums: EUR 10M / 2% or EUR 7M / 1.4% |
| Supply chain | Limited | Explicit supply chain security obligations |
| Management liability | Not specified | Personal liability for management bodies |
| Supervision | Primarily reactive | Proactive for essential entities, reactive for important entities |
| Cooperation | Basic CSIRT network | Enhanced EU-CyCLONe network for crisis management |
Who Must Comply with NIS2?
NIS2 applies to medium and large enterprises operating in one of the 18 covered sectors. The size thresholds are:
| Size Category | Employees | Annual Turnover | Balance Sheet |
|---|---|---|---|
| Medium enterprise | 50-249 | EUR 10M-50M | EUR 10M-43M |
| Large enterprise | 250+ | Over EUR 50M | Over EUR 43M |
| Micro/small | Fewer than 50 | Under EUR 10M | Under EUR 10M |
Micro and small enterprises are generally excluded, with important exceptions:
- Trust service providers (eIDAS)
- TLD name registries and DNS service providers
- Public electronic communications networks or services
- Public administration entities
- Sole providers of an essential service in a member state
- Entities where disruption could impact public safety, security, or health
- Entities identified as critical under the CER Directive
Supply chain effect: Even if your organisation is below the size thresholds, you may be contractually required to meet NIS2 standards if you are a supplier to an essential or important entity. NIS2 Article 21(2)(d) explicitly requires in-scope entities to address supply chain security.
Essential vs Important Entities
NIS2 divides in-scope organisations into two categories, which determine the level of supervision and maximum penalties.
Essential Entities (Annex I — High Criticality)
| Sector | Examples |
|---|---|
| Energy | Electricity (generators, DSOs, TSOs), oil, gas, hydrogen, district heating/cooling |
| Transport | Air, rail, water, and road transport operators and infrastructure managers |
| Banking | Credit institutions as defined by CRD |
| Financial market infrastructure | Trading venues, central counterparties, central securities depositories |
| Health | Hospitals, healthcare providers, EU reference laboratories, medical device manufacturers |
| Drinking water | Water supply and distribution operators |
| Waste water | Waste water collection, treatment, and disposal operators |
| Digital infrastructure | IXPs, DNS providers, TLD registries, cloud computing, data centres, CDNs, trust services, electronic communications |
| ICT service management (B2B) | Managed service providers (MSPs), managed security service providers (MSSPs) |
| Public administration | Central government entities (excluding judiciary, parliament, central banks) |
| Space | Operators of ground-based infrastructure supporting space services |
Important Entities (Annex II — Other Critical)
| Sector | Examples |
|---|---|
| Postal and courier | Postal service operators, courier and parcel delivery |
| Waste management | Waste collection, treatment, recovery, and disposal |
| Chemicals | Manufacturing, production, and distribution of chemical substances |
| Food | Food production, processing, and wholesale distribution |
| Manufacturing | Medical devices, computers, electronics, optical products, electrical equipment, machinery, motor vehicles, trailers, other transport equipment |
| Digital providers | Online marketplaces, online search engines, social networking platforms |
| Research | Research organisations |
The 10 Minimum Security Measures
Article 21 mandates that all in-scope entities implement appropriate and proportionate technical, operational, and organisational measures. The directive specifies 10 domains that must be addressed:
| # | Measure | What It Covers |
|---|---|---|
| 1 | Risk analysis and information security policies | Risk assessment methodology, security policies, asset classification, acceptable use |
| 2 | Incident handling | Detection, analysis, classification, containment, recovery, and lessons learned |
| 3 | Business continuity and crisis management | Backup management, disaster recovery, crisis management procedures |
| 4 | Supply chain security | Supplier risk assessment, contractual security requirements, continuous monitoring |
| 5 | Secure acquisition, development, and maintenance | Secure-by-design, vulnerability management, patch management, DevSecOps |
| 6 | Effectiveness assessment | Security audits, penetration testing, vulnerability scanning, KPIs |
| 7 | Cyber hygiene and training | Awareness programmes, phishing simulations, role-based training, management training |
| 8 | Cryptography and encryption | Encryption standards, key management, data protection at rest and in transit |
| 9 | HR security and access control | Screening, RBAC, least privilege, access reviews, offboarding procedures |
| 10 | Multi-factor authentication and secure communications | MFA for all systems, encrypted communications, emergency communication channels |
Proportionality Principle
The measures must be proportionate to:
- The size of the entity
- The likelihood and severity of potential incidents
- The state of the art and cost of implementation
- The entity's exposure to risks
- The potential societal and economic impact of an incident
Practical guidance: An SME with 60 employees in the food manufacturing sector will not be expected to implement the same controls as a major energy utility. However, both must demonstrate that they have addressed all 10 domains proportionate to their risk profile.
