Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

NIS2 directive explained - scope, security requirements, incident reporting and penalties

NIS2 Directive Explained: A Complete Compliance Guide

The NIS2 Directive is the EU’s most far-reaching cybersecurity law to date. Formally Directive (EU) 2022/2555, it dramatically expands the scope of the original NIS Directive, raising security requirements across thousands of organizations in critical sectors and making senior management personally accountable. This guide is your complete introduction to what NIS2 requires and how to comply.

NIS2 directive explained - scope, security requirements, incident reporting and penalties

Below we cover what the NIS2 Directive is, who it applies to, the security and reporting requirements, governance and penalties, deadlines, and how to prepare.

What is the NIS2 Directive?

NIS2 is an EU directive that sets a high, common level of cybersecurity across the Union. It replaces the 2016 NIS Directive, widening the sectors covered, tightening security and incident-reporting obligations, and introducing tougher enforcement. Because it is a directive, each member state transposes it into national law — so the precise details can vary by country, but the core requirements are consistent. The aim is straightforward: make the organizations that underpin Europe’s economy and society genuinely resilient to cyber threats.

Who does the NIS2 Directive apply to?

NIS2 divides in-scope organizations into essential and important entities across a broad list of sectors — including energy, transport, banking, financial market infrastructure, health, drinking and waste water, digital infrastructure, ICT service management, public administration, postal services, waste management, chemicals, food, manufacturing, and digital providers. In general, medium and large organizations (broadly, 50 or more staff or significant turnover) in these sectors are covered, though some are included regardless of size. The expansion from the original NIS Directive is dramatic — many organizations are in scope for the first time.

NIS2 security requirements

NIS2 requires in-scope entities to implement appropriate and proportionate technical, operational, and organizational measures to manage cybersecurity risk. These include policies on risk analysis and information security, incident handling, business continuity and crisis management, supply-chain security, security in the acquisition and development of systems, vulnerability handling, the use of cryptography, access control and asset management, and multi-factor authentication. The emphasis is on an all-hazards, risk-based approach that is evidenced and continually maintained.

NIS2 incident reporting requirements

NIS2 introduces a staged incident-reporting regime. For a significant incident, entities must submit an early warning within 24 hours, a fuller incident notification within 72 hours, and a final report within one month. This demands a documented incident-management process capable of detecting, assessing, and reporting within tight deadlines — something best prepared long before an incident occurs.

Governance and management accountability

A defining feature of NIS2 is executive accountability. Management bodies must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for failures. Senior managers are also expected to undergo cybersecurity training. This elevates NIS2 from an IT issue to a board-level governance obligation.

Penalties and the NIS2 deadline

Enforcement is significant. Essential entities can face administrative fines of up to €10 million or 2% of global annual turnover, and important entities up to €7 million or 1.4%, alongside supervisory measures. The transposition deadline for member states was 17 October 2024, meaning national NIS2 laws are now in force. In-scope organizations should treat compliance as a current obligation, not a future project.

How to prepare for NIS2

Start by confirming whether you are an essential or important entity and in which member states you are regulated. Then run a gap analysis against the NIS2 security measures, build the missing policies and controls, establish an incident-reporting process that meets the 24/72-hour timelines, and secure documented board oversight. Supply-chain security deserves particular attention, as it is both a NIS2 requirement and a common weak point. A mapped toolkit turns this into a structured programme rather than a blank page.

Meet NIS2 the fast way.

Our NIS2 Toolkit delivers the risk-management policies, incident-reporting procedures, supply-chain controls, and governance records NIS2 demands — mapped to the directive and editable in Word and Excel.

Explore the NIS2 Toolkit →

Frequently asked questions

What is the NIS2 Directive in simple terms?

NIS2 is an EU law that raises cybersecurity across critical sectors, requiring in-scope organizations to implement risk-management measures, report incidents quickly, and hold senior management accountable.

Who does NIS2 apply to?

Essential and important entities in sectors such as energy, transport, health, digital infrastructure, banking, and public administration — generally medium and large organizations, with some included regardless of size.

What is the NIS2 deadline?

Member states had to transpose NIS2 into national law by 17 October 2024, so NIS2 obligations are now in force and compliance is expected.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.