Skip to main content
Back to overview

What Is NIS2? Scope, Requirements and Compliance in 2026

By NIS2Certify
nis2nis2-directivecompliancearticle-21eu-directive

NIS2 is Directive (EU) 2022/2555, the EU law that requires medium and large organisations in 18 sectors to manage their cybersecurity risks, report significant incidents within 24 hours and put their management body in charge of both. It applies through the national law of each member state, and not every member state has one yet.

Sources: the directive text on EUR-Lex, the European Commission and national authorities. Transposition status checked on 28 September 2026.

Key takeaways

  • NIS2 binds you through national law. The directive entered into force on 16 January 2023 and member states had until 17 October 2024 to transpose it. On 8 July 2026 the Commission took Ireland, Spain, France and the Netherlands to the Court of Justice for failing to do so in full. The Netherlands has since applied its law from 15 August 2026.
  • Size and sector decide. You're in scope from 50 employees, or with fewer if both your annual turnover and your balance sheet total exceed €10 million, provided you work in one of 18 sectors. Some providers are in scope at any size.
  • Article 21 lists 10 measures every in-scope organisation must have, from risk analysis to multi-factor authentication.
  • Incidents are reported in three steps: an early warning within 24 hours, a notification within 72 hours and a final report within a month.
  • Fines reach at least €10 million or 2% of worldwide turnover for essential entities and €7 million or 1.4% for important ones. Management bodies can be held liable.

What is NIS2?

NIS2 is the second Network and Information Security Directive. The EU adopted it on 14 December 2022 to replace the first NIS Directive from 2016, which had left too much to each member state: one country regulated its hospitals, the next didn't, and the supply chains running between them ignored the difference.

NIS2 fixes that in four ways. It widens the scope from a handful of critical sectors to 18. It sets one size rule for all of them. It spells out ten concrete security measures instead of a general duty. And it makes the management body personally responsible.

A directive isn't a regulation, though. It tells member states what their law must achieve, and each country writes its own. That's why "Are we NIS2 compliant?" always has a second question hiding behind it: compliant with which country's law?

What does NIS2 compliance mean?

NIS2 compliance means your organisation meets the obligations of the national law that transposes Directive (EU) 2022/2555: the risk-management measures of Article 21, the reporting deadlines of Article 23, registration with the competent authority, and approval and oversight by the management body under Article 20. A national authority checks it. The EU doesn't.

In practice you need four things:

  1. Registration with the authority in the country where you're established.
  2. The ten measures of Article 21, proportionate to your risks and documented.
  3. An incident process that can produce an early warning within 24 hours of you becoming aware of a significant incident.
  4. A management body that approves the measures, oversees them and has followed cybersecurity training.

The word "documented" does a lot of work there. A supervisor won't take your word for it. If a measure exists only in the head of your IT manager, it doesn't exist for NIS2.

Who does NIS2 apply to?

NIS2 applies to organisations that operate in one of the 18 sectors in Annex I or II of the directive and are at least medium-sized under the EU definition in Recommendation 2003/361/EC. That means 50 or more employees, or fewer than 50 employees with both an annual turnover and a balance sheet total above €10 million.

Note the "both". A 30-person company with €12 million turnover but a €6 million balance sheet is still a small enterprise and usually outside NIS2. Plenty of summaries get this wrong by writing "50 employees or €10 million turnover", and it changes the answer for a lot of trading companies.

The 18 sectors

Annex I, sectors of high criticality:

  • Energy (electricity, district heating and cooling, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking
  • Financial market infrastructure
  • Health
  • Drinking water
  • Waste water
  • Digital infrastructure (internet exchange points, DNS, TLD registries, cloud, data centres, content delivery networks, trust services, public electronic communications)
  • ICT service management, business-to-business (managed service providers and managed security service providers)
  • Public administration
  • Space

Annex II, other critical sectors:

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing (medical devices, computers and electronics, electrical equipment, machinery, motor vehicles, other transport equipment)
  • Digital providers (online marketplaces, search engines, social networking platforms)
  • Research

In scope regardless of size

Some organisations can't hide behind the size rule. They include trust service providers, TLD name registries, DNS service providers, providers of public electronic communications networks or services, and public administration bodies. A member state can also designate a small organisation when it is the only provider of an essential service in that country.