Incident Reporting Requirements
NIS2 introduces a four-stage notification system for significant cybersecurity incidents:
| Stage | Deadline | Content |
|---|---|---|
| Early warning | Within 24 hours | Whether the incident is suspected to be unlawful/malicious; whether it may have cross-border impact |
| Incident notification | Within 72 hours | Initial assessment of severity and impact; indicators of compromise where available |
| Intermediate report | Upon request by CSIRT/authority | Status update on incident handling and response measures |
| Final report | Within 1 month of incident notification | Detailed description; root cause analysis; mitigation measures; cross-border impact assessment |
What Is a "Significant Incident"?
An incident qualifies as significant if it:
- Has caused or is capable of causing severe operational disruption of the service or financial loss to the entity
- Has affected or is capable of affecting other persons by causing considerable material or non-material damage
Reporting to Whom?
Reports go to the national CSIRT (Computer Security Incident Response Team) or the designated competent authority in each member state. ENISA coordinates cross-border incidents through the EU-CyCLONe network.
Double reporting obligation: If the incident also involves personal data, GDPR's 72-hour notification to the data protection authority applies simultaneously. The NIS2 24-hour early warning is a separate, additional obligation.
Management Liability
One of NIS2's most significant innovations is personal accountability for management bodies (Article 20).
What Management Must Do
| Obligation | Detail |
|---|---|
| Approve risk management measures | Management must formally approve the cybersecurity risk-management measures adopted under Article 21 |
| Oversee implementation | Active supervision of whether measures are actually implemented and effective |
| Undergo training | Management members must obtain sufficient knowledge and skills to identify cybersecurity risks and assess practices |
| Ensure staff training | All employees must receive regular cybersecurity awareness training |
Personal Consequences
Member states must ensure that management bodies can be held personally liable for infringements of Article 21. This may include:
- Personal fines against individual directors
- Temporary bans on exercising managerial functions
- Public disclosure of non-compliance
- Civil liability for damages caused by failure to fulfil obligations
This changes the dynamic fundamentally. Cybersecurity is no longer just an IT department responsibility — it is a board-level governance obligation with personal consequences for directors who fail to act.
Penalties and Enforcement
Maximum Fines
| Entity Type | Maximum Fine | Supervision |
|---|---|---|
| Essential entities | EUR 10,000,000 or 2% of global annual turnover (whichever is higher) | Proactive — regular audits, on-site inspections, security scanning |
| Important entities | EUR 7,000,000 or 1.4% of global annual turnover (whichever is higher) | Reactive — investigations following incidents, complaints, or evidence |
Other Enforcement Powers
Competent authorities may also:
- Issue binding instructions and compliance orders
- Require specific security audits (at the entity's cost)
- Issue warnings and publish findings
- Appoint a monitoring officer for essential entities
- Suspend certifications or authorisations temporarily
- Impose temporary bans on management functions for responsible individuals
Supply Chain Security
Article 21(2)(d) introduces explicit supply chain obligations — a first for EU cybersecurity legislation.
