Network and Information Security Directive (NIS2)

NIS2 requires medium-sized and large organizations in 18 EU sectors to implement documented cybersecurity risk management, hold management bodies personally accountable, and report significant security incidents to national authorities within strict timeframes. Fines reach up to €10 million or 2% of global annual turnover.

Next relevant deadline:

June 30, 2026: Essential entities in several EU member states must complete their first formal NIS2 compliance audit.

Substantive NIS2 obligations, including risk management, governance, supply chain security, and incident reporting, apply from the date each member state's national transposition law enters into force. For most EU countries, that point has already passed.

June 30, 2026 is the first formal verification checkpoint for essential entities in multiple member states: competent authorities assess whether governance structures are documented, risk assessments are complete, and incident response processes are operational. 

Essential entities face proactive (ex-ante) supervision under NIS2, meaning authorities can initiate audit requests without waiting for an incident or evidence of non-compliance. Important entities face reactive oversight but carry the same substantive obligations from the day their national transposition law entered into force.

Regulation timeline

16. January 2023

Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.

18. October 2024

EU Implementing Regulation (EU) 2024/2690 published in the Official Journal of the EU, entering into force on November 7, 2024. Specifies detailed technical and organizational requirements for digital-sector entities including DNS services, cloud providers, content delivery networks, and managed security service providers.

20. January 2026

European Commission proposes targeted amendments to NIS2 to increase legal clarity and simplify compliance, particularly for smaller entities. Core obligations unchanged. Legislative process ongoing as of June 2026.

Ongoing

National transposition status, registration portals, and audit cycles vary by member state. Organizations in jurisdictions that have not yet fully transposed should monitor the applicable national law and competent authority guidance.

17. October 2024

Deadline for EU member states to transpose NIS2 into national law. Substantive obligations apply to in-scope organizations in transposing member states from this date. Not all member states met the deadline; as of June 2026, the European Commission has referred several member states to the Court of Justice of the EU for failure to transpose.

6. December 2025

Germany's NIS2 implementation law (NIS2UmsuCG, the Act Implementing the NIS2 Directive and Regulating Essential Features of Information Security Management in the Federal Administration) enters into force, amending the Federal Office for Information Security Act (Bundesamt für Sicherheit in der Informationstechnik, BSIG). Approximately 29,500 entities fall within scope. Obligations apply immediately with no transition period. BSI registration deadline: March 6, 2026.

30. June 2026

Deadline for essential entities in several EU member states, including Hungary and Austria, to complete their first formal NIS2 compliance audit.

1 / 7
  • 2023
    16. January 2023

    Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.

  • 2024
    17. October 2024

    Deadline for EU member states to transpose NIS2 into national law. Substantive obligations apply to in-scope organizations in transposing member states from this date. Not all member states met the deadline; as of June 2026, the European Commission has referred several member states to the Court of Justice of the EU for failure to transpose.

  • 18. October 2024

    EU Implementing Regulation (EU) 2024/2690 published in the Official Journal of the EU, entering into force on November 7, 2024. Specifies detailed technical and organizational requirements for digital-sector entities including DNS services, cloud providers, content delivery networks, and managed security service providers.

  • 2025
    6. December 2025

    Germany's NIS2 implementation law (NIS2UmsuCG, the Act Implementing the NIS2 Directive and Regulating Essential Features of Information Security Management in the Federal Administration) enters into force, amending the Federal Office for Information Security Act (Bundesamt für Sicherheit in der Informationstechnik, BSIG). Approximately 29,500 entities fall within scope. Obligations apply immediately with no transition period. BSI registration deadline: March 6, 2026.

  • 2026
    20. January 2026

    European Commission proposes targeted amendments to NIS2 to increase legal clarity and simplify compliance, particularly for smaller entities. Core obligations unchanged. Legislative process ongoing as of June 2026.

  • 30. June 2026

    Deadline for essential entities in several EU member states, including Hungary and Austria, to complete their first formal NIS2 compliance audit.

  • Ongoing

    National transposition status, registration portals, and audit cycles vary by member state. Organizations in jurisdictions that have not yet fully transposed should monitor the applicable national law and competent authority guidance.

What the regulation requires

NIS2 (Directive (EU) 2022/2555) entered into force on January 16, 2023, with a member state transposition deadline of October 17, 2024. The directive applies to medium-sized and large organizations in 18 sectors. 

Essential entities are generally organizations in Annex I sectors, including energy, transport, healthcare, and digital infrastructure, with at least 250 employees or annual turnover above €50 million combined with a balance sheet above €43 million. 

Important entities are generally organizations in Annex I or Annex II sectors, including manufacturing, food, and chemicals, with at least 50 employees or annual turnover above €10 million combined with a balance sheet above €10 million. 

Both categories carry the same core obligations: documented, all-hazards risk management and technical security measures; a three-stage incident reporting process (24-hour early warning, 72-hour notification, one-month final report); and personal accountability for management bodies. Organizations must also assess and manage cybersecurity risks arising from suppliers and service providers that can affect their information security.

Common NIS2 implementation challenges

Scope determination depends on all economic activities, not primary sector alone

A company whose core sector sits outside NIS2's scope can still qualify if a secondary activity (such as operating a data center for group entities) falls within a covered sector. For international groups with legal entities in multiple EU member states, each entity requires a separate scope assessment, and the applicable supervisory authority, registration procedure, and audit cycle differ by jurisdiction.

NIS2 governance obligations extend beyond existing IT frameworks

NIS2 makes management bodies personally liable for approving and overseeing cybersecurity risk management measures. Organizations require defined cybersecurity roles and reporting lines, formal management approval of risk treatment decisions, and documented evidence that the management body receives regular cybersecurity briefings.

Third-party security data is rarely consolidated or structured

NIS2 requires organizations to assess and manage suppliers and service providers with access to or influence over their information systems. Identifying relevant suppliers, collecting structured security evidence, and running recurring assessments requires processes and tooling that existing ERP and procurement setups do not typically provide.

National NIS2 implementations differ significantly across member states

NIS2 is a directive: core obligations are consistent across the EU, but national implementation details vary significantly. 

Germany's transposition law entered into force on December 6, 2025, with a registration deadline of March 6, 2026; Belgium's requirements have been active since October 2024; Italy's first operational deadlines for security measure adoption fall in October 2026.

Structured NIS2 compliance across every obligation area

The osapiens HUB for NIS2 maps NIS2 obligations into structured processes built directly on the supplier and entity data already in the osapiens HUB Supplier Intelligence solution suite.

Capture NIS2 scope, run structured assessments, and track implementation progress across every obligation

Predefined NIS2 questionnaires go to relevant suppliers with AI-assigned risk scores and automated alerts from continuous news monitoring. Supplier profiles built for CSDDD due diligence are reused directly for NIS2 third-party risk assessments, without a separate supplier engagement process.

ADDITIONAL NIS2 RESOURCES

Frequently Asked Questions (FAQ)

 

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290026-CMH 1787050137 783828046


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290026-CMH 1787050137 783828046


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290026-CMH 1787050137 783828046


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290026-CMH 1787050137 783828046


Varnish cache server