TRANSPOSITION DEADLINE PASSED · ENFORCEMENT UNDER WAY
The complete guide to NIS2 compliance
Directive (EU) 2022/2555 raises the cybersecurity bar for essential and important entities across the EU. NIS2 Atlas turns dense legal text into a clear, practical path to compliance — written for the security leaders and businesses now in scope.
What is NIS2
A single, tougher cybersecurity baseline for the EU
NIS2 replaces the original 2016 NIS Directive, closing the gaps that left the earlier rules inconsistent across member states. It significantly widens the range of organisations in scope, imposes uniform risk-management and reporting obligations, and — for the first time — makes senior management directly accountable for cybersecurity.
Compliance is not optional and not just an IT project: it is a legal obligation with financial and personal consequences for those who fall in scope.
KEY MILESTONES
-
Nov 2022
Adopted
NIS2 adopted by the European Parliament and the Council.
-
Jan 2023
In force
Directive (EU) 2022/2555 entered into force on 16 January 2023.
-
17 Oct 2024
Transposition deadline
Member states had to adopt and publish their national measures.
-
From 2025
Registration & enforcement
Authorities open entity registration and begin supervision.
-
2026
Maturity
Audits, penalties and supply-chain scrutiny intensify.
Explore the guide
Everything you need, one topic at a time
Work through the guide in order, or jump straight to the answer you need.
Who's covered
Essential vs important entities, the Annex I/II sectors, and the size thresholds that decide your scope.
The 10 security measures
What Article 21 requires in practice — from risk management to multi-factor authentication.
Incident reporting
The Article 23 clock: a 24-hour early warning, a 72-hour notification and a one-month final report.
Penalties & liability
Fines up to €10M or 2% of worldwide turnover — plus direct, personal accountability for management.
Compliance roadmap
Six pragmatic steps, from confirming your scope to maintaining auditable, continuous compliance.
Transposition tracker
NIS2 becomes law country by country. Check where each member state currently stands.
Free readiness assessment
Where does your organisation stand?
Answer six quick questions to gauge whether NIS2 applies to you and how prepared you are. No email required.
6 questions · about 60 seconds
We'll estimate your likely scope tier and score your current readiness against the core obligations.
Begin assessment →FAQ
Common questions
Is NIS2 a law I have to follow directly?
NIS2 is an EU directive, so it takes legal effect through each member state's national transposition law. Your concrete obligations come from that national law — which must meet, and may go beyond, the directive's minimum standard.
How is NIS2 different from the original NIS Directive?
NIS2 widens the sectors and entities in scope, standardises the risk-management and reporting requirements, adds strict incident-reporting deadlines, introduces management accountability, and raises penalties significantly.
We're a small company — are we exempt?
Generally the rules target medium and large entities (50 or more staff, or above €10 million turnover or balance sheet) in covered sectors. But some providers are in scope regardless of size, and you may still be affected as part of a larger entity’s supply chain.
Turn the directive into a plan you can defend
Start with a free readiness snapshot, then follow the roadmap step by step.
Start free assessment →