Key takeaways
- NIS2 is Directive (EU) 2022/2555. It entered into force on 16 January 2023, member states had to apply their transposing measures from 18 October 2024, and it repealed the original NIS Directive on the same date.
- Annex I lists 11 high-criticality sectors and Annex II lists 7 further sectors. Entities of a listed type that are medium-sized or larger are in scope, plus several categories that are covered regardless of size.
- Article 21 sets ten minimum risk-management measures. Article 23 sets the reporting clock: early warning within 24 hours, incident notification within 72 hours, and a final report within one month.
- Management bodies must approve the measures, oversee their implementation, can be held liable for infringements, and are personally required to follow training under Article 20.
- National law must allow maximum fines of at least EUR 10 million or 2 percent of the group's total worldwide annual turnover for essential entities, whichever is higher, and at least EUR 7 million or 1.4 percent for important entities. Those are floors for the national ceiling, not the size of a typical fine.
What is the NIS2 Directive?
The NIS2 Directive is Directive (EU) 2022/2555, which sets a raised common baseline for cybersecurity risk management and incident reporting across essential and important sectors in the European Union. It entered into force on 16 January 2023 and replaced the 2016 NIS Directive with effect from 18 October 2024. The old directive covered too few operators and was applied too inconsistently between member states.
NIS2 covers far more organizations than its predecessor, because scope now follows a size-and-sector rule rather than each member state nominating individual operators. It harmonizes the substance, so the same ten measures and the same reporting clock apply wherever an entity sits. And it attaches consequences at board level, through personal liability and training obligations for management bodies. The full text is available in the EU legal database.
NIS2 is a directive, not a regulation, so it does not bind companies directly. What binds you is your own member state's transposing law, which may go further than the directive in places. Treat everything below as the floor rather than the finished obligation, and confirm the detail in the national law that applies to you.
Where transposition stands in 2026
Member states had to adopt and publish their transposing measures by 17 October 2024 and apply them from 18 October 2024. Most missed that deadline. The European Commission opened infringement proceedings, and on 8 July 2026 it referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union over their outstanding transposition.
For a company, the practical consequence cuts two ways. In the member states that have transposed, including Germany, the obligations are already enforceable and the supervisory authorities are already operating. In the member states that have not, the obligations are coming and the direction is settled, so an early start costs less than a late one. If you operate in several member states, the sequence in which each one switches on matters for your planning, and the Commission tracks the position country by country on its NIS2 policy pages.
Who NIS2 applies to: essential and important entities
NIS2 applies to public and private entities of a type listed in Annex I or Annex II that qualify as medium-sized enterprises or exceed the ceilings for medium-sized enterprises, and that provide services or carry out activities in the Union. Size is measured against the Annex to Commission Recommendation 2003/361/EC, the same definition used across EU SME policy.
The size test is not the whole rule, and this is where most scoping errors start. Article 3(1) defines essential entities as an enumerated list of seven categories rather than as a single size threshold. Large Annex I entities are only the first of them. The list also captures qualified trust service providers, top-level domain name registries, and DNS service providers regardless of size; medium-sized providers of public electronic communications networks or publicly available electronic communications services; certain public administration entities; entities a member state has specifically identified; entities designated as critical under the Critical Entities Resilience Directive; and, where the member state so provides, entities it had already identified as operators of essential services under the 2016 NIS Directive before 16 January 2023. Important entities are then the residual category: any Annex I or Annex II entity that is not essential.
Several categories are in scope whatever their headcount: providers of public electronic communications networks and services, trust service providers, top-level domain name registries, DNS service providers, entities providing domain name registration services, public administration entities of central government, and entities identified as critical entities under the Critical Entities Resilience Directive. On top of that, a member state can bring an entity into scope on one of four grounds under Article 2(2): that it is the sole provider in that country of a service essential to critical societal or economic activity; that disruption of its service could significantly affect public safety, public security, or public health; that disruption could induce significant systemic risk; or that it is critical because of its specific importance at national or regional level. A twelve-person DNS provider is therefore in scope, while a three-hundred-person marketing agency is not, because no annex lists marketing agencies.
