Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.
Network and Information Security Directive (NIS2)
NIS2 requires medium-sized and large organizations in 18 EU sectors to implement documented cybersecurity risk management, hold management bodies personally accountable, and report significant security incidents to national authorities within strict timeframes. Fines reach up to €10 million or 2% of global annual turnover.
Next relevant deadline:
June 30, 2026: Essential entities in several EU member states must complete their first formal NIS2 compliance audit.
Substantive NIS2 obligations, including risk management, governance, supply chain security, and incident reporting, apply from the date each member state's national transposition law enters into force. For most EU countries, that point has already passed.
June 30, 2026 is the first formal verification checkpoint for essential entities in multiple member states: competent authorities assess whether governance structures are documented, risk assessments are complete, and incident response processes are operational.
Essential entities face proactive (ex-ante) supervision under NIS2, meaning authorities can initiate audit requests without waiting for an incident or evidence of non-compliance. Important entities face reactive oversight but carry the same substantive obligations from the day their national transposition law entered into force.
Regulation timeline
What the regulation requires
NIS2 (Directive (EU) 2022/2555) entered into force on January 16, 2023, with a member state transposition deadline of October 17, 2024. The directive applies to medium-sized and large organizations in 18 sectors.
Essential entities are generally organizations in Annex I sectors, including energy, transport, healthcare, and digital infrastructure, with at least 250 employees or annual turnover above €50 million combined with a balance sheet above €43 million.
Important entities are generally organizations in Annex I or Annex II sectors, including manufacturing, food, and chemicals, with at least 50 employees or annual turnover above €10 million combined with a balance sheet above €10 million.
Both categories carry the same core obligations: documented, all-hazards risk management and technical security measures; a three-stage incident reporting process (24-hour early warning, 72-hour notification, one-month final report); and personal accountability for management bodies. Organizations must also assess and manage cybersecurity risks arising from suppliers and service providers that can affect their information security.
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server
Error 429 Too many requests
Too many requests
Error 54113
Details: cache-cmh1290087-CMH 1787057202 3547119566
Varnish cache server