Back to Knowledge Base
Knowledge Base · implementation

NIS2 implementation guide: 8 steps for essential and important entities

7 June 2026 6 min read NIS2

NIS2 is in force. Essential and important entities must comply now. This guide covers the 8 implementation steps: scope confirmation, risk assessment, Article 21 measures, and incident notification.

The short answer

NIS2 has been in force since October 2024. Essential and important entities across 18 sectors must comply now — there is no further transitional period. The eight implementation steps below cover scope confirmation, governance, risk assessment, Article 21 security measures, supplier assessment, incident notification, and evidence management.

Step 1 — Confirm your NIS2 scope

NIS2 applies if you meet both of these conditions:

Sector test (Annex I or II):

Size test:

Micro-enterprises (< 10 employees, < €2M turnover) are generally exempt unless they are critical infrastructure operators or DNS/TLD/cloud/data centre providers.

→ NIS2 Applicability Checker — 2-minute scope confirmation

  • Essential entities (Annex I): energy, transport, banking, financial market infrastructure, health, drinking water, wastewater, digital infrastructure, ICT service management (B2B), public administration, space
  • Important entities (Annex II): postal/courier services, waste management, chemical manufacturing/distribution, food production/processing/distribution, manufacturing of medical devices/computers/electrical equipment/machinery/motor vehicles/other transport, digital providers (online marketplaces, online search engines, social networks), research organisations
  • Essential: medium enterprise or above (≥250 employees OR ≥€50M turnover AND ≥€43M balance sheet) or critical infrastructure regardless of size
  • Important: small enterprise or above (≥50 employees OR ≥€10M turnover AND ≥€10M balance sheet)

Step 2 — Identify your competent authority and registration obligation

Each Member State has designated national competent authorities (NCAs) for each sector. Some Member States require in-scope entities to register.

Actions:

  • Identify your sector's NCA in each Member State where you operate
  • Check whether registration or self-identification is required in those Member States
  • Identify your national CSIRT (Computer Security Incident Response Team) for incident notification
  • Note: essential entities may be subject to proactive supervision; important entities face reactive supervision (post-incident)

Step 3 — Appoint governance and accountability

NIS2 Art. 20 requires management bodies to approve, oversee, and be accountable for cybersecurity risk management measures. Non-compliance by management can result in personal liability.

Actions:

Key point: NIS2 Art. 20 creates personal liability for management body members who fail to ensure compliance. This is a significant change from previous frameworks.

  • Board/management body must formally approve the organisation's cybersecurity risk management approach
  • Designate a cybersecurity-responsible senior executive (CISO or equivalent)
  • Ensure management receives regular cybersecurity training (Art. 20(2))
  • Document the governance structure and approval chain for security decisions

Step 4 — Conduct a cybersecurity risk assessment

NIS2 Art. 21(1) requires entities to take "appropriate and proportionate technical, operational and organisational measures" based on a risk assessment. The assessment must consider:

Format: No mandated format. ISO 27005, NIST SP 800-30, or ENISA's threat landscape methodology are accepted approaches. The assessment must be entity-specific, not a generic framework application.

Update trigger: Material change to the operational environment, significant incident, or annual review minimum.

  • All risks to network and information systems
  • The impact of incidents on service continuity
  • The entity's size, exposure, and criticality
  • The likelihood of incidents and their potential impact on society and the economy

Step 5 — Implement the 10 Article 21 security measures

NIS2 Art. 21(2) requires all in-scope entities to implement at minimum these 10 categories of measures:

| # | Measure | Art. 21(2) ref |

|---|---|---|

| 1 | Policies on risk analysis and information system security | (a) |

| 2 | Incident handling | (b) |

| 3 | Business continuity, backup management, disaster recovery, crisis management | (c) |

| 4 | Supply chain security (security of relationships with direct suppliers and service providers) | (d) |

| 5 | Security in network and information systems acquisition, development and maintenance, including vulnerability handling and disclosure | (e) |

| 6 | Policies and procedures to assess the effectiveness of cybersecurity risk management measures | (f) |

| 7 | Basic cyber hygiene practices and cybersecurity training | (g) |

| 8 | Policies and procedures regarding the use of cryptography and, where appropriate, encryption | (h) |

| 9 | Human resources security, access control policies, and asset management | (i) |

| 10 | Use of multi-factor authentication or continuous authentication solutions, secured voice/video/text communications, and secured emergency communication systems | (j) |

Proportionality: The measures must be proportionate to the size of the entity, the risk exposure, and the potential societal and economic impact of an incident.