Annex I covers energy, transport, banking, financial market infrastructures, health, drinking water, waste water, digital infrastructure, ICT service management, public administration, and space. Annex II covers postal and courier services, waste management, chemicals, food, manufacturing, digital providers, and research. Within each sector the annexes list specific entity types, and only entities matching a listed type are caught, which is why "we are in manufacturing" is not by itself an answer.
Which obligations attach to your tier is set out in detail in our breakdown of the NIS2 requirements. Scope is also where the most expensive misreadings happen, from "we are too small" to "this is an IT problem," and we work through the common ones in the most dangerous NIS2 misconceptions. Essential entities in the Annex I sectors carry the heaviest obligations, and the NIS2 implementation guide for critical infrastructure covers that case using Germany's KRITIS regime as the worked example.
Which member state regulates you, and what happens if you are not in the EU
For most entities, jurisdiction follows establishment: you answer to each member state in which you are established. Article 26(1) sets out three exceptions to that. Providers of public electronic communications networks and publicly available electronic communications services fall under the jurisdiction of each member state where they provide their services. Public administration entities fall under the jurisdiction of the member state that established them. And a specific list of digital providers falls under the jurisdiction of the single member state where it has its main establishment in the Union. That list covers DNS service providers, top-level domain name registries, entities providing domain name registration services, cloud computing service providers, data center service providers, content delivery network providers, managed service providers, managed security service providers, and providers of online marketplaces, online search engines, and social networking services platforms.
Main establishment is defined by a three-step cascade in Article 26(2). It is the member state where decisions on cybersecurity risk-management measures are predominantly taken. If that cannot be determined, or if those decisions are taken outside the Union, it is the member state where cybersecurity operations are carried out. If that cannot be determined either, it is the member state where the entity has the establishment with the most employees in the Union. For a cloud provider with engineering in one country and a holding company in another, the answer turns on where the security decisions actually get made, not on the registered office.
This is the part that catches non-EU companies. If an entity in that Article 26(1)(b) list is not established in the Union but offers services in the Union, Article 26(3) requires it to designate a representative in the Union, established in one of the member states where it offers the services. The entity is then treated as falling under that member state's jurisdiction. Skipping the designation does not create an exemption; it removes the single point of contact, and any member state where the entity provides services may take legal action against it. A UK or US managed service provider with European customers should read Article 26 before concluding that NIS2 is somebody else's problem.
The same list of providers had to submit identifying information for an ENISA-maintained registry by 17 January 2025 under Article 27: entity name, sector and entity type, the addresses of the main establishment and other EU establishments or of the representative, current contact details, the member states where services are provided, and the entity's IP ranges. Registration duties under national law sit on top of this. Germany's registration deadline with the BSI has already passed, and what to do if you missed it is covered in our guide to the missed NIS2 registration deadline.
The ten risk-management measures under Article 21
Article 21(1) requires appropriate and proportionate technical, operational, and organizational measures to manage risks to the network and information systems used for your operations or services, and to prevent or minimize the impact of incidents on recipients of your services and on other services. Proportionality is judged against your degree of exposure to risk, your size, the cost of implementation, and the likelihood and severity of incidents including their societal and economic impact. The measures must rest on an all-hazards approach, which means physical and environmental threats count, not only cyber ones.
Article 21(2) then sets ten measures as the minimum:
- policies on risk analysis and information system security
- incident handling
- business continuity, such as backup management and disaster recovery, and crisis management
- supply chain security, including security-related aspects concerning the relationships between each entity and its direct suppliers or service providers
- security in network and information systems acquisition, development, and maintenance, including vulnerability handling and disclosure
- policies and procedures to assess the effectiveness of cybersecurity risk-management measures
- basic cyber hygiene practices and cybersecurity training
- policies and procedures regarding the use of cryptography and, where appropriate, encryption
- human resources security, access control policies, and asset management
- the use of multi-factor authentication or continuous authentication solutions, secured voice, video, and text communications, and secured emergency communication systems within the entity, where appropriate
Most of the ten can be evidenced with policies and records. Business continuity is the hardest, because a recovery plan only counts once it has been tested, and an untested plan is a statement of intent rather than a control. How to build a business impact analysis, a backup strategy, and a crisis team that survive their first test is covered in our guide to NIS2 business continuity planning.
