Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
The EU’s NIS2 Directive raises cybersecurity and incident-reporting requirements for organizations providing services in 18 critical sectors. It does not apply to every business in those industries, create one EU-wide compliance certificate, or operate through a single EU regulator: scope and many practical procedures depend on the organization’s services, size, and the national law where it operates.
For a potentially covered organization, the immediate priorities are to check its status under the relevant country’s rules, document cybersecurity risks and supplier dependencies, prepare tested incident procedures, and ensure management can oversee the program. The directive-level transposition deadline was October 17, 2024, but implementation and enforcement details remain country-specific.
What NIS2 is—and what it is not
NIS2 is Directive (EU) 2022/2555, adopted on December 14, 2022, and in force since January 16, 2023. It replaces the original NIS Directive and sets a higher common baseline for cybersecurity across the EU. Member States were required to transpose it into national law by October 17, 2024. Read the directive on EUR-Lex or see the European Commission’s NIS2 overview.
As a directive, NIS2 is implemented through national legislation. The EU framework establishes core duties, but organizations must check the applicable national statute, competent authority, registration process, reporting channel, and any relevant sector rules. The European Commission reported on July 8, 2026, that it had referred Ireland, Spain, France, and the Netherlands to the Court of Justice for failing to notify full transposition measures. That does not make it prudent to assume NIS2 risks or customer obligations disappear in those countries; check current national rules and regulator guidance.
#1 Best Overall
The Commission proposed targeted NIS2 amendments on January 20, 2026, as part of a cybersecurity package. A proposal is not an adopted amendment. Unless and until the legislative process makes changes law, organizations should distinguish proposed changes from operative requirements. See the Commission’s package.
- Not a universal company rule: coverage depends on sector, service, size, entity type, establishment, and national implementation.
- Not a single certification: NIS2 does not create one EU-wide “NIS2 certificate” that automatically proves compliance to every authority.
- Not a product purchase: a security tool can support controls, but it cannot replace governance, risk decisions, supplier oversight, testing, or accountability.
Who may be in scope?
NIS2 covers entities in 18 critical sectors. Many medium-sized and large entities in the listed sectors may be covered, but a sector label alone is not enough to decide. The specific service, entity and group structure, EU establishment, size test, exceptions, and national law matter. Some categories may be covered regardless of ordinary SME thresholds. Use the directive’s Articles 2 and 3 and the relevant country’s guidance rather than relying only on headcount or whether a regulator has contacted the organization.
| Sector group | Examples of activities or entities |
|---|---|
| Energy | Electricity, district heating and cooling, oil, gas, and hydrogen |
| Transport | Air, rail, water, and road transport |
| Banking and financial-market infrastructure | Banks and certain trading or settlement infrastructure |
| Health | Healthcare providers, laboratories, pharmaceutical and medical-supply entities |
| Water | Drinking-water and wastewater providers |
| Digital infrastructure | Cloud services, data centers, content-delivery networks, DNS, top-level-domain registries, and electronic communications |
| ICT service management | Managed service providers (MSPs) and managed security service providers (MSSPs) |
| Public administration and space | Relevant public bodies, subject to national rules and exclusions, and certain entities supporting space-based services |
| Other listed sectors | Postal and courier services, waste management, chemicals, food, selected manufacturing categories, digital providers such as online marketplaces and search engines, and certain research organizations |
This is a guide to the sector categories, not a finding that every business in each industry is regulated. An organization operating across several EU countries may also need to address multiple national authorities, registration procedures, and reporting portals. Record the scope analysis—including the services considered, size and entity assumptions, applicable national rules, and any exclusions—so the decision can be revisited if the business changes.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Essential and important entities
NIS2 distinguishes essential entities from important entities. Both face core cybersecurity risk-management and incident-reporting duties. The distinction mainly affects supervision and enforcement: essential entities generally face stronger proactive oversight, while important entities are commonly supervised more ex post. It is not a compliant/noncompliant distinction. National authorities may maintain registers or require organizations to identify themselves; absence of a regulator letter is not proof that an entity is out of scope.
What covered organizations must do
Article 21 requires proportionate and appropriate technical, operational, and organizational measures to manage cybersecurity risks. In practical terms, this means a working security program—not a policy binder or a single endpoint-security purchase. At a minimum, assess how the organization addresses:
- Risk and governance: risk analysis, security policies, responsibility for decisions, and a way to assess whether controls work.
- Incident handling: detection, escalation, investigation, containment, communication, and lessons learned.