What In-Scope Entities Must Do
- Assess the cybersecurity posture of direct suppliers and service providers
- Evaluate the overall quality of products and cybersecurity practices of suppliers
- Include security requirements in contracts with suppliers
- Monitor supplier compliance on an ongoing basis
- Consider the results of coordinated EU-level supply chain risk assessments
Impact on Suppliers
Even if your organisation is not directly in scope of NIS2, your clients in regulated sectors may require you to:
- Demonstrate compliance with specific security standards (e.g., ISO 27001)
- Accept audit rights and security assessments
- Meet incident reporting obligations contractually
- Implement specific technical controls (encryption, MFA, access management)
NIS2 Compliance Roadmap
A structured approach to achieving compliance:
Phase 1: Assessment (Months 1-2)
- Determine whether your organisation is in scope (sector + size)
- Identify which entity classification applies (essential vs important)
- Map existing security controls against the 10 minimum measures
- Conduct a gap analysis to identify missing or inadequate controls
- Review national transposition legislation for country-specific requirements
Phase 2: Planning (Months 2-3)
- Present gap analysis findings to management and secure board approval
- Develop a prioritised compliance roadmap with timelines and budgets
- Assign accountability — designate a NIS2 compliance lead
- Identify resource requirements (internal team, external consultants, tools)
Phase 3: Implementation (Months 3-9)
- Develop or update security policies for all 10 measure domains
- Implement technical controls (MFA, encryption, monitoring, backup)
- Establish incident detection and response capabilities
- Build supply chain risk assessment and monitoring processes
- Create business continuity and disaster recovery plans
- Deploy cybersecurity training for all staff and management
Phase 4: Validation (Months 9-11)
- Conduct internal security audit against NIS2 requirements
- Perform penetration testing and vulnerability assessments
- Run incident response tabletop exercises
- Test business continuity and disaster recovery procedures
- Verify all documentation is complete and accessible
Phase 5: Ongoing Compliance (Continuous)
- Conduct risk assessments at least annually (or after significant changes)
- Schedule regular security audits and penetration tests
- Monitor and update supplier security assessments
- Review and update policies, procedures, and plans annually
- Track regulatory updates and adapt to evolving requirements
- Report compliance status to management regularly
NIS2 and ISO 27001
ISO 27001 provides an excellent foundation for NIS2 compliance, but it is not a complete solution.
| NIS2 Requirement | ISO 27001 Coverage | Gap? |
|---|---|---|
| Risk analysis and security policies | Clause 6.1 (risk assessment), Annex A | Covered |
| Incident handling | A.5.24-A.5.28 (incident management) | Covered |
| Business continuity | A.5.29-A.5.30 (business continuity) | Covered |
| Supply chain security | A.5.19-A.5.23 (supplier management) | Partially — NIS2 goes further |
| Secure development | A.8.25-A.8.33 (development security) | Covered |
| Effectiveness assessment | Clause 9 (performance evaluation) | Covered |
| Cyber hygiene and training | A.6.3 (awareness), Clause 7.2 (competence) | Partially — NIS2 mandates management training |
| Cryptography | A.8.24 (cryptography) | Covered |
| Access control | A.5.15-A.5.18, A.8.2-A.8.5 (access management) | Covered |
| MFA and secure comms | A.8.5 (authentication) | Partially — NIS2 is more specific on MFA |
Key gaps to address even with ISO 27001:
- NIS2-specific incident reporting timelines (24h/72h/1m)
- Management liability and mandatory board training
- Expanded supply chain due diligence requirements
- Registration with national competent authority
- Cross-border incident coordination
Read more: For a detailed comparison, see NIS2 vs ISO 27001: Complete Mapping Guide, which maps every NIS2 requirement to specific ISO 27001 controls and identifies the exact gaps.
NIS2 and Other EU Regulations
| Regulation | Relationship with NIS2 |
|---|---|
| GDPR (EU 2016/679) | Complementary — NIS2 security measures support GDPR Article 32; a cyber incident may trigger both NIS2 and GDPR breach notifications |
| DORA (EU 2022/2554) | Lex specialis — financial entities subject to DORA are generally exempt from NIS2 for overlapping requirements |
| CER Directive (EU 2022/2557) | Complementary — entities identified as critical under CER must also comply with NIS2 |
| Cyber Resilience Act | Complementary — CRA covers product security; NIS2 covers operational security of the entities using those products |
| AI Act (EU 2024/1689) | Overlapping — high-risk AI systems in NIS2 entities must comply with both frameworks |
| ePrivacy Directive | Complementary — electronic communications providers subject to NIS2 must also comply with ePrivacy incident reporting |
National Transposition Status
Member states were required to transpose NIS2 by 17 October 2024. The implementation timeline varies across the EU:
| Status | Countries |
|---|---|
| Transposed and enforcing | Belgium, Croatia, Hungary, Italy, Latvia, Lithuania |
| Transposed, enforcement pending | Germany, France, Netherlands, Czech Republic, Poland, Finland, Sweden |
| Delayed / in progress | Spain, Ireland, Portugal, Austria, Denmark, and others |
Note: Even in countries where national transposition is delayed, the European Commission can take infringement proceedings. Organisations should not wait for national legislation to begin their compliance programmes.
