Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.
Network and Information Security Directive (NIS2)
NIS2 requires medium-sized and large organizations in 18 EU sectors to implement documented cybersecurity risk management, hold management bodies personally accountable, and report significant security incidents to national authorities within strict timeframes. Fines reach up to €10 million or 2% of global annual turnover.
Next relevant deadline:
June 30, 2026: Essential entities in several EU member states must complete their first formal NIS2 compliance audit.
Substantive NIS2 obligations, including risk management, governance, supply chain security, and incident reporting, apply from the date each member state's national transposition law enters into force. For most EU countries, that point has already passed.
June 30, 2026 is the first formal verification checkpoint for essential entities in multiple member states: competent authorities assess whether governance structures are documented, risk assessments are complete, and incident response processes are operational.
Essential entities face proactive (ex-ante) supervision under NIS2, meaning authorities can initiate audit requests without waiting for an incident or evidence of non-compliance. Important entities face reactive oversight but carry the same substantive obligations from the day their national transposition law entered into force.
Regulation timeline
What the regulation requires
NIS2 (Directive (EU) 2022/2555) entered into force on January 16, 2023, with a member state transposition deadline of October 17, 2024. The directive applies to medium-sized and large organizations in 18 sectors.
Essential entities are generally organizations in Annex I sectors, including energy, transport, healthcare, and digital infrastructure, with at least 250 employees or annual turnover above €50 million combined with a balance sheet above €43 million.
Important entities are generally organizations in Annex I or Annex II sectors, including manufacturing, food, and chemicals, with at least 50 employees or annual turnover above €10 million combined with a balance sheet above €10 million.
Both categories carry the same core obligations: documented, all-hazards risk management and technical security measures; a three-stage incident reporting process (24-hour early warning, 72-hour notification, one-month final report); and personal accountability for management bodies. Organizations must also assess and manage cybersecurity risks arising from suppliers and service providers that can affect their information security.
Common NIS2 implementation challenges
Scope determination depends on all economic activities, not primary sector alone
A company whose core sector sits outside NIS2's scope can still qualify if a secondary activity (such as operating a data center for group entities) falls within a covered sector. For international groups with legal entities in multiple EU member states, each entity requires a separate scope assessment, and the applicable supervisory authority, registration procedure, and audit cycle differ by jurisdiction.
NIS2 governance obligations extend beyond existing IT frameworks
NIS2 makes management bodies personally liable for approving and overseeing cybersecurity risk management measures. Organizations require defined cybersecurity roles and reporting lines, formal management approval of risk treatment decisions, and documented evidence that the management body receives regular cybersecurity briefings.
Third-party security data is rarely consolidated or structured
NIS2 requires organizations to assess and manage suppliers and service providers with access to or influence over their information systems. Identifying relevant suppliers, collecting structured security evidence, and running recurring assessments requires processes and tooling that existing ERP and procurement setups do not typically provide.
National NIS2 implementations differ significantly across member states
NIS2 is a directive: core obligations are consistent across the EU, but national implementation details vary significantly.
Germany's transposition law entered into force on December 6, 2025, with a registration deadline of March 6, 2026; Belgium's requirements have been active since October 2024; Italy's first operational deadlines for security measure adoption fall in October 2026.
Structured NIS2 compliance across every obligation area
The osapiens HUB for NIS2 maps NIS2 obligations into structured processes built directly on the supplier and entity data already in the osapiens HUB Supplier Intelligence solution suite.
Capture NIS2 scope, run structured assessments, and track implementation progress across every obligation
Predefined NIS2 questionnaires go to relevant suppliers with AI-assigned risk scores and automated alerts from continuous news monitoring. Supplier profiles built for CSDDD due diligence are reused directly for NIS2 third-party risk assessments, without a separate supplier engagement process.
Manage incidents through standardized workflows that produce audit-ready reporting outputs
The osapiens HUB for NIS2 provides policy templates covering governance, incident management, vulnerability management, and supplier security requirements. Significant incidents are captured and managed through standardized workflows that produce the structured outputs required for the three-stage incident reporting timeline.
Surface NIS2 compliance status in the Reporting Cockpit alongside all other regulatory obligations
Risk assessments, treatment decisions, supplier evaluations, and incident records are stored with full traceability and version control. NIS2 risk and compliance status surfaces in the Reporting Cockpit for executive and supervisory reporting, without manual data extraction from the osapiens HUB.
ADDITIONAL NIS2 RESOURCES
Frequently Asked Questions (FAQ)
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290026-CMH 1787050137 783828046
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290026-CMH 1787050137 783828046
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290026-CMH 1787050137 783828046
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290026-CMH 1787050137 783828046
Varnish cache server