Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.
Network and Information Security Directive (NIS2)
NIS2 requires medium-sized and large organizations in 18 EU sectors to implement documented cybersecurity risk management, hold management bodies personally accountable, and report significant security incidents to national authorities within strict timeframes. Fines reach up to €10 million or 2% of global annual turnover.
Next relevant deadline:
June 30, 2026: Essential entities in several EU member states must complete their first formal NIS2 compliance audit.
Substantive NIS2 obligations, including risk management, governance, supply chain security, and incident reporting, apply from the date each member state's national transposition law enters into force. For most EU countries, that point has already passed.
June 30, 2026 is the first formal verification checkpoint for essential entities in multiple member states: competent authorities assess whether governance structures are documented, risk assessments are complete, and incident response processes are operational.
Essential entities face proactive (ex-ante) supervision under NIS2, meaning authorities can initiate audit requests without waiting for an incident or evidence of non-compliance. Important entities face reactive oversight but carry the same substantive obligations from the day their national transposition law entered into force.
Regulation timeline
What the regulation requires
NIS2 (Directive (EU) 2022/2555) entered into force on January 16, 2023, with a member state transposition deadline of October 17, 2024. The directive applies to medium-sized and large organizations in 18 sectors.
Essential entities are generally organizations in Annex I sectors, including energy, transport, healthcare, and digital infrastructure, with at least 250 employees or annual turnover above €50 million combined with a balance sheet above €43 million.
Important entities are generally organizations in Annex I or Annex II sectors, including manufacturing, food, and chemicals, with at least 50 employees or annual turnover above €10 million combined with a balance sheet above €10 million.
Both categories carry the same core obligations: documented, all-hazards risk management and technical security measures; a three-stage incident reporting process (24-hour early warning, 72-hour notification, one-month final report); and personal accountability for management bodies. Organizations must also assess and manage cybersecurity risks arising from suppliers and service providers that can affect their information security.
Common NIS2 implementation challenges
Scope determination depends on all economic activities, not primary sector alone
A company whose core sector sits outside NIS2's scope can still qualify if a secondary activity (such as operating a data center for group entities) falls within a covered sector. For international groups with legal entities in multiple EU member states, each entity requires a separate scope assessment, and the applicable supervisory authority, registration procedure, and audit cycle differ by jurisdiction.
NIS2 governance obligations extend beyond existing IT frameworks
NIS2 makes management bodies personally liable for approving and overseeing cybersecurity risk management measures. Organizations require defined cybersecurity roles and reporting lines, formal management approval of risk treatment decisions, and documented evidence that the management body receives regular cybersecurity briefings.
Third-party security data is rarely consolidated or structured
NIS2 requires organizations to assess and manage suppliers and service providers with access to or influence over their information systems. Identifying relevant suppliers, collecting structured security evidence, and running recurring assessments requires processes and tooling that existing ERP and procurement setups do not typically provide.
National NIS2 implementations differ significantly across member states
NIS2 is a directive: core obligations are consistent across the EU, but national implementation details vary significantly.
Germany's transposition law entered into force on December 6, 2025, with a registration deadline of March 6, 2026; Belgium's requirements have been active since October 2024; Italy's first operational deadlines for security measure adoption fall in October 2026.
Structured NIS2 compliance across every obligation area
The osapiens HUB for NIS2 maps NIS2 obligations into structured processes built directly on the supplier and entity data already in the osapiens HUB Supplier Intelligence solution suite.
Capture NIS2 scope, run structured assessments, and track implementation progress across every obligation
Predefined NIS2 questionnaires go to relevant suppliers with AI-assigned risk scores and automated alerts from continuous news monitoring. Supplier profiles built for CSDDD due diligence are reused directly for NIS2 third-party risk assessments, without a separate supplier engagement process.
Manage incidents through standardized workflows that produce audit-ready reporting outputs
The osapiens HUB for NIS2 provides policy templates covering governance, incident management, vulnerability management, and supplier security requirements. Significant incidents are captured and managed through standardized workflows that produce the structured outputs required for the three-stage incident reporting timeline.