- Continuity and recovery: crisis management, business continuity, backup management, disaster recovery, and tested restoration.
- Supply-chain security: risks from direct suppliers and service providers, including the security practices relevant to the relationship.
- Secure systems and vulnerabilities: security in acquisition, development, and maintenance; vulnerability handling and disclosure.
- People and access: cybersecurity training, basic cyber hygiene, human-resources security, asset management, and access-control policies.
- Technical safeguards: cryptography and encryption where appropriate, and multifactor or continuous authentication where appropriate.
- Communications: secure voice, video, and text communications where relevant.
For digital infrastructure and certain ICT service-management and digital-provider entities, Commission Implementing Regulation (EU) 2024/2690 supplies more detailed EU-level requirements. ENISA’s June 26, 2025 technical implementation guidance includes examples of evidence and mappings to security requirements. These resources can help translate obligations into controls, but organizations still need to determine which rules apply to them.
Rank #3
The incident-reporting clock: 24 hours, 72 hours, and one month
For a significant incident, NIS2’s core reporting sequence is:
Free tools Windows power users keep installed
One-click scans. No signup required.
- Within 24 hours of becoming aware: send an early warning.
- Within 72 hours: submit an incident notification, including an initial assessment of severity and impact.
- During the response: provide intermediate reports when requested or when relevant developments occur.
- Normally within one month after the incident notification: submit a final report. If the incident is still ongoing, submit a progress report and follow the applicable process for later updates.
The report goes to the designated national CSIRT or competent authority. National law and authority procedures can specify the reporting portal, forms, contacts, thresholds, or additional duties. The 24-hour clock is tied to when the entity becomes aware of a significant incident—not necessarily when an attacker first gained access. Set criteria for who makes the significance decision, who can notify authorities, and how the organization records discovery, awareness, escalation, decision, notification, and follow-up times. The legal basis is Article 23 of the directive.
Do not assume another reporting regime automatically satisfies NIS2. A single coordinated incident process can serve multiple laws, but the organization must separately confirm each regime’s trigger, recipient, content, and deadline. NIS2 reporting is also distinct from product-related reporting under the Cyber Resilience Act (CRA): the CRA’s Single Reporting Platform concerns specified manufacturers and product vulnerabilities or incidents, with CRA reporting obligations applying from September 11, 2026. See the Commission’s CRA reporting information and ENISA’s platform overview.
Management and board responsibilities
Under Article 20, management bodies must approve and oversee cybersecurity risk-management measures, and members must undertake cybersecurity training. National law determines the specific liability and enforcement mechanisms; do not assume NIS2 imposes identical personal fines on every director throughout the EU. The directive’s text sets out the EU-level duties.
Board oversight should produce decisions and evidence, not just meeting minutes. Useful questions include:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute- Which services are essential to customers, the economy, or public safety, and which systems support them?
- Which suppliers, cloud services, identity providers, and communications links are critical dependencies?
- What recovery time and recovery point are acceptable, and when was restoration last tested?
- Who can decide that an incident is significant and authorize a regulator notification?
- How does management know supplier controls are monitored, and which high risks have been formally accepted?
Enforcement and possible penalties
NIS2 requires effective, proportionate, and dissuasive sanctions. At directive level, Member States must provide maximum administrative fine levels of at least:
Best Value
- Essential entities: €10 million or 2% of worldwide annual turnover, whichever is higher.
- Important entities: €7 million or 1.4% of worldwide annual turnover, whichever is higher.
These are minimum maximum levels required by the directive—not a prediction of the fine any particular organization will receive. National law sets the procedure and actual sanctions. The outcome can depend on the infringement, duration, intent or negligence, damage, prior violations, cooperation, and other factors. Authorities may also have powers to issue binding instructions, require deficiencies to be remedied, conduct audits or inspections, access evidence, and in serious cases order measures such as temporary suspension of certifications or services. See Articles 32–34 and check the applicable national law.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.A practical NIS2 readiness plan
- Decide and document scope. Identify legal entities, EU establishments, services, sector classifications, size, and relevant national rules. Check whether a group company, branch, or particular supplier has a separate status. Record the reasoning, including uncertainty and exclusions.
- Map critical services and dependencies. Inventory regulated services and the applications, infrastructure, privileged accounts, identity providers, cloud and hosting providers, DNS, telecom, MSPs, MSSPs, SaaS, data centers, data flows, and external dependencies they rely on. Set recovery priorities and objectives.
