What is NIS2
What is NIS2, and why it matters
NIS2 is the EU's tougher, more uniform cybersecurity law. It widens who must comply, standardises what they must do, and — for the first time — holds senior management personally accountable.
From NIS to NIS2
The original NIS Directive (2016) was the EU's first cybersecurity law, but it left wide discretion to member states and produced an uneven patchwork of rules. NIS2 — Directive (EU) 2022/2555 — repeals and replaces it, harmonising scope, security requirements, incident reporting, supervision and penalties across the Union.
What changed
- Far wider sector coverage, with a clear, size-based test for who is in scope.
- A two-tier model of essential and important entities.
- Standardised risk-management measures under Article 21.
- A strict, multi-stage incident-reporting timeline under Article 23.
- Direct management accountability under Article 20.
- GDPR-scale penalties, stronger supervision and cross-border cooperation.
Key milestones
NIS2 moved from adoption to active enforcement over four years:
KEY MILESTONES
-
Nov 2022
Adopted
NIS2 adopted by the European Parliament and the Council.
-
Jan 2023
In force
Directive (EU) 2022/2555 entered into force on 16 January 2023.
-
17 Oct 2024
Transposition deadline
Member states had to adopt and publish their national measures.
-
From 2025
Registration & enforcement
Authorities open entity registration and begin supervision.
-
2026
Maturity
Audits, penalties and supply-chain scrutiny intensify.
Who enforces it
Each member state designates one or more competent authorities and a CSIRT (Computer Security Incident Response Team) to supervise entities and receive incident reports. At EU level, ENISA and the Cooperation Group coordinate a consistent approach, and the CSIRTs network supports cross-border response.
Who this guide is for
Security and risk leaders, compliance and legal teams, and executives in organisations that are newly in scope. If you are trying to work out what NIS2 means for your business — and what to do about it — start here, then take the readiness assessment.
Not sure whether NIS2 applies to you?
Take the free six-question assessment to estimate your scope tier and readiness.
Start free assessment →