Surface NIS2 compliance status in the Reporting Cockpit alongside all other regulatory obligations
Risk assessments, treatment decisions, supplier evaluations, and incident records are stored with full traceability and version control. NIS2 risk and compliance status surfaces in the Reporting Cockpit for executive and supervisory reporting, without manual data extraction from the osapiens HUB.
ADDITIONAL NIS2 RESOURCES
Frequently Asked Questions (FAQ)
NIS2 covers medium-sized and large organizations in 18 sectors across two annexes.
Essential entities are generally organizations in Annex I sectors, including energy, transport, healthcare, banking, and digital infrastructure, with at least 250 employees or annual turnover above €50 million combined with a balance sheet above €43 million. Important entities are generally organizations in Annex I or Annex II sectors, including manufacturing, chemicals, food production, postal services, and research, with at least 50 employees or annual turnover above €10 million combined with a balance sheet above €10 million.
Certain organizations are always classified as essential entities regardless of size, including qualified trust service providers, DNS service providers, and entities identified as critical infrastructure under the Critical Entities Resilience Directive (Directive (EU) 2022/2557). Non-EU companies providing services within the EU may also fall within scope depending on their activities and the applicable national transposition law.
NIS2 sets maximum fine levels that member states must apply. Essential entities face fines of up to €10 million or 2% of global annual turnover, whichever is higher. Important entities face fines of up to €7 million or 1.4% of global annual turnover, whichever is higher. Beyond fines, competent authorities can issue binding instructions, order security audits at the entity's expense, suspend certifications or authorizations, and temporarily prohibit executives from holding management functions. Management bodies are personally liable for violations under Article 20. The directive requires penalties to be effective, proportionate, and dissuasive; enforcement intensity and priority differ by member state.
Article 21 requires in-scope organizations to implement appropriate and proportionate technical, operational, and organizational measures, based on an all-hazards approach covering cyberattacks, physical threats, human error, and environmental risks. In practice this means a documented ISMS with regular risk assessments; network security, access controls, and asset management; vulnerability identification and remediation processes; backup and recovery procedures; business continuity planning aligned with security incident management; mandatory cybersecurity training for management and staff; and policies on cryptography and multi-factor authentication. The measures must follow from a documented risk assessment. Article 23 requires reporting significant incidents in three stages: early warning within 24 hours of becoming aware of the incident, notification within 72 hours with an initial severity and impact assessment, and a final report within one month covering root cause and remediation.
NIS2 explicitly requires organizations to incorporate cybersecurity requirements into supplier relationships where those suppliers have the potential to affect information security. This applies to suppliers with system access, hosting or maintenance roles, remote access rights, or critical service delivery functions. Organizations must identify relevant suppliers, run structured security assessments, incorporate cybersecurity clauses into contracts, and monitor suppliers on an ongoing basis. Supply chain attacks are specifically identified in the NIS2 preamble as high-risk because vulnerabilities at external partners can propagate rapidly across interconnected systems. The obligation extends to both directly contracted suppliers and key subcontractors where security exposure exists.
NIS2 is a directive: core obligations are consistent, but each member state's national law governs the specific registration portal, supervisory authority, and audit procedures applicable in that country. For international groups, each legal entity requires a separate scope assessment. The home state of an entity's main establishment typically determines which national authority holds jurisdiction, though secondary operations in other member states may carry additional local requirements. Registration procedures and deadlines already differ significantly: Germany's deadline was March 6, 2026; Belgium's requirements have been active since October 2024; and as of June 2026, some member states are still completing transposition. Organizations operating across the EU need a structured process to track which obligations and deadlines apply in each jurisdiction.
Standalone ISMS tools manage information security processes but are disconnected from supplier data, due diligence workflows, and regulatory reporting. The osapiens HUB for NIS2 is part of the Supplier Intelligence solution suite: supplier and entity data built for CSDDD or other supply chain due diligence is reused directly for NIS2 third-party risk assessments, and NIS2 compliance status surfaces in the Reporting Cockpit alongside other regulatory obligations. A separate supplier questionnaire is not required for organizations already collecting supplier data on the osapiens HUB.
For companies managing NIS2 alongside CSDDD, the same supplier profile covers both regulatory obligations without running parallel data collection processes.