Step 6 — Implement incident notification workflows

NIS2 Art. 23 sets strict timelines for notifying significant incidents:

| Stage | Deadline | Content |

|---|---|---|

| Early warning | Within 24 hours of awareness | Initial notification that a significant incident has occurred; indication of whether it may be caused by unlawful or malicious acts |

| Incident notification | Within 72 hours of awareness | Updated assessment: severity, impact, indicators of compromise (if available) |

| Intermediate report | On request of CSIRT or NCA | Progress update on handling |

| Final report | Within 1 month of notification | Full description, type, root cause, cross-border impact, measures taken |

What is a "significant incident"? An incident is significant if it:

Actions:

  • Has caused or could cause severe operational disruption or financial loss to the affected entity; or
  • Has affected or could affect other natural or legal persons by causing considerable material or non-material damage
  • Document your internal incident classification criteria for "significant"
  • Build and test the early warning and notification workflow to national CSIRT and NCA
  • Maintain a 24/7 contact point for incident reporting (or a defined escalation chain)
  • Log all incidents, including those below the "significant" threshold

Step 7 — Address supply chain security

NIS2 Art. 21(2)(d) requires entities to assess the security practices of their direct suppliers and service providers. For critical services, this includes assessing the suppliers' suppliers.

Minimum actions:

Note: Supply chain security under NIS2 overlaps with CRA Annex I Part I §2(3) for manufacturers. If dual-regulated, one supplier security programme can address both.

  • Inventory critical third-party suppliers and ICT service providers
  • Include NIS2-aligned security clauses in new supplier contracts
  • Request evidence of security practices (ISO 27001 certification, SOC 2 reports, or equivalent)
  • Assess software supply chain risk — software components, open-source dependencies, update mechanisms

Step 8 — Maintain evidence and documentation

NIS2 does not specify a retention period for compliance documentation, but market practice and audit readiness require:

  • Risk assessment — dated, signed, version-controlled; updated annually or on material change
  • Security policy documentation — covering all 10 Art. 21(2) categories; approved by management body
  • Incident log — all incidents, significant and below-threshold; dates, classification, actions taken, notification records
  • Supplier security assessments — evidence of supplier due diligence; updated on contract renewal or significant change
  • Training records — management cybersecurity training (Art. 20(2)); employee cyber hygiene training (Art. 21(2)(g))
  • Notification records — copies of all CSIRT/NCA notifications submitted; acknowledgements received

NIS2 × CRA: dual implementation efficiency

If you are also subject to CRA, significant evidence overlap exists — see NIS2 × CRA overlap. Key shared artefacts:

  • SBOM — satisfies both CRA Annex I and NIS2 Art. 21(2)(e) supply chain requirement
  • CVD policy — satisfies both CRA Annex I Part II §1 and NIS2 Art. 21(2)(e)
  • Risk assessment — can be structured to reference both frameworks
  • Incident response plan — one plan with two notification tracks (CSIRT for NIS2; ENISA for CRA Art. 14)

Key dates

| Date | Event |

|---|---|

| October 2024 | NIS2 transposition deadline — Member States must have transposed; entities must comply |

| Now | NIS2 is in force and enforceable |

| 11 September 2026 | CRA Art. 14 applies (relevant for dual-regulated entities) |

| 11 December 2027 | Full CRA enforcement |

Tools on NexCyber

This page provides regulatory guidance for informational purposes. It is not legal advice. NIS2 transposition varies by Member State — check your national competent authority's guidance for jurisdiction-specific requirements. For compliance decisions, consult a qualified legal adviser.

NexCyber — EU Market Access Compliance Platform

  • NIS2 Applicability Checker — confirm scope in 2 minutes
  • 144-obligation gap assessment — maps NIS2, CRA, DORA, AI Act and RED in one assessment
  • NIS2 × CRA overlap guide

This is an educational explainer. For the canonical regulation reference, see the dedicated NIS2 page — or run an assessment to see how it applies to your product.