Loading…
Loading…
Directive (EU) 2022/2555 (NIS2) is the EU's second-generation network and information security framework, replacing the original NIS1 Directive (Directive (EU) 2016/1148). It was adopted by the European Parliament and the Council on 14 December 2022, published in the Official Journal (OJ L 333) on 27 December 2022, and entered into force on 16 January 2023. Member States were required to transpose the Directive into national law by 17 October 2024 — a deadline that a majority of EU Member States missed (the EU's largest economy, Germany, did not transpose until December 2025).
The core expansion over NIS1 operates on four axes:
Scope expansion (7 → 18 sectors) — NIS2 creates a two-tier classification of covered entities:
heating/cooling, hydrogen), transport (air, rail, water, road), banking, financial-market infrastructure, health, drinking water, wastewater, digital infrastructure (cloud computing services, data centre services, content-delivery networks, trust-service providers, public-electronic-communications-network providers, top-level-domain registries, DNS service providers), ICT service management (managed- service and managed-security-service providers), public administration (central and regional), and space.
management, manufacture of chemicals, manufacture of food, manufacture of medical devices, manufacture of computers and electronics, manufacture of motor vehicles and trailers, manufacture of other transport equipment, digital providers (online marketplaces, online search engines, social-networking-service platforms), research institutions.
The NIS1 scope covered only operators of essential services (OES) in 7 sectors and certain digital service providers. NIS2's 18-sector scope brings an estimated 100,000+ entities across the EU within the binding framework.
Harmonised cybersecurity risk-management obligations — all covered entities must implement proportionate technical and organisational security measures across ten baseline categories: risk analysis and IT security policies; incident handling; business continuity and crisis management; supply-chain security (covering relationships with direct suppliers and service providers); security in network and information systems acquisition, development, and maintenance; policies and procedures to assess the effectiveness of cybersecurity risk-management measures; basic cyber-hygiene practices and cybersecurity training; cryptography and encryption; HR security, access control, and asset management; multi-factor authentication.
Incident-reporting cascade — for significant incidents:
Management accountability — NIS2 (Art. 20) requires management bodies of covered entities to approve cybersecurity risk-management measures, oversee implementation, and complete cybersecurity training. Management bodies can be held personally liable for infringements. This is the single most operationally disruptive provision: it shifts cybersecurity from a technical/IT compliance function to a board-level governance obligation, analogous to what SOX did for financial controls in the US in 2002.
Enforcement and sanctions — essential entities face administrative fines up to EUR 10M or 2% of global annual turnover (whichever is higher); important entities up to EUR 7M or 1.4% of global turnover. National supervisory authorities (designated CSIRTs and competent authorities in each Member State) are empowered to conduct on-site inspections, off-site supervision, targeted security audits, and security scans.
Relationship to the EU cybersecurity regulatory stack — NIS2 operates as the general critical-infrastructure cybersecurity framework. It interfaces with:
financial-sector ICT risk management — financial-sector entities satisfying DORA requirements are considered to satisfy the equivalent NIS2 obligations.
digital elements — product manufacturers in NIS2-covered sectors face both product-level CRA obligations and entity-level NIS2 obligations.
counterpart to NIS2's cyber resilience requirements for critical entities.
coordinating incident response, threat-intelligence sharing, and peer-review support across Member State authorities.
transposing in December 2025 (NIS2UmsuCG, filed 2025-12-06-germany- nis2umsucg), Commission infringement-procedure pressure on non- transposing states has intensified. Expect France, Spain, Italy, the Netherlands, Belgium, Poland, and the Nordic states to complete their national transpositions in 2026.
for multinational companies.** Art. 21(2)(d) requires covered entities to manage cybersecurity risks in supply chains, including assessing suppliers' own cybersecurity practices. This creates contractual flow-down obligations from covered entities to their technology vendors, cloud providers, and managed-service providers regardless of those vendors' own size or NIS2 coverage status.
as essential entities under ICT-service-management — a first in the EU framework, directly bringing major vendors (IBM Security, Accenture, Atos, Orange Cyberdefense, Telindus) within the direct supervisory perimeter.
(24h early warning) are more demanding than comparable US CISA CIRCIA timelines (72h for covered entities). This creates dual-reporting compliance complexity for multinationals operating in both jurisdictions.
provisions are expected to drive a 2026-2028 wave of cyber-governance restructuring across European large-caps: dedicated board cyber committees, CISO elevation to executive committee level, and board cybersecurity training programs comparable to the post-GDPR DPO appointment cycle.
NIS2 maximum fines are below GDPR (4%) but above the NIS1 regime. Combined with DORA (for financial sector) and CRA (for product manufacturers), the EU has built a layered multi-regulator sanction stack where a single incident at a large financial-sector technology firm could theoretically trigger concurrent NIS2, DORA, and CRA investigations.
Italy (ACN), Spain (INCIBE/CCN), and the Netherlands (NCSC) are the four largest outstanding transpositions as of 2026-05.
supply-chain risk assessments for critical ICT products and services are pending; the 5G supply-chain toolbox process is the prototype.
supervisory-authority enforcement for incidents involving personal data — dual-report and possible dual-investigation dynamics are not fully resolved in the current framework.
enlarged entity population and 24-hour notification volumes.