Want to check your own organisation step by step? Use the NIS2 applicability check.

Suppliers below the threshold

Being out of scope isn't the same as being unaffected. Article 21(2)(d) requires in-scope organisations to manage the security of their supply chain, including their direct suppliers. Expect questionnaires, contract clauses and audit rights from customers who are in scope, whether or not you are. The mechanics are in NIS2 supply chain security.

Is NIS2 applicable in the UK?

No. NIS2 is an EU directive and the UK left the EU before it was adopted. The UK regulates the same ground through its own NIS Regulations 2018, which it is reforming. A UK group is still in scope through subsidiaries established in the EU, and cloud, DNS, managed service and some other digital providers that offer services in the EU must designate a representative in a member state (Article 26). Which regulator supervises you explains how that works.

Essential or important entity: what's the difference?

The two categories carry the same obligations. Articles 21 and 23 apply to both. What differs is how closely you're watched and how much a breach can cost.

Essential entityImportant entity
Typical profileLarge organisation in an Annex I sectorMedium-sized organisation in Annex I, or medium or large in Annex II
SupervisionProactive: inspections, regular and targeted audits, security scans (Article 32)Reactive: after an incident or evidence of non-compliance (Article 33)
Maximum fineAt least €10 million or 2% of worldwide annual turnover, whichever is higherAt least €7 million or 1.4%, whichever is higher
Ban on managersPossible: temporary ban on exercising managerial functionsNot in the directive

The profile row is the general rule. Some providers are essential at any size, such as qualified trust service providers and DNS service providers, and member states can designate others.

What are the NIS2 requirements?

The requirements come down to three duties: take the Article 21 measures, report incidents under Article 23, and register with your authority. Article 20 then puts the management body on the hook for all of it.

The 10 measures of Article 21

Article 21(2) lists the minimum measures. "Appropriate and proportionate" is the test, so a 60-person food producer isn't expected to run the security operations of a bank. But it is expected to have something, on paper, for each of these ten:

Article 21 — 10 NIS2 Cybersecurity Measures

Article 21

10 Cybersecurity Measures

Governance & Strategy

1Risk analysis & information security policies
6Effectiveness assessment of security measures

Incident & Continuity

2Incident handling & notification
3Business continuity & disaster recovery

Supply Chain & Systems

4Supply chain security
5Security in network & information systems development

Technical Controls

8Cryptography & encryption
10Multi-factor authentication & secure communications

People & Assets

7Cyber hygiene & training
9HR security & access control
  1. Risk analysis and information system security policies. A documented risk assessment and a security policy that follows from it. Auditors ask for these two documents first; here's what they should contain.
  2. Incident handling. Detection, triage, response and recovery, with roles written down before the incident. See why Article 21(2)(b) fails audits.
  3. Business continuity. Backup management, disaster recovery and crisis management. A backup you have never restored from is a hope, not a measure. What backup and continuity actually require.
  4. Supply chain security. Security requirements for direct suppliers and service providers, in contracts and in practice.
  5. Security in acquisition, development and maintenance of systems, including vulnerability handling and disclosure. Secure development under 21(2)(e).
  6. Assessing effectiveness. Policies and procedures to test whether the other nine work. It's the measure most teams skip; here's the audit loop.
  7. Basic cyber hygiene and training for all staff. What 21(2)(g) requires.
  8. Cryptography and encryption policies. "We have encryption" isn't a policy; why it fails.
  9. HR security, access control and asset management. You can't protect what isn't in your inventory. Access control and assets under 21(2)(i).
  10. Multi-factor or continuous authentication and secured voice, video, text and emergency communications. See MFA requirements and secure communications.

For digital infrastructure and ICT service providers, Implementing Regulation (EU) 2024/2690 turns these ten headings into detailed technical requirements. The full walkthrough of all ten measures covers each one in depth.