FAQ
Does NIS2 apply to non-EU companies?
Yes. If you provide services within the EU in a covered sector and meet the size thresholds, NIS2 applies. Non-EU entities must designate a representative in one of the member states where they provide services.
Can ISO 27001 certification replace NIS2 compliance?
No, but it covers approximately 70-80% of NIS2 requirements. ISO 27001 is an excellent foundation that demonstrates a mature information security management system. However, NIS2 has specific requirements around incident reporting timelines, management liability, and registration that ISO 27001 does not cover.
What if my organisation operates in multiple EU countries?
You will primarily be supervised by the member state where your main establishment is located (where cybersecurity decisions are predominantly made). However, you must comply with national laws in all member states where you operate.
Are there exemptions?
Certain sectors have specific regulations that take precedence (lex specialis). DORA applies to financial entities instead of NIS2 for overlapping requirements. Entities exclusively serving national security, defence, or law enforcement are generally exempt.
How does NIS2 interact with GDPR breach notification?
A cyber incident may trigger both NIS2 and GDPR notification obligations simultaneously. NIS2 requires a 24-hour early warning to the CSIRT/competent authority; GDPR requires a 72-hour notification to the data protection authority if personal data is affected. These are separate obligations to separate authorities.
What happens if management refuses to comply?
NIS2 allows member states to impose personal sanctions on individual managers, including fines and temporary bans from exercising managerial functions. This is unprecedented in EU cybersecurity regulation.
Should I start compliance now or wait for national legislation?
Start now. The directive's requirements are clear, and most national transpositions closely follow the directive text. Early preparation avoids the rush and demonstrates proactive governance to regulators.
What is the cost of NIS2 compliance?
Costs vary significantly based on organisation size and current security maturity. Organisations with existing ISO 27001 certification may need EUR 50,000-150,000 to close NIS2-specific gaps. Organisations starting from a lower maturity level should budget EUR 200,000-500,000+ for the initial compliance programme, including technical controls, documentation, and training. Factoring in cyber insurance can help transfer residual risk and is increasingly expected by boards alongside NIS2 compliance.
Conclusion
NIS2 represents a fundamental shift in EU cybersecurity governance. It moves from the voluntary, fragmented approach of the original NIS Directive to a mandatory, harmonised framework with real enforcement power and personal accountability for leadership.
For organisations in scope, the message is clear:
- Determine your status — are you essential or important? In one or multiple member states?
- Close the gaps — map your existing controls against the 10 minimum measures and address shortfalls
- Engage management — NIS2 makes cybersecurity a board-level obligation with personal consequences
- Build resilience — the goal is not just compliance but genuine cybersecurity maturity
- Maintain continuously — NIS2 compliance is an ongoing programme, not a one-time project
The organisations that treat NIS2 as an opportunity to strengthen their security posture — rather than a checkbox exercise — will be best positioned to manage cyber risks and meet regulatory expectations.
Related Articles
- NIS2 Compliance Checklist — 10 essential steps with practical implementation guidance
- ISO 27001 Implementation Guide — Build an ISMS that supports NIS2 compliance
- DORA Compliance Guide — Digital resilience for financial entities (NIS2 lex specialis)
- GDPR Compliance Guide — Data protection requirements that complement NIS2
Get Expert Help
Need support with NIS2 compliance? Vision Compliance provides end-to-end support — from initial gap assessment and risk analysis to implementation, training, and ongoing monitoring.
- Cybersecurity Services — NIS2 compliance, risk management, and incident response
- Contact us — Schedule a free consultation
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.