- Assess control gaps. Map existing measures to Article 21 themes. Classify each as implemented and evidenced, implemented but untested, partial, missing, supplier-dependent, or not applicable with a reason. Prioritize risks to critical services rather than treating every gap as equal.
- Make incident readiness operational. Define significant-incident criteria, a 24-hour decision and escalation path, current authority and CSIRT contacts, notification templates, and a timestamped incident log. Exercise the process with legal, communications, executives, IT, and relevant suppliers; test whether the team can assemble an initial assessment inside 72 hours.
- Test resilience and technical controls. Test backup restoration, segment critical systems, secure privileged access with multifactor authentication where appropriate, set vulnerability-management timelines, maintain asset and software inventories, centralize risk-appropriate logs, and exercise crisis communications.
- Govern suppliers and group services. Review contracts for security requirements, incident escalation, cooperation and evidence access, subcontractors, vulnerability disclosure, continuity, exit and transition support, data access, and audit or assurance rights. A covered organization cannot outsource its legal accountability to a cloud provider or MSP.
How NIS2 differs from other rules and frameworks
| Framework | What it addresses | How it relates to NIS2 |
|---|---|---|
| NIS1 | The earlier EU network and information security regime | NIS2 replaces it and broadens sector coverage and obligations. |
| GDPR | Personal-data protection | A cyber incident may trigger both laws. Their purposes, thresholds, recipients, and reporting timelines differ; assess each separately. |
| DORA | Digital operational resilience for financial entities | It is a sector-specific regime. Financial entities should assess how DORA and NIS2 interact under applicable rules, not assume one replaces every duty under the other. |
| Cyber Resilience Act | Cybersecurity requirements for products with digital elements | It focuses on products and manufacturers, with separate product-related reporting mechanics. It is not a substitute for NIS2 duties of covered entities. |
| ISO 27001 and NIST CSF | Security-management and risk frameworks | They can organize controls and evidence, but certification or use of a framework does not by itself establish compliance with NIS2 or national law. |
Keep three questions separate: Is the entity legally in scope? Are its security controls effective and evidenced? Does it hold a particular certification or assurance? A positive answer to one does not automatically answer the others.
Choosing how to implement the program
Organizations can build the program internally, use compliance software, contract managed security services, or bring in legal and security consultants. These options solve different problems and are often combined:
- DIY: Suits organizations with capable internal security, legal, and compliance staff. It offers direct control but requires time, expertise, and sustained ownership.
- Compliance or GRC platform: Can organize policies, evidence, risk registers, supplier questionnaires, tasks, and mappings. Verify the plan’s NIS2 coverage and relevant national-law support. A platform cannot make scope decisions, negotiate contracts, implement controls, or guarantee regulatory acceptance.
- MSP/MSSP or managed security: Can address monitoring, response, vulnerability management, or staffing gaps. Define escalation, evidence preservation, reporting-clock support, and who makes or files regulatory notifications. Outsourcing does not transfer the covered entity’s accountability.
- Legal and security consulting: Particularly useful for complicated scope questions, country-specific interpretation, board governance, high-risk remediation, and regulator engagement. Confirm deliverables, independence, and whether implementation is included.
When evaluating a provider, ask whether its work reflects the applicable national implementation or only a generic NIS2 mapping; whether evidence is dated, auditable, and shows controls operating; how it supports incident timestamps and notification workflows; which assets, suppliers, subsidiaries, and dependencies it can cover; what integrations and implementation help are included; where evidence is stored and how it is protected; and whether you can export records and audit history if you leave. Compare total cost, including remediation, testing, security services, legal review, licenses, and staff time. Treat claims of guaranteed compliance cautiously.
Quick Recap
Common situations that need a closer check
- Small organization: Fewer than 50 employees does not always settle the question. Some categories can be covered regardless of ordinary SME thresholds; check the directive and national law.
- Supplier to a covered customer: You may not be directly regulated, but customers can impose stronger security questionnaires, audit requests, incident-notification terms, and evidence requirements through contract.
- Already ISO 27001-certified: Reuse relevant governance and evidence, but perform a crosswalk to NIS2 and national requirements rather than presuming equivalence.
- Incident reporting under another law: Coordinate processes, but verify each law’s trigger, recipient, content, and timing separately.
- Country with delayed transposition: Do not treat delay as a safe harbor. Review available national measures, regulator notices, customer commitments, and obtain appropriate local legal advice.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

