Risk management measures
Documented policies on risk analysis, incident handling, business continuity, supply chain security and access control.
Regulation
The EU Network and Information Security Directive 2 — cybersecurity requirements for essential and important entities across the union.
NIS2 in 60 seconds
Documented policies on risk analysis, incident handling, business continuity, supply chain security and access control.
Early warning within 24 hours and a full notification within 72 hours, with a defined internal escalation path.
Company leadership must approve the measures and can be held personally responsible for failures.
Supervisory authorities may request documentation, audit results and proof of training at short notice.
Five guides covering scope, obligations, deadlines and consequences.
The two-criteria scope test in full: the eighteen Annex I and Annex II sectors, and the size thresholds that decide whether you are in or out. Includes the essential vs important comparison, the entity types covered regardless of headcount, and a five-step self-assessment.
Read the guideEvery mandatory risk-management measure from risk analysis through to multi-factor authentication, with a plain-language description of what each one actually covers. Also explains why implementation without documentation still fails an audit.
Read the guideThe harmonised fine ceilings for essential and important entities, and the Article 20 duties that make cybersecurity a board matter. Covers management liability, temporary suspension of executives and the extra sanctions member states add.
Read the guideThe 24-hour early warning, 72-hour notification and one-month final report, with what each submission must contain. Explains what makes an incident significant and why speed beats completeness at the first stage.
Read the guideThe complete list of the eleven Annex I sectors of high criticality and the seven Annex II other critical sectors, each with a one-line description. The quickest way to check whether your activity is named in the directive.
Read the guide2016
Original NIS Directive
Directive (EU) 2016/1148 sets the first EU-wide cybersecurity rules, with wide national discretion.
14 Dec 2022
NIS2 adopted
Directive (EU) 2022/2555 is signed and published in the Official Journal.
18 Oct 2024
Enforceable
Transposition deadline passes, national rules apply and the 2016 directive is repealed.
2025
National transposition
Member states continue converting NIS2 into national law and open entity registration.
2026
Commission review
The Commission reviews the functioning of the directive and proposes amendments where needed.
Every package lists its full contents before purchase.
For organisations beginning their NIS2 programme
The complete starting point for NIS2: editable policies, templates and step-by-step guidance to get your compliance work moving.
Small teams starting their NIS2 assessment and needing a clear picture of where they stand.
A structured gap-analysis checklist covering all NIS2 article requirements, ready to work through with your team.