← Glossary

Regulation & Compliance

NIS2 Directive

Also: NIS 2 · Directive (EU) 2022/2555 · Network and Information Security Directive · essential entities · important entities

Last reviewed: — regulation changes; check the primary source below before relying on a date or a threshold.

In one sentence

NIS2 is the EU directive that widens cybersecurity obligations from a few critical operators to most medium and large organisations in eighteen sectors, with mandatory security measures, incident reporting and personal liability for management.

Why it matters

The first NIS directive (2016) covered "operators of essential services" — a short list of energy, transport, banking, health, water and digital infrastructure companies that each member state chose. NIS2 replaces the choice with a size rule: if you are in one of eighteen listed sectors and are a medium or large enterprise (50+ staff or €10 m+ turnover), you are in scope, full stop. Manufacturing, food, waste, postal services, public administration, research and managed service providers all joined the list.

Two provisions changed the conversation in boardrooms. Management bodies must approve the cybersecurity measures, oversee their implementation and can be held personally liable (Article 20), and must attend training. And fines scale with turnover: up to €10 m or 2 % for essential entities, €7 m or 1.4 % for important ones.

How it is structured

Entities are either essential (large enterprises in high-criticality sectors such as energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration and space) or important (the other sectors, and medium enterprises in the high-criticality ones). The obligations are the same; the difference is supervision — proactive audits for essential entities, after-the-fact for important ones — and the fine ceiling.

Article 21 sets the security floor: ten minimum measures every entity must implement, on an all-hazards basis. Risk analysis and information system security policies; incident handling; business continuity, backup and crisis management; supply-chain security; security in acquisition, development and maintenance including vulnerability handling; policies to assess the effectiveness of the measures; cyber hygiene and training; cryptography and encryption; human resources security, access control and asset management; and multi-factor authentication, secured communications and emergency communication systems.

Article 23 sets the reporting clock for significant incidents: an early warning within 24 hours of becoming aware, an incident notification within 72 hours with an initial assessment, and a final report within one month — to the national CSIRT or competent authority. Recipients of the service must be notified where a significant cyber threat could affect them.

NIS2 is a directive: member states had to transpose it by 17 October 2024 and several were late, so the operative text is the national law — in Luxembourg, the law transposing NIS2 with the ILR and CSSF as competent authorities depending on sector. Where a sector-specific EU act such as DORA applies, it takes precedence (Article 4).

Try it yourself hands-on

You run IT for a 120-person food-processing company. Someone forwarded an article about NIS2 fines and asked "does this apply to us?"

  1. Open the NIS2 Self-Assessment. The scope section asks your sector and size: production, processing and distribution of food is an Annex II sector and 120 staff makes you a medium enterprise, so you are an important entity. That is the answer to the email.
  2. Continue into the Article 21 measures. For each of the ten, record status and a note. Measure (j) — multi-factor authentication — is where a "we have MFA on email" answer needs to become "MFA on email, VPN and the ERP admin console; not on the OT network", because the directive says where appropriate and the auditor will ask where you decided it was not.
  3. Export the gap report. It is organised by Article 21 letter, which is how the competent authority will ask about it. Tick "Keep my progress in this browser" and revisit it as measures land.
  4. Rehearse the 24-hour early warning: pick a scenario (ransomware on the packaging line), open the Incident Report Generator and draft the early warning with only what you would know in the first day — suspected unlawful act, cross-border impact — nothing more is required at that stage.
  5. If you already hold ISO 27001, the Control Mapper shows which Annex A controls evidence which Article 21 measure, so you do not build a second programme.

Common misreadings

  • Supply-chain security is your problem even if you are out of scope. Measure (d) obliges in-scope customers to assess their suppliers, so small vendors receive NIS2 questionnaires without being NIS2 entities themselves.
  • "Significant incident" has a definition. Severe operational disruption or financial loss, or considerable damage to others — not every phishing email. But the 24-hour clock starts at awareness, not at confirmation.
  • Registration is a separate duty. Entities must register with the national authority; being in scope and never having registered is itself a finding.