Incident reporting: 24 hours, 72 hours, one month

A significant incident is one that causes, or can cause, severe operational disruption or financial loss, or considerable damage to others. Article 23 sets three deadlines, counted from the moment you become aware of it:

DeadlineWhat you submit
Within 24 hoursEarly warning: is it suspected to be malicious, and could it have cross-border impact?
Within 72 hoursIncident notification: an initial assessment of severity and impact, and indicators of compromise where available
Within one month of the notificationFinal report: detailed description, root cause, mitigation applied, cross-border impact

The 24-hour clock is the one that catches organisations out. It runs through weekends. Who decides that an incident is "significant" at 23:00 on a Saturday, and who has the login for the reporting portal? If you can't name both people, you don't have a reporting process yet. More in NIS2 incident reporting deadlines.

Registration

In-scope organisations must register with their competent authority and give at least their name, address, sector, contact details, the member states where they provide services and their IP ranges. The portal and the deadline depend on the country. NIS2 registration deadlines lists them.

The management body (Article 20)

Article 20 moves cybersecurity out of the IT department. The management body must approve the risk-management measures, oversee their implementation and follow training, and its members can be held liable for infringements. Signing a policy once a year doesn't meet that bar. The directive expects the board to understand the risks well enough to make decisions about them. NIS2 and personal board liability goes into what that means for individual directors.

Is NIS2 already law in your country?

Not everywhere. Member states had until 17 October 2024 to transpose NIS2, and most missed that date. The Commission sent letters of formal notice to 23 member states on 28 November 2024 and reasoned opinions to 19 on 7 May 2025. Most of them have since notified their national law.

On 8 July 2026 the Commission referred the four that hadn't, Ireland, Spain, France and the Netherlands, to the Court of Justice of the EU, and asked the Court to impose a lump sum and daily penalties (press release IP/26/1499).

CountryStatus on 28 September 2026
BelgiumNIS2 law of 26 April 2024 in force since 18 October 2024. Most entities had to register by 18 March 2025; essential entities had to meet their first conformity deadline by 18 April 2026
GermanyNIS2UmsuCG in force since 6 December 2025 (BGBl. 2025 I Nr. 301), covering about 29,500 entities according to the BSI. Registration was due 6 March 2026 (§ 33 BSIG); by 30 June 2026, 17,729 companies had registered. Fines up to €10 million and €7 million, or 2% and 1.4% of worldwide turnover for companies with more than €500 million in total turnover; up to €500,000 for registration breaches (§ 65 BSIG)
ItalyD.Lgs. 138/2024 in force since 16 October 2024. Incident notification has been mandatory since 15 January 2026. Entities listed in 2025 must have ACN's base security measures in place by October 2026, 18 months after ACN notified them of their listing; entities listed in 2026 follow on 1 January 2027 and 31 July 2027
PolandAmended National Cybersecurity System Act (UKSC) in force since 3 April 2026. Registration in the Wykaz KSC is due 3 October 2026; risk-management measures and S46 obligations by 3 April 2027
NetherlandsCyberbeveiligingswet in force since 15 August 2026, after the referral
IrelandNational Cyber Security Bill not yet enacted; NIS1 rules still apply
SpainReferred to the Court of Justice; national law not yet complete
FranceReferred to the Court of Justice; national law not yet complete

For every other country, check where each EU country stands, and confirm with the national authority before you plan around a date. Country guides: Ireland, the Netherlands, Spain.

Does a missing national law mean you can wait? We'd argue no, for two reasons. Your customers in countries that have transposed NIS2 already apply its supply-chain duty to you. And when a country does pass its law, the registration deadlines that follow are short. Belgium gave most entities five months, until 18 March 2025. Germany requires registration within three months of falling in scope (§ 33 BSIG); for most entities that deadline passed on 6 March 2026. Italy runs a registration window on the ACN platform every year, from 1 January to 28 February.

The directive itself is also moving. On 20 January 2026 the Commission proposed targeted amendments to simplify compliance; what the proposal changes.

What happens if you don't comply?

Non-compliance exposes essential entities to fines of at least €10 million or 2% of worldwide annual turnover, and important entities to at least €7 million or 1.4%, whichever is higher (Article 34). Those are the minimum ceilings the directive requires; a national law can set them higher.

Fines are rarely the first thing a supervisor reaches for. It can issue binding instructions, order an audit, require you to inform customers of a threat, or publish the infringement. For essential entities it can suspend a certification and temporarily ban a CEO or legal representative from exercising managerial functions. Seven NIS2 penalties that are worse than money covers these, and NIS2 fines in 2026 covers the amounts country by country.

