EU Directive 2022/2555

NIS2 Compliance Guide

What the NIS2 Directive requires of essential and important entities: which sectors are covered, the mandatory security measures, incident reporting deadlines, and personal liability for management.

Oct 18, 2024
National laws apply from
18 sectors
In scope
EUR 10M / 2%
Max fine, essential entities

What is NIS2?

NIS2 (Directive (EU) 2022/2555) is the EU's cybersecurity law for critical and important sectors, replacing the 2016 NIS Directive. It entered into force on January 16, 2023, and member states had until October 17, 2024 to transpose it into national law, with the rules applying from October 18, 2024. Because NIS2 is a directive, the obligations you actually face come from your member state's implementing law, and both timing and details vary by country; several member states transposed late.

NIS2 dramatically widens the net compared to its predecessor: it covers eighteen sectors, applies a size threshold instead of case-by-case designation, imposes a common baseline of security measures, tightens incident reporting to a 24-hour early warning, and makes management bodies personally accountable for compliance.

Who is in scope

NIS2 generally applies to organizations in a covered sector that are medium-sized or larger (50 or more employees, or over EUR 10 million annual turnover), plus certain entities regardless of size, such as sole providers of a critical service, qualified trust service providers, and TLD registries. Entities fall into two categories with different supervision intensity:

Essential entities (Annex I sectors, larger organizations)

  • Energy (electricity, district heating, oil, gas, hydrogen)
  • Transport (air, rail, water, road)
  • Banking and financial market infrastructures
  • Health (providers, labs, pharma, medical device manufacturers)
  • Drinking water and waste water
  • Digital infrastructure (IXPs, DNS, TLD registries, cloud, data centers, CDNs, trust services, electronic communications)
  • ICT service management (managed service providers and managed security service providers)
  • Public administration and space

Important entities (Annex II sectors, and medium-sized Annex I entities)

  • Postal and courier services
  • Waste management
  • Chemicals (manufacture, production, distribution)
  • Food (production, processing, distribution)
  • Manufacturing (medical devices, computers and electronics, machinery, motor vehicles, other transport equipment)
  • Digital providers (online marketplaces, search engines, social networks)
  • Research organizations

The substantive security obligations are the same for both categories. The differences are supervision (essential entities face proactive, ex-ante supervision; important entities are supervised after the fact) and penalty ceilings.

Required security measures (Article 21)

Entities must take appropriate and proportionate technical, operational, and organizational measures covering, at minimum:

  • Risk analysis and information system security policies
  • Incident handling
  • Business continuity: backup management, disaster recovery, and crisis management
  • Supply chain security, including the security of relationships with direct suppliers and service providers
  • Security in network and system acquisition, development, and maintenance, including vulnerability handling and disclosure
  • Policies and procedures to assess the effectiveness of the measures
  • Basic cyber hygiene practices and cybersecurity training
  • Policies on the use of cryptography and, where appropriate, encryption
  • Human resources security, access control policies, and asset management
  • Multi-factor or continuous authentication, and secured voice, video, and text communications where appropriate

Management bodies must approve these measures, oversee their implementation, and complete cybersecurity training. Under Article 20 they can be held personally liable for infringements, and for essential entities regulators can even temporarily suspend managers from their duties.

Incident reporting deadlines

Significant incidents must be reported to the CSIRT or competent authority in stages:

Stage Deadline Content
Early warning 24 hours from awareness Whether the incident is suspected to be malicious or could have cross-border impact
Incident notification 72 hours from awareness Initial assessment of severity, impact, and indicators of compromise
Final report One month Detailed description, root cause, mitigation applied, and cross-border impact

An incident is significant when it causes or can cause severe operational disruption or financial loss, or affects others through considerable material or non-material damage. Recipients of services must also be notified when significant incidents are likely to adversely affect them.

Penalties

National laws must provide administrative fines of at least the following maximums, using whichever of the fixed amount or turnover percentage is higher:

  • Essential entities: EUR 10 million or 2% of total worldwide annual turnover
  • Important entities: EUR 7 million or 1.4% of total worldwide annual turnover

Beyond fines, regulators can issue binding instructions, order security audits, mandate public disclosure of infringements, and for essential entities temporarily suspend certifications or management. Since these are directive minimums, individual member states may set higher ceilings.

Where to start

  1. Determine scope: match your activities to Annex I and II sectors, apply the size test, and check the national law of every member state where you provide services (registration duties differ by country).
  2. Classify yourself as essential or important; this sets your supervision model and fine exposure.
  3. Gap-assess against Article 21: existing ISO 27001 or IEC 62443 programs cover much of it, but supply chain security, cyber hygiene training, and management accountability are common gaps.
  4. Build the 24-hour reporting capability, including incident-significance criteria, on-call escalation, and knowing which national CSIRT to notify.
  5. Brief the board. Management must approve the measures, complete training, and understand its personal liability.

Related guides

Assess your NIS2 exposure

BD Emerson helps organizations determine NIS2 scope, gap-assess against Article 21, and build incident reporting processes that meet the 24-hour deadline.