Regulation

NIS2

The EU Network and Information Security Directive 2 — cybersecurity requirements for essential and important entities across the union.

NIS2 in 60 seconds

  • What it is: an EU cybersecurity law, Directive (EU) 2022/2555, replacing the 2016 NIS Directive with stricter and more uniform obligations.
  • Who it applies to: around 160,000 organisations across 18 sectors according to Commission estimates — generally medium-sized enterprises and up, plus some entity types regardless of size, split between essential and important entities.
  • Since when: enforceable from 18 October 2024, the date national transposition was due and the old directive was repealed.
  • What it costs to ignore: fines up to €10 million or 2% of global annual turnover, whichever is higher, plus personal accountability for management.
  • Start here: check whether NIS2 applies to your organisation.

What NIS2 asks of you

Risk management measures

Documented policies on risk analysis, incident handling, business continuity, supply chain security and access control.

Incident reporting

Early warning within 24 hours and a full notification within 72 hours, with a defined internal escalation path.

Management accountability

Company leadership must approve the measures and can be held personally responsible for failures.

Evidence on request

Supervisory authorities may request documentation, audit results and proof of training at short notice.

Explore NIS2 in depth

Five guides covering scope, obligations, deadlines and consequences.

How NIS2 got here

  1. 2016

    Original NIS Directive

    Directive (EU) 2016/1148 sets the first EU-wide cybersecurity rules, with wide national discretion.

  2. 14 Dec 2022

    NIS2 adopted

    Directive (EU) 2022/2555 is signed and published in the Official Journal.

  3. 18 Oct 2024

    Enforceable

    Transposition deadline passes, national rules apply and the 2016 directive is repealed.

  4. 2025

    National transposition

    Member states continue converting NIS2 into national law and open entity registration.

  5. 2026

    Commission review

    The Commission reviews the functioning of the directive and proposes amendments where needed.

Available packages

Every package lists its full contents before purchase.

Frequently asked questions