Skip to main content
NIS2 Directive · national laws taking effect across the EU

The NIS2 Directive — what it requires and who must comply

NIS2 (Directive (EU) 2022/2555) is the EU-wide cybersecurity law for essential and important entities. It imposes a duty of care, strict incident reporting and registration in the national register.

At a glance

The facts

EU-wide
Directive(EU) 2022/2555
MeasuresArt. 21 + national law
Reporting24h / 72h / 1 month
Registrationnational register
Fines (essential)from 10 m / 2%

What is the NIS2 Directive?

NIS2 is the EU directive on cybersecurity for network and information systems, replacing the original NIS Directive with a far wider scope and stricter enforcement. Each member state transposes it into national law — for example the Cyberbeveiligingswet in the Netherlands or the NISG in Austria. The concrete measures come from Article 21. For eleven types of digital provider — among them cloud, data centre, CDN, managed service and managed security service providers, online marketplaces, search engines and trust service providers — they are spelled out in Implementing Regulation (EU) 2024/2690. For every other sector the detail comes from national law.

When does it apply?

The obligations apply through national law, and the timing differs from one member state to the next. The transposition deadline in the directive itself was 17 October 2024, but not every country met it — several national laws arrived later. The Dutch Cyberbeveiligingswet, for instance, takes effect on 15 August 2026. If your country's law is already in force, the duty of care and reporting obligations apply now; check the status for every country you operate in, not only the one your headquarters sits in.

Inside the NIS2 Manager

The obligations, as a working tool

Screenshots from the English edition with the EU country pack, filled with sample data.

Emergency tab showing the statutory notification deadlines of 24 hours, 72 hours and 1 month, along with the competent authority, the CSIRT and a link to the official notification portal.

Deadlines to act on

The statutory 24-hour, 72-hour and one-month windows sit next to the competent authority and CSIRT contacts, so a notification does not start with a search.

Close-up of a single requirement card with chapter heading, requirement text, mandatory badge and tags for the related NIS 2 articles and the current fulfilment status.

Every measure, traced

Each requirement links back to its article and paragraph, so a fulfilment status is never just an unsupported claim.

Project progress report showing a management summary with completed, ongoing and open phases, and an embedded Gantt chart of the nine-phase implementation plan.

Progress, exportable

A management summary and a Gantt chart turn the current status into a report you can hand to a manager without rebuilding it by hand.

Who is affected?

NIS2 distinguishes between essential and important entities in designated sectors — among them energy, transport, drinking water, digital infrastructure, healthcare, public administration, postal services, waste management and manufacturing — as a rule from 50 employees or 10 million euros in turnover.

The size threshold is the rule, not the whole story. Article 2(2) pulls certain organisations into scope regardless of size: providers of public electronic communications networks and services, trust service providers, DNS service providers and TLD registries, any entity that is the sole provider in a member state of a service essential to society or the economy, entities whose disruption would significantly affect public safety or public health, and parts of central government. A company with twenty people can therefore be in scope.

Not sure whether your organisation is in scope? Find out in a few minutes with the free NIS2 self-check — including an overview of the measures that would then apply to you.

What does the duty of care require?

The duty of care demands appropriate technical and organisational measures. Article 21 lists, among others:

  • Risk analysis and information security policies
  • Incident handling and business continuity / backup
  • Supply chain security (suppliers and service providers)
  • Access control, encryption and security in acquisition and maintenance
  • Cyber hygiene, training and policies to assess the effectiveness of measures

Incident reporting: 24 hours, 72 hours, 1 month

For a significant incident you must submit an early warning within 24 hours, an incident notification within 72 hours and a final report within one month. The report goes to your national CSIRT or, where the member state has set it up that way, to the competent authority.

Two details decide whether a deadline is met. First, the clock starts when you become aware of the incident, not when it began. Second, the month for the final report runs from the 72-hour notification, not from the incident. If the incident is still ongoing at that point you file a progress report instead, and the final report follows within a month of the incident being handled. The CSIRT or the authority can also ask for an intermediate report in between. One exception worth knowing: trust service providers report within 24 hours at the second stage as well.

Registration: where do you sign up?

Entities in scope must register — but not always with the body that supervises them, and the place differs by country. In the Netherlands you register in the national entity register through MijnNCSC, using eHerkenning or SSOnRijk; the RDI is a sectoral supervisor there and does not run the register. In Belgium you register with the CCB through Safeonweb@Work. In Germany registration is with the BSI. Look the right channel up once and write down who your contact is — not on the day you have to report an incident.

What are the fines?

For essential entities fines reach at least 10 million euros or 2% of worldwide annual turnover — whichever is higher; for important entities at least 7 million euros or 1.4%, again whichever is higher. Those are floors, not ceilings: the directive obliges member states to provide for at least these maximums, and some national laws go further. In addition, management can be held personally responsible, and at essential entities a manager can be temporarily barred from holding a management role. That makes demonstrability — being able to show that the measures are in place — the core issue.

How do you prepare?

  • Determine whether you are in scope — take the free NIS2 self-check.
  • Document your measures and registers — structured and auditable.
  • Set up your reporting process — 24h/72h/1 month to your national CSIRT, with roles agreed in advance.
  • Register — in the register your country operates, which is not necessarily your supervisor.

Frequently asked questions

Is NIS2 a law?

NIS2 is an EU directive; it becomes binding through national laws such as the Dutch Cyberbeveiligingswet or the Austrian NISG.

Who must comply with NIS2?

Essential and important entities in designated sectors, as a rule from 50 employees or 10 million euros in turnover. Some organisations are in scope regardless of size, for example trust service providers, DNS providers and the sole provider of an essential service in a member state.

What are the reporting deadlines?

Early warning within 24 hours of becoming aware, incident notification within 72 hours, final report within one month of that notification. Trust service providers report within 24 hours at the second stage as well.

Do I have to register?

Yes, but not always with your supervisor. In the Netherlands you register in the national entity register through MijnNCSC, in Belgium with the CCB through Safeonweb@Work, in Germany with the BSI.

What are the fines under NIS2?

At least 10 million euros or 2% of worldwide turnover for essential entities, at least 7 million euros or 1.4% for important entities, whichever is higher in each case. The directive sets minimum maximums; national laws may go further.

From knowing to doing

Find out for free whether you are in scope, or see how the local NIS2 software takes you from duty of care to incident reporting.

This page provides general information and does not constitute legal advice. Dates and amounts: confirm against the final legal texts of your member state.