Supply chain security is the most demanding of the ten
Number 4 asks for security-related aspects of the relationships between you and your direct suppliers or service providers. The word "direct" is doing real work: the obligation stops at your first tier, and teams that miss this spend months mapping suppliers of suppliers to no regulatory benefit. What the obligation is not satisfied by is a list of supplier names. Security-related aspects of a relationship means an assessment of each supplier and contractual terms that match that assessment.
A workable scope starts with the suppliers whose failure or compromise would hit your in-scope services directly: cloud and data center services, managed service providers, software with access to production systems, and anyone holding administrative credentials. For that group you need a documented assessment, a date, a named owner, and a review cycle. That chain of assessment, evidence, and re-review is what our risk management module is built to hold.
Article 22 lets the Cooperation Group, with the Commission and ENISA, carry out coordinated Union-level security risk assessments of specific critical ICT supply chains, which can change the risk picture for a widely used product without any action by you. And the obligation is reciprocal: once your customers are in scope, you become one of their assessed direct suppliers. For most software companies, a customer security questionnaire is the first time NIS2 shows up at all.
Incident reporting: 24 hours, 72 hours, one month
Article 23 requires essential and important entities to report significant incidents to their CSIRT or, where applicable, their competent authority, without undue delay. An incident is significant if it has caused or is capable of causing severe operational disruption of services or financial loss for you, or if it has affected or is capable of affecting others by causing considerable material or non-material damage. The hour figures below are outer limits, not targets.
Trust service providers get 24 hours rather than 72 for the incident notification stage where the incident affects the provision of their trust services, under a derogation in Article 23(4). And Article 23(1) requires entities, where appropriate, to notify the recipients of their services without undue delay about significant incidents likely to adversely affect the provision of those services. That is a customer communication duty sitting inside a regulatory reporting clause, and it needs a drafted template and a named approver long before you need it.
The 24-hour deadline is rarely missed for technical reasons. It is missed because nobody has the authority to file. If an incident surfaces on a Friday evening and nobody is designated to file the early warning without checking upward first, the deadline passes while the assessment is still being organized. A missed reporting deadline is an infringement in its own right, regardless of how well the incident itself was handled afterward.
Management body obligations and liability
Article 20(1) puts two duties on the management bodies of essential and important entities and attaches one consequence. They must approve the cybersecurity risk-management measures taken to comply with Article 21, and they must oversee the implementation of those measures. They can then be held liable for the entity's infringements of Article 21. Liability is left to national law, so what it means in practice depends on the company law of the member state and the legal form of the company, which is exactly why the answer differs between a German GmbH and an Irish limited company.
Article 20(2) adds a personal training duty. Members of management bodies are required to follow training so that they gain sufficient knowledge and skills to identify risks, assess cybersecurity risk-management practices, and judge their impact on the services the entity provides. Note the asymmetry that gets misreported: the training requirement is mandatory for the management body, while for employees the directive only requires member states to encourage entities to offer similar training. Broad staff awareness training is still required, but through Article 21(2)(g) rather than Article 20.
What a director should actually be able to produce, from approval records through training evidence to a recurring oversight routine, is set out in our NIS2 checklist for managing directors.
Supervision and penalties
Supervision is deliberately asymmetric between the two tiers. Competent authorities must be able to subject essential entities to on-site inspections and off-site supervision, regular and targeted security audits by an independent body or a competent authority, ad hoc audits, security scans, requests for information and for access to data and documents, and requests for evidence that security policies are actually implemented. For important entities, Article 33 works the other way: authorities act when provided with evidence, indication, or information of non-compliance, through ex post supervisory measures. Essential entities can be examined without anything having gone wrong; important entities generally are not.
This construction is routinely reported as a cap, and it is a floor. Article 34 requires a national maximum of "at least" those amounts, so these are floors for what member states must make possible, and a national law may set a higher ceiling. The turnover reference is also group-level: the undertaking to which the entity belongs, worldwide, in the preceding financial year.
The supervisory powers matter more than the fines. Where enforcement measures have not worked and a deadline to remedy passes, Article 32(5) lets authorities suspend, or ask a certification body or a court to suspend, a certification or authorization covering part or all of the relevant services. It also lets them ask the relevant body or court to prohibit temporarily a person discharging managerial responsibilities at chief executive or legal representative level from exercising managerial functions. Both powers apply to essential entities only, they are not available against important entities under Article 33, and Article 32(5) does not apply to public administration entities at all.
