Framework / POLICY

NIS2 Directive — operationalised.

Directive (EU) 2022/2555 — the EU baseline for cyber resilience.

POLICY

Scope, registration, incident reporting and management accountability for ~160k essential and important entities across 18 sectors.

NIS2 replaces the original NIS Directive and dramatically widens the EU's cybersecurity perimeter. It applies to medium and large entities across 18 sectors — energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, space, postal & courier, waste management, chemicals, food, manufacturing of critical products, digital providers and research. Member States were required to transpose NIS2 into national law by 17 October 2024, with active supervision rolling out through 2025 and 2026.

Open NIS2 hub on ENISA
/ KEY.FACTS
Legal basis
Directive (EU) 2022/2555
In force
16 Jan 2023
Transposition deadline
17 Oct 2024
Entities in scope
~160,000 across EU-27
Sectors
18 (Annex I & II)
Max fine — Essential
€10M or 2% global turnover
Max fine — Important
€7M or 1.4% global turnover
/ GUIDANCE

What this framework covers

§ 01

Who is in scope

NIS2 distinguishes between Essential entities (Annex I — energy, transport, banking, health, water, digital infrastructure, public administration, space) and Important entities (Annex II — postal, waste, chemicals, food, manufacturing, digital providers, research). Size thresholds are medium (50+ staff, €10M+ turnover) and large (250+ staff, €50M+ turnover), with mandatory inclusion for some sub-sectors regardless of size.

  • Essential entities: ex-ante and ex-post supervision
  • Important entities: ex-post supervision after incident or indication
  • Same baseline security obligations apply to both tiers
§ 02

Article 21 — security measures

All entities must implement a baseline of technical, operational and organisational measures, proportionate to risk, covering ten domains.

  • Risk analysis and information system security policies
  • Incident handling (prevention, detection, response)
  • Business continuity, backups and crisis management
  • Supply chain security including direct supplier relationships
  • Security in acquisition, development and maintenance of network and information systems
  • Policies and procedures to assess effectiveness of cybersecurity risk-management measures
  • Basic cyber hygiene practices and cybersecurity training
  • Cryptography and, where appropriate, encryption
  • Human resources security, access control and asset management
  • Multi-factor authentication, secured voice/video/text and secured emergency communications
§ 03

Article 23 — incident reporting

Significant incidents must be notified to the national CSIRT or competent authority on a strict three-step cadence.

  • Early warning within 24 hours of awareness — including suspected malicious cause and any cross-border impact
  • Incident notification within 72 hours — initial assessment, severity, impact and indicators of compromise
  • Final report within 1 month — root cause, mitigations applied and cross-border effects
  • Intermediate report on request and a progress report if the incident is ongoing at the one-month mark
§ 04

Article 20 — management accountability

Management bodies must approve cybersecurity risk-management measures, oversee their implementation, and can be held personally liable for infringements. Members of management bodies are required to follow training and are encouraged to offer similar training to employees on a regular basis.

/ TIMELINE

Regulatory milestones

  1. 16 Jan 2023
    NIS2 enters into force
  2. 17 Oct 2024
    Member State transposition deadline
  3. 17 Jan 2025
    Lists of essential & important entities established
  4. 2025–2026
    Active supervision, audits and first sanctions
  5. 17 Oct 2027
    First Commission review of NIS2 effectiveness
/ THECYBERCO.SERVICE

How TheCyberCo operationalises NIS2

  • Scoping assessment — confirm Essential vs Important classification and sector mapping
  • Gap analysis against the ten Article 21 measures with prioritised remediation roadmap
  • Incident reporting playbooks aligned to the 24h / 72h / 1-month cadence
  • Board-level training pack for management accountability under Article 20
  • Supply chain due-diligence framework for direct ICT suppliers
  • Continuous compliance reporting fed by our SOC telemetry

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment