The NIS2 Directive (Directive (EU) 2022/2555) is the EU's new baseline for cybersecurity in critical and important sectors. It covers most medium-sized and large organizations in 18 sectors listed in its two annexes, plus some providers regardless of size. In-scope organizations must put specific risk-management measures in place, report significant incidents on a 24-hour, 72-hour and one-month timeline, and make their management bodies accountable for cybersecurity. Member states have until October 17, 2024 to write NIS2 into national law, and they must apply those rules from October 18, 2024.

Here's who is in scope, how essential and important entities differ, and what the core obligations look like.

What is the NIS2 Directive?

NIS2 replaces the original NIS Directive (Directive (EU) 2016/1148), which left each country to decide which operators it covered. The results were uneven. NIS2 widens the list of sectors, adds a size-based rule for who is in, and tightens security, reporting and enforcement.

The Directive entered into force on January 16, 2023. Because it's a directive, it doesn't bind your organization directly. Each member state must transpose it by October 17, 2024 and apply those measures from October 18, 2024, the day the original NIS Directive is repealed.

NIS2 sets a minimum, and member states can go further. The national law in each country where you operate is what you'll ultimately comply with. The full text is on EUR-Lex.

Who does NIS2 apply to?

Two tests decide scope: sector and size. A set of exceptions then pulls in certain entities regardless of size.

The sector test: Annex I and Annex II

Annex I lists 11 "sectors of high criticality":

  • Energy: electricity, district heating and cooling, oil, gas, hydrogen
  • Transport: air, rail, water, road
  • Banking and financial market infrastructures
  • Health
  • Drinking water and waste water
  • Digital infrastructure: internet exchange points, DNS providers, TLD registries, cloud, data centers, content delivery networks, trust services, public electronic communications
  • ICT service management (business-to-business): managed service providers and managed security service providers
  • Public administration
  • Space

Annex II lists 7 "other critical sectors":

  • Postal and courier services
  • Waste management
  • Manufacture, production and distribution of chemicals
  • Production, processing and distribution of food
  • Manufacturing: medical devices, computer and electronic products, electrical equipment, machinery, motor vehicles, other transport equipment
  • Digital providers: online marketplaces, online search engines, social networking platforms
  • Research

Within each sector, the annexes define the specific entity types covered. For IT readers, the big one is ICT service management. If you run an MSP or MSSP of meaningful size, NIS2 almost certainly reaches you.

The size test

NIS2 applies to entities in those sectors that qualify as medium-sized enterprises, or exceed the medium-sized ceilings, under Commission Recommendation 2003/361/EC. Micro and small enterprises are out unless an exception applies.

A small enterprise under the Recommendation has fewer than 50 staff and annual turnover or balance sheet total of no more than €10 million. So you're likely over the line if you have 50 or more employees, or if both turnover and balance sheet exceed €10 million. The Recommendation's rules on linked and partner enterprises can pull group figures in, so a small subsidiary of a large group may not count as small.

When size doesn't matter

Article 2 brings some entities into scope regardless of size, including:

  • Public electronic communications providers, trust service providers, TLD registries, DNS service providers and domain name registration services
  • The sole provider in a member state of a service essential to critical societal or economic activities
  • Entities whose disruption could significantly affect public safety, security or health, or create significant systemic risk
  • Central government public administration entities
  • Critical entities under the Critical Entities Resilience Directive (Directive (EU) 2022/2557)

By April 17, 2025, member states will have to establish a list of essential and important entities. Expect national authorities to ask in-scope organizations to register with contact details, IP ranges, sector and the member states where they provide services.

What about financial entities and DORA?

Article 4 says that where a sector-specific EU law imposes at least equivalent requirements, that law applies instead. For banks and other financial entities, that's the Digital Operational Resilience Act (Regulation (EU) 2022/2554), which will govern their ICT risk management and incident reporting.

Essential vs. important entities: what's the difference?

Every in-scope organization is either essential or important. The obligations in Articles 20, 21 and 23 are the same for both. Supervision and fine levels are what differ.

Essential entities are mainly large enterprises in Annex I sectors, plus certain providers regardless of size (such as qualified trust service providers, TLD registries and DNS providers), medium-sized public electronic communications providers, central government entities, and any entity a member state designates as essential. Important entities are every other in-scope entity, which means medium-sized Annex I entities and all in-scope Annex II entities unless designated otherwise.

Essential entities Important entities
Supervision Proactive (ex ante) and reactive Reactive (ex post), triggered by evidence of non-compliance
Typical tools On-site inspections, regular and ad hoc audits, security scans Similar tools, used after the fact
Maximum fines (at least) €10M or 2% of worldwide turnover €7M or 1.4% of worldwide turnover

What does Article 21 require?

Article 21 requires "appropriate and proportionate technical, operational and organisational measures" to manage risks to your network and information systems. The measures follow an all-hazards approach, covering physical risks as well as cyber threats. Proportionality depends on your exposure, size, the likelihood and severity of incidents, the state of the art and cost.

Article 21(2) sets ten minimum areas:

  1. Policies on risk analysis and information system security
  2. Incident handling
  3. Business continuity, such as backup management, disaster recovery and crisis management
  4. Supply chain security, including relationships with direct suppliers and service providers
  5. Security in acquiring, developing and maintaining systems, including vulnerability handling and disclosure
  6. Policies and procedures to assess whether these measures are effective
  7. Basic cyber hygiene practices and cybersecurity training
  8. Policies on cryptography and, where appropriate, encryption
  9. Human resources security, access control policies and asset management
  10. Multi-factor or continuous authentication, and secured voice, video, text and emergency communications, where appropriate

None of this is new to a mature program. What changes is that it becomes a legal minimum, and you'll need evidence that each measure is in place and working.

Supply chain security reaches beyond NIS2's scope. Article 21(3) asks entities to consider each direct supplier's vulnerabilities, product quality and secure development practices. Small suppliers outside the annexes should expect more questionnaires, audit rights and contract clauses from customers who are in scope.

The Commission must also adopt implementing acts by October 17, 2024 setting technical requirements for certain digital entities, including cloud providers, data centers, MSPs and MSSPs.

What are the NIS2 incident reporting deadlines?

Article 23 requires notification of any significant incident to the national CSIRT or competent authority. An incident is significant if it has caused, or could cause, severe operational disruption or financial loss for the entity, or considerable material or non-material damage to others.

Stage Deadline What it covers
Early warning Within 24 hours of becoming aware Whether unlawful or malicious acts are suspected, and any cross-border impact
Incident notification Within 72 hours of becoming aware Initial assessment of severity and impact, and indicators of compromise where available
Intermediate report On request Status updates
Final report One month after the incident notification Root cause or threat type, mitigation measures, cross-border impact

If the incident is still ongoing at the final report deadline, you submit a progress report instead, then a final report within one month of handling the incident. You must also tell recipients of your services, without undue delay, about significant incidents likely to affect them.

The 24-hour clock starts when you become aware, not when the investigation ends. Your triage process needs a quick, documented way to decide whether an event is significant. Reporting other incidents, threats and near misses is voluntary.

What does NIS2 mean for management bodies?

Article 20 makes cybersecurity a leadership duty. Management bodies must approve the Article 21 measures, oversee their implementation, and can be held liable for infringements. Their members must also follow cybersecurity training.

For essential entities, Article 32(5) goes further. If other enforcement steps fail, authorities can seek a temporary ban on a person at CEO or legal representative level exercising managerial functions in that entity. The details of liability will depend on national law.

What are the penalties under NIS2?

For infringements of Article 21 or 23, member states must set maximum fines of at least:

  • Essential entities: €10 million or 2% of total worldwide annual turnover, whichever is higher
  • Important entities: €7 million or 1.4% of total worldwide annual turnover, whichever is higher

Turnover is measured at the level of the undertaking the entity belongs to, which can mean the group. National law can set higher caps. Authorities also get binding instructions, orders to fix deficiencies by a deadline and, where national law provides, periodic penalty payments.

Frequently asked questions

Does NIS2 apply to companies outside the EU?

It can. NIS2 covers entities that provide services or carry out activities in the EU. Certain digital providers, such as cloud, data center and managed service providers, that offer services in the EU without being established there must designate an EU representative.

Will NIS2 be the same in every EU country?

No. It's a minimum-harmonization directive, so national laws can add requirements, designate more entities or set higher fines. Track each transposition separately.

Do we have to report every security incident?

No. Mandatory reporting covers significant incidents only. You still need a fast, documented way to assess significance.

Next steps

With the October deadline approaching, a practical sequence looks like this:

  1. Confirm scope country by country. Check sector, size (including group figures) and exceptions, and follow each national transposition.
  2. Work out your classification. Essential or important status drives supervision and fine levels.
  3. Run a gap assessment against Article 21. Map controls and evidence to the ten areas and prioritize gaps.
  4. Build and test a reporting runbook. Decide who judges significance, who files the 24-hour early warning, and which national channels you'll use.
  5. Brief and train the management body. Put approval of risk-management measures on the leadership agenda.
  6. Tighten supplier management. Rank direct suppliers by criticality and update contract security requirements.

NIS2 obligations will ultimately come from national law, and this post isn't legal advice. Confirm the specifics for your organization with counsel.