Formally Directive (EU) 2022/2555, it replaces the original NIS Directive and expands the sectors and organizations expected to manage cyber risk, report significant incidents, secure supply chains, and establish management accountability.
NIS2 is a directive, so organizations comply with the national law that transposes it in each relevant Member State — not with a single self-executing EU rulebook in isolation. The deadline for Member States to adopt and publish their measures was 17 October 2024. Scope, supervision, registration, authorities, procedures, and penalties must therefore be checked against the current national implementation, particularly for organizations operating in several countries.
Key points
Who may be in scopeMedium and large entities in the directive’s listed sectors are the main population, divided into essential and important entities. Certain providers can be covered regardless of size, and national authorities may identify additional entities. Sector, service, establishment, size, and national rules all matter.
Risk-management measuresArticle 21 requires appropriate and proportionate technical, operational, and organizational measures. The listed areas include incident handling; business continuity and crisis management; supply-chain security; secure acquisition, development, and maintenance; vulnerability handling and disclosure; effectiveness assessment; cyber hygiene and training; cryptography; access control and asset management; and, where appropriate, MFA or continuous authentication and secure communications.
Management responsibilityManagement bodies must approve the cybersecurity risk-management measures, oversee implementation, and can be held accountable under national law. Members of those bodies must follow training, and organizations are expected to offer relevant training to employees regularly.
Incident reportingFor a significant incident, Article 23 establishes a staged process: an early warning without undue delay and within 24 hours of awareness; an incident notification without undue delay and within 72 hours of awareness — or within 24 hours for a trust service provider where the significant incident affects provision of its trust services; intermediate reports when requested; and a final report no later than one month after the incident notification. A progress report may replace the final report while an incident is ongoing.
Supply chainNIS2 makes security in direct suppliers and service providers an explicit part of risk management. This does not mean every supplier must meet identical controls; organizations need a risk-based approach that considers vulnerabilities, dependency, and the quality and resilience of products and services.
Supervision and penaltiesEssential and important entities are subject to different supervisory approaches, but both can face enforcement. The directive sets maximum administrative-fine frameworks that national laws must implement, alongside possible binding instructions and other measures.
Important limitationNIS2 establishes an EU framework, but a glossary article cannot determine whether a particular legal entity is in scope or satisfy national implementation requirements. Classification and duties depend on the entity, service, jurisdiction, and applicable transposing law.