NIS2 Directive — operationalised.
Directive (EU) 2022/2555 — the EU baseline for cyber resilience.
Scope, registration, incident reporting and management accountability for ~160k essential and important entities across 18 sectors.
NIS2 replaces the original NIS Directive and dramatically widens the EU's cybersecurity perimeter. It applies to medium and large entities across 18 sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal & courier, waste management, chemicals, food, manufacturing of critical products, digital providers and research. Member States were required to transpose NIS2 into national law by 17 October 2024, with active supervision rolling out through 2025 and 2026.
Open NIS2 hub on ENISA- Legal basis
- Directive (EU) 2022/2555
- In force
- 16 Jan 2023
- Transposition deadline
- 17 Oct 2024
- Entities in scope
- ~160,000 across EU-27
- Sectors
- 18 (Annex I & II)
- Max fine — Essential
- €10M or 2% global turnover
- Max fine — Important
- €7M or 1.4% global turnover
What this framework covers
Who is in scope
NIS2 distinguishes between Essential entities (Annex I — energy, transport, banking, health, water, digital infrastructure, public administration, space) and Important entities (Annex II — postal, waste, chemicals, food, manufacturing, digital providers, research). Size thresholds are medium (50+ staff, €10M+ turnover) and large (250+ staff, €50M+ turnover), with mandatory inclusion for some sub-sectors regardless of size.
- ›Essential entities: ex-ante and ex-post supervision
- ›Important entities: ex-post supervision after incident or indication
- ›Same baseline security obligations apply to both tiers
Article 21 — security measures
All entities must implement a baseline of technical, operational and organisational measures, proportionate to risk, covering ten domains.
- ›Risk analysis and information system security policies
- ›Incident handling (prevention, detection, response)
- ›Business continuity, backups and crisis management
- ›Supply chain security including direct supplier relationships
- ›Security in acquisition, development and maintenance of network and information systems
- ›Policies and procedures to assess effectiveness of cybersecurity risk-management measures
- ›Basic cyber hygiene practices and cybersecurity training
- ›Cryptography and, where appropriate, encryption
- ›Human resources security, access control and asset management
- ›Multi-factor authentication, secured voice/video/text and secured emergency communications
Article 23 — incident reporting
Significant incidents must be notified to the national CSIRT or competent authority on a strict three-step cadence.
- ›Early warning within 24 hours of awareness — including suspected malicious cause and any cross-border impact
- ›Incident notification within 72 hours — initial assessment, severity, impact and indicators of compromise
- ›Final report within 1 month — root cause, mitigations applied and cross-border effects
- ›Intermediate report on request and a progress report if the incident is ongoing at the one-month mark
Article 20 — management accountability
Management bodies must approve cybersecurity risk-management measures, oversee their implementation, and can be held personally liable for infringements. Members of management bodies are required to follow training and are encouraged to offer similar training to employees on a regular basis.
Regulatory milestones
- 16 Jan 2023NIS2 enters into force
- 17 Oct 2024Member State transposition deadline
- 17 Jan 2025Lists of essential & important entities established
- 2025–2026Active supervision, audits and first sanctions
- 17 Oct 2027First Commission review of NIS2 effectiveness
How TheCyberCo operationalises NIS2
- Scoping assessment — confirm Essential vs Important classification and sector mapping
- Gap analysis against the ten Article 21 measures with prioritised remediation roadmap
- Incident reporting playbooks aligned to the 24h / 72h / 1-month cadence
- Board-level training pack for management accountability under Article 20
- Supply chain due-diligence framework for direct ICT suppliers
- Continuous compliance reporting fed by our SOC telemetry