NIS2 Directive

NIS2 is the EU directive that sets cybersecurity risk-management and incident reporting duties for medium and large entities in 18 critical sectors.

The NIS2 Directive, Directive (EU) 2022/2555, is the EU's baseline cybersecurity law for the organizations that keep the economy and society running. It entered into force in January 2023, replacing the first NIS Directive, and member states had until 17 October 2024 to transpose it. According to the Commission's NIS2 page, it covers 18 critical sectors, among them energy, transport, health, finance, digital infrastructure, manufacturing and public administration, and generally applies to medium-sized and large entities in them.

In-scope organizations are classed as essential or important entities, which sets how closely they are supervised. Both must:

  • Take cybersecurity risk-management measures (Article 21), including incident handling, business continuity, supply chain security and vulnerability handling.
  • Report significant incidents (Article 23): an early warning within 24 hours of becoming aware, an incident notification within 72 hours, and a final report within one month.
  • Have their management bodies approve and oversee those measures (Article 20).

Maximum fines are at least EUR 10 million or 2% of worldwide annual turnover for essential entities, and at least EUR 7 million or 1.4% for important entities, whichever is higher (Article 34).

Because NIS2 is a directive, the obligations that bind a company sit in national transposing laws, and several arrived late. The Commission's page, as updated on 2 July 2026, records its decision to refer Ireland, Spain, France and the Netherlands to the Court of Justice for failing to notify transposition measures, and on 20 January 2026 the Commission proposed targeted amendments to NIS2 as part of a new cybersecurity package. Financial entities apply DORA instead where its ICT rules are equivalent, so groups that span sectors often run both regimes side by side.

This entry is general information, not legal advice.

Sources

  1. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2), EUR-Lex accessed 30 Sep 2026
  2. European Commission, NIS2 Directive: securing network and information systems (last updated 2 July 2026) accessed 30 Sep 2026

Know which changes apply to your business.

RegWatch reads the regulators you choose and explains every change it surfaces.

Book a demo