Skip to content
atlas

NIS2 Directive

Also known as: NIS2, Directive (EU) 2022/2555

The EU cybersecurity law that sets shared security duties for organisations in important and critical sectors.

Draft - this entry has not been reviewed yet.

Read the full article →

Formal

Directive (EU) 2022/2555, to be written into national law by 17 October 2024, which obliges essential and important entities in 18 sectors to manage cyber risk, report significant incidents in stages and make their management body answerable.

In plain English

Like common building safety rules for the whole EU - every country must write them into its own law, and those who keep society running must build by them.

In practice

The board of a mid-sized Danish shipping company learns it falls under NIS2, so it approves a risk assessment, a routine for reporting incidents within 24 hours and security terms for its suppliers.

Why it matters

The first NIS rules covered too few sectors and were applied unevenly; NIS2 brings in thousands more organisations, fines of up to 10 million euro or 2% of turnover, and personal liability for leaders.

Technical deep dive

Directive (EU) 2022/2555 was published in the Official Journal on 27 December 2022, entered into force on 16 January 2023 and had to be transposed by 17 October 2024 and applied from the following day. Most member states missed that deadline and the Commission opened infringement procedures, so the date from which a given organisation is actually bound depends on its national law; in Denmark that is the NIS2 Act in force from 1 July 2025, with energy, telecommunications and finance handled in separate acts. As a minimum-harmonisation directive, NIS2 allows national law to go further, for example by adding sectors or entities.

Scope is set by Article 2 and Annexes I (11 sectors of high criticality) and II (7 other critical sectors) through a size-cap rule based on Commission Recommendation 2003/361/EC: medium and large enterprises in the listed sectors are covered, and Article 2(2) adds entities covered regardless of size, such as DNS service providers, TLD name registries, trust service providers, providers of public electronic communications and sole providers of an essential service in a member state. Article 3 splits covered entities into essential and important. Article 4 makes sector-specific EU law with at least equivalent requirements take precedence, which is why financial entities follow DORA.

The substantive duties are short. Article 20 puts approval, oversight and training on the management body; Article 21 requires appropriate and proportionate technical, operational and organisational measures on an all-hazards basis, with ten minimum areas in 21(2); and Article 23 defines a significant incident and the staged reporting to the CSIRT or competent authority: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, intermediate reports on request and a final report within one month of the notification. For DNS, TLD, cloud, data centre, CDN, managed and managed security service providers, online marketplaces, search engines, social networks and trust service providers, Commission Implementing Regulation (EU) 2024/2690 specifies both the technical measures and when an incident counts as significant.

Enforcement is split between Article 32 (ex ante supervision of essential entities, including on-site inspections, security audits and scans) and Article 33 (ex post supervision of important entities, triggered by evidence of non-compliance). Article 34 sets fine maxima of at least EUR 10 million or 2 % of worldwide annual turnover for essential entities and EUR 7 million or 1.4 % for important entities, whichever is higher. Article 27 creates a registry of certain digital providers held by ENISA, and Article 35 coordinates with GDPR: where a data protection authority fines an infringement arising from the same conduct, the NIS2 authority may not impose an additional fine under Article 34. A single incident can therefore trigger an NIS2 report and a GDPR Article 33 notification to different authorities on different clocks.

What to learn first

Everything this builds on, foundations first.

  1. Cyber and information security
  2. →NIS2 Directive

Relationships

A kind of
EU directive
Supersedes
NIS1 Directive

Sources & further reading

Standards & official texts

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.