The commercial cost often lands first, though. A supplier that can't show its NIS2 posture loses the tender before any regulator gets involved.

NIS2 vs ISO 27001: does ISO 27001 make you compliant?

Not on its own. ISO 27001 is a voluntary, certifiable standard for an information security management system; NIS2 is a legal duty. The overlap is large: a working ISO 27001 system covers risk analysis, access control, cryptography, supplier security and continuity, which is most of Article 21.

What it doesn't give you by itself:

  • registration with your national authority
  • the 24-hour, 72-hour and one-month reports to your CSIRT or authority
  • the training duty and personal accountability of the management body
  • a scope that matches the services NIS2 covers, rather than the scope you chose for your certificate

Treat ISO 27001 as strong evidence and a head start. NIS2 vs ISO 27001 maps the two clause by clause. If you're also in financial services, read NIS2 vs DORA as well.

Is there a NIS2 certification?

No. The directive has no certificate for organisations; you comply by meeting your national law and showing a supervisor the evidence. Article 24 does let member states require EU-certified ICT products for certain uses, which is a different thing. What Article 24 actually requires.

How to start with NIS2 compliance

Three sources of help build on each other. Your national authority's guidance tells you whether you're in scope and what it expects. A readiness assessment tells you how far you are from that. An external audit or ISO 27001 certificate proves it to others.

National authority guidanceNIS2 readiness assessmentExternal audit or ISO 27001 certification
Question it answersAm I in scope, and what does my regulator expect?Where am I per Article 21 measure, and what do I fix first?Can I prove to customers and regulators that my controls work?
DepthScope, definitions, minimum expectationsStructured questions per measure, weighted scoreIndependent check of evidence
TimeMinutes to readAbout 15 minutes for a first baselineWeeks to months
OutputGuidance, no scoreScore per measure, report, action planCertificate or audit opinion
CostFreeFrom a few hundred eurosDepends on scope and auditor

For most organisations the sensible order is:

  1. Confirm scope. Sector, size, and which country's law applies to you.
  2. Measure the gap against the ten Article 21 measures. Our step-by-step gap analysis guide shows how to do it by hand.
  3. Fix the biggest risks first. Usually incident reporting, backups you have actually restored from, MFA and supplier contracts.
  4. Write it down. NIS2 compliance you can't show is compliance you don't have.
  5. Bring it to the board for approval, and book their training.

NIS2Certify's readiness assessment does step 2 in about 15 minutes: 55 questions mapped to the ten measures of Article 21, answered with yes, partial, no or not applicable, and a PDF report with a score per measure and a prioritised action plan. It's a self-assessment, not a certification. Want a first impression before you commit? Take the free quick scan.

Frequently asked questions

What is NIS2 in simple terms?

NIS2 is an EU law that makes medium and large organisations in 18 critical sectors take ten basic security measures, report serious incidents within 24 hours and make their board responsible for cybersecurity. Each EU country puts it into its own national law.

When did NIS2 come into force?

The directive entered into force on 16 January 2023 and had to be transposed by 17 October 2024. The obligations apply to you from the date your country's national law takes effect, which differs per country.

Who needs to be NIS2 compliant?

Organisations in the 18 sectors of Annexes I and II with 50 or more employees, or with fewer employees but both turnover and balance sheet above €10 million. Some providers, such as DNS service providers and public administration bodies, are in scope at any size.

What is the difference between NIS and NIS2?

NIS2 covers 18 sectors instead of the original seven, uses one size rule instead of letting each country pick its operators, lists ten specific measures, adds supply-chain security, sets tighter reporting deadlines and makes the management body liable.

Does NIS2 apply to small businesses?

Usually not directly. Small businesses fall outside the size rule unless they provide a service that is in scope at any size, such as DNS. But many are pulled in indirectly through the supply-chain requirements of in-scope customers.

Is NIS2 the same as DORA?

No. DORA is an EU regulation for the financial sector that applies directly without national law. Where DORA applies, it takes precedence over NIS2 for banks and other financial entities. NIS2 vs DORA explains the overlap.

Still have a question?

Answers are generated from our articles and are not legal advice. Do not enter personal or confidential data.