Back to Knowledge Base
Knowledge Base · fundamentals

What is NIS2: who it covers, the ten measures, and why the board is named

20 May 2026 8 min read NIS2

NIS2 — Directive (EU) 2022/2555 — is the EU's baseline cybersecurity law for organisations that operate critical or important services. It replaced the 2016 NIS Directive and had to be transposed into national law by 17 October 2024.

The short answer

NIS2 — Directive (EU) 2022/2555 — is the EU's baseline cybersecurity law for organisations that operate critical or important services. It replaced the 2016 NIS Directive and had to be **transposed into national law by 17 October 2024**.

It widened the previous regime in three directions at once: **more sectors**, **more entities within each sector**, and **personal accountability for management bodies**.

**The single most important thing to understand about NIS2 is that it is a Directive, not a Regulation.** It does not bind you directly. **The national law of each Member State where you operate binds you** — and those laws differ in registration procedure, supervisory authority, deadlines and penalty ceilings. An organisation operating in five Member States faces five transpositions of the same text, not one.

Anyone quoting "the NIS2 requirement" without naming a country is quoting the floor, not the rule that applies.

Who is in scope

Scope is determined by **sector** and then by **size**.

**Annex I — sectors of high criticality:** energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management (business-to-business), public administration, and space.

**Annex II — other critical sectors:** postal and courier services, waste management, manufacture and distribution of chemicals, production and distribution of food, manufacturing (including medical devices, computer and electronic products, machinery and motor vehicles), digital providers, and research.

**The size rule then sorts entities into two supervisory classes:**

``` essential large entities in an Annex I sector important medium-sized entities in Annex I large and medium-sized entities in Annex II ```

**Some entities are in scope regardless of size** — among them DNS service providers, top-level domain name registries, trust service providers and providers of public electronic communications networks or services. Size is not a defence for these.

**The reach that catches most companies by surprise**

**Article 21(2)(d) requires in-scope entities to manage the security risks of their supply chain**, including the security of their direct suppliers.

This does not put suppliers in scope. **It puts NIS2 into their contracts.** A small software vendor selling to a hospital group, an energy utility or a logistics operator will be asked to evidence its own security practices — not because the law reaches it, but because the law reaches its customer, and the customer has to answer for it.

For most technology companies, **this is how NIS2 arrives: through a procurement questionnaire, not through a regulator.**

The ten measures — Article 21

Article 21(2) sets out a minimum set of measures, to be implemented on a risk-based and proportionate basis:

1. **Policies on risk analysis and information system security** 2. **Incident handling** 3. **Business continuity** — backup management, disaster recovery, crisis management 4. **Supply chain security**, including the security of direct suppliers 5. **Security in network and information systems acquisition, development and maintenance**, including vulnerability handling and disclosure 6. **Policies and procedures to assess the effectiveness** of the measures themselves 7. **Basic cyber hygiene practices and cybersecurity training** 8. **Policies on the use of cryptography and, where appropriate, encryption** 9. **Human resources security, access control policies and asset management** 10. **Multi-factor or continuous authentication, secured voice, video and text communications, and secured emergency communication systems**

**Measure 6 is the one most programmes omit.** It requires you to assess whether your measures actually work — which means a review with a date, a scope and a result, not an annual assertion that the policy exists.

Reporting: three stages, and the clock is short

Article 23 applies to **significant incidents** — broadly, those causing or capable of causing severe operational disruption or financial loss, or affecting others through considerable material or non-material damage.

``` 24 hours early warning 72 hours incident notification — initial assessment, severity, indicators of compromise 1 month final report — description, root cause, mitigation, cross-border impact ```

An **intermediate report** may be requested, and where an incident is still ongoing at the one-month mark, a progress report is submitted with the final report following after the incident is handled.

Entities must also, where appropriate, **notify recipients of their services** of incidents likely to adversely affect the service.

**Twenty-four hours starts from awareness, not from resolution.** The practical consequence is that the early warning must be sendable while facts are still incomplete — which is a decision-rights problem more than a technical one. If the person who can authorise a regulatory notification is not reachable within a day, the deadline is already lost.

Management liability — Article 20

This is the change that moved NIS2 from a security topic to a board topic.

**Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements.** Members are also required to follow training, and entities are encouraged to offer similar training to staff.

**Approval must be evidenced.** A minuted decision naming the framework and the date it was approved is the artefact — and the same minute serves as evidence under DORA Article 5 for any group entity that also falls under DORA.

Penalties, and the supervision that precedes them

Article 34 sets national fine ceilings as the **higher** of a fixed amount or a percentage of **total worldwide annual turnover**:

``` essential entities at least EUR 10 000 000 or 2 % important entities at least EUR 7 000 000 or 1.4 % ```

**The classes differ more in supervision than in fines.** Essential entities are subject to **ex ante** supervision — regular audits, targeted security scans, information requests that do not require a triggering event. Important entities are supervised **ex post**, when evidence suggests non-compliance.

Authorities can also suspend a certification or authorisation, and temporarily prohibit an individual from exercising managerial functions in an essential entity.

When NIS2 gives way — Article 4

Where a sector-specific EU act imposes cybersecurity or incident-reporting requirements **at least equivalent in effect**, that act applies instead of the corresponding NIS2 provisions.

**DORA is the working example.** A bank does not report the same ICT incident twice under two regimes: DORA governs where it applies, and NIS2 continues to govern what DORA does not reach. The determination is made obligation by obligation, not entity by entity — which is why the two instruments are best mapped side by side rather than chosen between.

What to establish first

1. **Identify every Member State where you are established or provide services**, and read the transposition for each. The Directive is the floor; the national act is the rule. 2. **Determine essential or important**, because the supervisory regime follows from it. 3. **Minute the management body's approval** of the risk-management measures. It is the cheapest artefact in the programme and the first one an auditor asks for. 4. **Build the 24-hour path before the 72-hour content.** The early warning is a decision process; the notification is a document. 5. **Answer the supply-chain question before a customer asks it.** If you sell into Annex I or Annex II sectors, the questionnaire is coming regardless of your own scope.

Tools available on NexCyber

Further reading

Essential versus important entitiesNIS2 incident reporting timelines in detailNIS2 implementation guide — eight stepsDORA × NIS2 — which instrument governs when both applyNIS2 × CRA — what overlaps and what does notOne evidence set across five EU regulationsNIS2 regulation overview

*This is regulatory information, not legal advice, and nothing here constitutes a compliance guarantee. NIS2 is a Directive: the binding text is the national transposition in each Member State where you operate, and those texts differ. Verify against the applicable national law and consult your competent authority or a qualified adviser.*

This is an educational explainer. For the canonical regulation reference, see the dedicated NIS2 page — or run an assessment to see how it applies to your product.