Regulations · NIS2

NIS2 Directive

Directive (EU) 2022/2555NIS2 (Directive EU 2022/2555) applies to essential and important entities in 18 EU critical sectors from October 2024. Article 21 security measures and 24h/72h incident reporting required. Free applicability check.

In force since
2024-10-17
Atomic obligations
28
Max exposure
€10M
or 2% global turnover

Who is concerned?

NIS2 dramatically expanded the scope of EU cybersecurity regulation. It covers two categories :

Essential entities (Annex I) : energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, space.

Important entities (Annex II) : postal and courier services, waste management, manufacture/production/distribution of chemicals, food, manufacturing, digital providers, research.

Generally : medium and large enterprises (>50 employees, >€10M turnover) in these sectors. Specific thresholds vary by member state transposition.

What it requires (high-level)

  • Risk management measures (Art. 21) : policies, incident handling, business continuity, supply chain security, vulnerability disclosure, cryptography, MFA.
  • Incident notification : early warning within 24h, incident notification within 72h, final report within 1 month.
  • Supply chain security : assess and account for vulnerabilities of direct suppliers and service providers.
  • Management body accountability : top management is personally liable for non-compliance — including potential bans from management roles.

Penalty exposure

Up to €10M or 2% of global annual turnover for essential entities. Up to €7M or 1.4% for important entities. Plus personal liability for board / management body in some member states (FR, DE, IT, ES have implemented this strongly).

How NexCyber helps with NIS2

  • Essential vs important classification — automated based on your sector, size, and member state.
  • 21 risk management measures mapping — each measure mapped to controls (ISO 27001, NIST CSF).
  • Incident reporting workflow — pre-filled templates for 24h / 72h / 1-month obligations.
  • Supply chain visibility — vendor inventory + tier-1 risk scoring.
  • Management body briefings — board-ready PDF reports with personal liability heat-map.

Critical : if you haven't started NIS2 implementation yet, you are already non-compliant in most EU member states.

NIS2 — Frequently asked questions

Does NIS2 apply to my organisation?+

NIS2 applies to medium and large organisations (≥50 employees or >€10M turnover) in 18 critical sectors including energy, transport, banking, health, water, digital infrastructure, ICT service management, public administration, manufacturing and food. Run the free NIS2 Applicability Checker at nexcyber.eu/tools/nis2-applicability-checker for a 60-second verdict.

When did NIS2 take effect?+

NIS2 entered into force on 16 January 2023 and the Member State transposition deadline was 17 October 2024. National implementing laws (NIS2 transposition acts) are now in force across the EU, with enforcement powers granted to national cybersecurity agencies.

What are the NIS2 incident-reporting deadlines?+

Early warning within 24 hours of becoming aware of a significant incident, intermediate incident notification within 72 hours, and a final report within 1 month. Cross-border incidents must be coordinated through ENISA and the CSIRT network.

What does Article 21 require?+

Article 21 lists ten cybersecurity risk management measures : risk analysis and policies, incident handling, business continuity, supply chain security, vulnerability handling, training, cryptography, access control, MFA and basic cyber hygiene. NexCyber maps each measure to evidence items and existing controls (ISO 27001, NIST CSF).

See your NIS2 readiness in 5 minutes.

Free assessment. No credit card. EU-hosted. Auditable engine.

Run free assessment