TRANSPOSITION DEADLINE PASSED · ENFORCEMENT UNDER WAY

The complete guide to NIS2 compliance

Directive (EU) 2022/2555 raises the cybersecurity bar for essential and important entities across the EU. NIS2 Atlas turns dense legal text into a clear, practical path to compliance — written for the security leaders and businesses now in scope.

18
sectors across Annexes I & II
2 tiers
essential & important entities
10
mandatory security measures
27
EU member states transposing

What is NIS2

A single, tougher cybersecurity baseline for the EU

NIS2 replaces the original 2016 NIS Directive, closing the gaps that left the earlier rules inconsistent across member states. It significantly widens the range of organisations in scope, imposes uniform risk-management and reporting obligations, and — for the first time — makes senior management directly accountable for cybersecurity.

Compliance is not optional and not just an IT project: it is a legal obligation with financial and personal consequences for those who fall in scope.

KEY MILESTONES

  1. Nov 2022

    Adopted

    NIS2 adopted by the European Parliament and the Council.

  2. Jan 2023

    In force

    Directive (EU) 2022/2555 entered into force on 16 January 2023.

  3. 17 Oct 2024

    Transposition deadline

    Member states had to adopt and publish their national measures.

  4. From 2025

    Registration & enforcement

    Authorities open entity registration and begin supervision.

  5. 2026

    Maturity

    Audits, penalties and supply-chain scrutiny intensify.

Free readiness assessment

Where does your organisation stand?

Answer six quick questions to gauge whether NIS2 applies to you and how prepared you are. No email required.

6 questions · about 60 seconds

We'll estimate your likely scope tier and score your current readiness against the core obligations.

Begin assessment →

FAQ

Common questions

Is NIS2 a law I have to follow directly?

NIS2 is an EU directive, so it takes legal effect through each member state's national transposition law. Your concrete obligations come from that national law — which must meet, and may go beyond, the directive's minimum standard.

How is NIS2 different from the original NIS Directive?

NIS2 widens the sectors and entities in scope, standardises the risk-management and reporting requirements, adds strict incident-reporting deadlines, introduces management accountability, and raises penalties significantly.

We're a small company — are we exempt?

Generally the rules target medium and large entities (50 or more staff, or above €10 million turnover or balance sheet) in covered sectors. But some providers are in scope regardless of size, and you may still be affected as part of a larger entity’s supply chain.

See all questions →

Turn the directive into a plan you can defend

Start with a free readiness snapshot, then follow the roadmap step by step.

Start free assessment →