How to prepare for NIS2
The ten measures in Article 21 map closely onto the requirements of ISO 27001, so an information security management system you already run has done much of the work. It does not cover everything. The reporting clock in Article 23, the jurisdiction and representative questions in Article 26, the registry submission in Article 27, and the personal duties of the management body in Article 20 have no direct counterpart in the standard. Which parts transfer and which gaps remain is mapped in our guide to where NIS2 and ISO 27001 overlap.
If you are not certified yet, the sequence still favors the ISMS. Building it first and hanging the NIS2-specific additions off it costs less than maintaining two separate evidence structures, and it gives you something a customer questionnaire will accept. What certification takes and costs is covered in our guide to ISO 27001 certification. One thing an ISMS will not give you is a NIS2 certificate, because there is no such thing. Article 24 only lets member states require the use of ICT products and services certified under European cybersecurity certification schemes adopted under the Cybersecurity Act. NIS2 creates no certification of its own, so a vendor offering you a NIS2 certificate is offering something the directive does not recognize.
From there the work is tractable. Confirm your entity type against the annexes and your size band, and document the conclusion, because the scoping assessment is itself evidence. Establish which member state has jurisdiction, and designate a representative if Article 26(3) applies to you. Close the gaps against the ten measures, with a named owner and an effectiveness measure for each. Stand up the reporting process with named on-call authority and drafted templates, including the customer notification, and rehearse it once. Then put the management body's approval, training, and oversight on a recurring calendar.
How Kertos supports NIS2
Kertos combines a compliance platform with certified experts who carry out the implementation with you rather than only assessing it. The platform maps one control set across NIS2, ISO 27001, GDPR, and your other frameworks, collects evidence automatically, and shows which of the ten Article 21 measures are actually substantiated and which are not.
In practice that means your scoping assessment, the direct-supplier register for measure 4, the effectiveness reviews for measure 6, and the Article 23 notification templates sit in one place, versioned and dated. If you already run ISO 27001, NIS2 becomes an extension of a program you have rather than a second project with its own evidence trail. The detail is on the NIS2 solution page and the compliance platform, and if you would rather talk through where your company actually stands, book a demo.
Frequently asked questions
Who has to comply with NIS2?
Public and private entities matching a type listed in Annex I or Annex II of the directive that are medium-sized or larger, meaning broadly 50 or more employees, or both turnover and balance sheet total above EUR 10 million. Providers of public electronic communications networks and services, trust service providers, top-level domain name registries, and DNS service providers are covered regardless of size, as are entities a member state specifically identifies as critical.
What is the difference between essential and important entities?
Both tiers owe the same substantive obligations under Articles 21 and 23. Supervision and penalties differ. Essential entities can be inspected and audited without any triggering event and face fine ceilings of at least EUR 10 million or 2 percent of worldwide turnover. Important entities are supervised ex post, once there is an indication of non-compliance, and face at least EUR 7 million or 1.4 percent.
What are the NIS2 reporting deadlines?
An early warning within 24 hours of becoming aware of a significant incident, an incident notification with an initial assessment within 72 hours, and a final report within one month of that notification. If the incident is still ongoing at the one-month point, a progress report replaces the final report for the time being. Trust service providers get 24 hours for that stage.
Is NIS2 in force yet?
The directive has been in force since 16 January 2023, and member states had to apply their transposing measures from 18 October 2024. Most were late. As of August 2026 the obligations are enforceable in the majority of member states, including Germany, while the Commission has referred Ireland, Spain, France, and the Netherlands to the Court of Justice over outstanding transposition. What binds you is your national law, so check its status and its wording.
Does NIS2 apply to companies outside the EU?
It can. If you provide services in the Union and fall within the Article 26(1)(b) list, which includes cloud, data center, CDN, managed service, managed security service, marketplace, search engine, and social network providers, you must designate a representative in a member state where you offer those services, and you come under that member state's jurisdiction. Without a representative, any member state where you provide services may take legal action against you.
How does NIS2 relate to ISO 27001?
The ten Article 21 measures overlap substantially with ISO 27001, so a certified ISMS evidences most of the technical and organizational side. The gaps are the parts the standard was never written for: statutory reporting deadlines, jurisdiction, registration, and the personal duties of the board. And there is no NIS2 certificate to obtain.




