Network and Information Security Directive (NIS2)

NIS2 requires medium-sized and large organizations in 18 EU sectors to implement documented cybersecurity risk management, hold management bodies personally accountable, and report significant security incidents to national authorities within strict timeframes. Fines reach up to €10 million or 2% of global annual turnover.

Next relevant deadline:

June 30, 2026: Essential entities in several EU member states must complete their first formal NIS2 compliance audit.

Substantive NIS2 obligations, including risk management, governance, supply chain security, and incident reporting, apply from the date each member state's national transposition law enters into force. For most EU countries, that point has already passed.

June 30, 2026 is the first formal verification checkpoint for essential entities in multiple member states: competent authorities assess whether governance structures are documented, risk assessments are complete, and incident response processes are operational. 

Essential entities face proactive (ex-ante) supervision under NIS2, meaning authorities can initiate audit requests without waiting for an incident or evidence of non-compliance. Important entities face reactive oversight but carry the same substantive obligations from the day their national transposition law entered into force.

Regulation timeline

16. January 2023

Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.

18. October 2024

EU Implementing Regulation (EU) 2024/2690 published in the Official Journal of the EU, entering into force on November 7, 2024. Specifies detailed technical and organizational requirements for digital-sector entities including DNS services, cloud providers, content delivery networks, and managed security service providers.

20. January 2026

European Commission proposes targeted amendments to NIS2 to increase legal clarity and simplify compliance, particularly for smaller entities. Core obligations unchanged. Legislative process ongoing as of June 2026.

Ongoing

National transposition status, registration portals, and audit cycles vary by member state. Organizations in jurisdictions that have not yet fully transposed should monitor the applicable national law and competent authority guidance.

17. October 2024

Deadline for EU member states to transpose NIS2 into national law. Substantive obligations apply to in-scope organizations in transposing member states from this date. Not all member states met the deadline; as of June 2026, the European Commission has referred several member states to the Court of Justice of the EU for failure to transpose.

6. December 2025

Germany's NIS2 implementation law (NIS2UmsuCG, the Act Implementing the NIS2 Directive and Regulating Essential Features of Information Security Management in the Federal Administration) enters into force, amending the Federal Office for Information Security Act (Bundesamt für Sicherheit in der Informationstechnik, BSIG). Approximately 29,500 entities fall within scope. Obligations apply immediately with no transition period. BSI registration deadline: March 6, 2026.

30. June 2026

Deadline for essential entities in several EU member states, including Hungary and Austria, to complete their first formal NIS2 compliance audit.

1 / 7
  • 2023
    16. January 2023

    Directive (EU) 2022/2555 (NIS2) enters into force. Replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), which had been in effect since 2016 but produced fragmented national implementations.

  • 2024
    17. October 2024

    Deadline for EU member states to transpose NIS2 into national law. Substantive obligations apply to in-scope organizations in transposing member states from this date. Not all member states met the deadline; as of June 2026, the European Commission has referred several member states to the Court of Justice of the EU for failure to transpose.

  • 18. October 2024

    EU Implementing Regulation (EU) 2024/2690 published in the Official Journal of the EU, entering into force on November 7, 2024. Specifies detailed technical and organizational requirements for digital-sector entities including DNS services, cloud providers, content delivery networks, and managed security service providers.

  • 2025
    6. December 2025

    Germany's NIS2 implementation law (NIS2UmsuCG, the Act Implementing the NIS2 Directive and Regulating Essential Features of Information Security Management in the Federal Administration) enters into force, amending the Federal Office for Information Security Act (Bundesamt für Sicherheit in der Informationstechnik, BSIG). Approximately 29,500 entities fall within scope. Obligations apply immediately with no transition period. BSI registration deadline: March 6, 2026.

  • 2026
    20. January 2026

    European Commission proposes targeted amendments to NIS2 to increase legal clarity and simplify compliance, particularly for smaller entities. Core obligations unchanged. Legislative process ongoing as of June 2026.

  • 30. June 2026

    Deadline for essential entities in several EU member states, including Hungary and Austria, to complete their first formal NIS2 compliance audit.

  • Ongoing

    National transposition status, registration portals, and audit cycles vary by member state. Organizations in jurisdictions that have not yet fully transposed should monitor the applicable national law and competent authority guidance.

What the regulation requires

NIS2 (Directive (EU) 2022/2555) entered into force on January 16, 2023, with a member state transposition deadline of October 17, 2024. The directive applies to medium-sized and large organizations in 18 sectors. 

Essential entities are generally organizations in Annex I sectors, including energy, transport, healthcare, and digital infrastructure, with at least 250 employees or annual turnover above €50 million combined with a balance sheet above €43 million. 

Important entities are generally organizations in Annex I or Annex II sectors, including manufacturing, food, and chemicals, with at least 50 employees or annual turnover above €10 million combined with a balance sheet above €10 million. 

Both categories carry the same core obligations: documented, all-hazards risk management and technical security measures; a three-stage incident reporting process (24-hour early warning, 72-hour notification, one-month final report); and personal accountability for management bodies. Organizations must also assess and manage cybersecurity risks arising from suppliers and service providers that can affect their information security.

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server

429 Too many requests

Error 429 Too many requests

Too many requests

Error 54113

Details: cache-cmh1290087-CMH 1787057202 3547119566


Varnish cache server