From NIS to NIS2

The original NIS Directive (2016) was the EU's first cybersecurity law, but it left wide discretion to member states and produced an uneven patchwork of rules. NIS2 — Directive (EU) 2022/2555 — repeals and replaces it, harmonising scope, security requirements, incident reporting, supervision and penalties across the Union.

What changed

  • Far wider sector coverage, with a clear, size-based test for who is in scope.
  • A two-tier model of essential and important entities.
  • Standardised risk-management measures under Article 21.
  • A strict, multi-stage incident-reporting timeline under Article 23.
  • Direct management accountability under Article 20.
  • GDPR-scale penalties, stronger supervision and cross-border cooperation.

Key milestones

NIS2 moved from adoption to active enforcement over four years:

KEY MILESTONES

  1. Nov 2022

    Adopted

    NIS2 adopted by the European Parliament and the Council.

  2. Jan 2023

    In force

    Directive (EU) 2022/2555 entered into force on 16 January 2023.

  3. 17 Oct 2024

    Transposition deadline

    Member states had to adopt and publish their national measures.

  4. From 2025

    Registration & enforcement

    Authorities open entity registration and begin supervision.

  5. 2026

    Maturity

    Audits, penalties and supply-chain scrutiny intensify.

Who enforces it

Each member state designates one or more competent authorities and a CSIRT (Computer Security Incident Response Team) to supervise entities and receive incident reports. At EU level, ENISA and the Cooperation Group coordinate a consistent approach, and the CSIRTs network supports cross-border response.

Who this guide is for

Security and risk leaders, compliance and legal teams, and executives in organisations that are newly in scope. If you are trying to work out what NIS2 means for your business — and what to do about it — start here, then take the readiness assessment.

Not sure whether NIS2 applies to you?

Take the free six-question assessment to estimate your scope tier and readiness.

Start free assessment →