NIS2, explained for the teams who have to comply.
NIS2 — Directive (EU) 2022/2555 — is the EU's baseline cybersecurity law for essential and important entities. It entered into force on 16 January 2023, with a transposition deadline of 17 October 2024. It reaches organisations in the Annex I and Annex II sectors that are medium-sized or larger, plus specific providers regardless of size.
Who is in scope
Scope has two doors: a size-and-sector door, and a set of size-independent categories.
The main rule in Article 2 brings in entities of a type listed in Annex I or Annex II that are medium-sized or larger — 50 or more staff, or turnover and balance sheet both above €10 million — and that provide services or carry out activities in the Union. Size follows Commission Recommendation 2003/361, aggregating partner and linked enterprises, and NIS2 disapplies that recommendation's small-enterprise exemption.
Separately, Article 2(2) to 2(4) bring some entities in regardless of size: providers of public electronic communications; trust service providers; TLD name registries and DNS providers; providers of domain name registration services; entities a Member State identifies as sole providers, as systemically significant, or as otherwise critical; central and regional public administration; and entities identified as critical under the CER Directive (EU) 2022/2557. Get the sector or a category right and the size question may not even arise.
What in-scope entities must do
Four duties, each anchored in a specific article of the directive.
Governance and training — Article 20
The management body must approve the cybersecurity risk-management measures, oversee their implementation, and can be held liable for infringements. Its members must follow training, and the entity is encouraged to offer similar training to staff regularly. Article 20
The ten risk-management measures — Article 21(2)
An all-hazards set of technical, operational and organisational measures, at least: (a) risk-analysis and information-system security policies; (b) incident handling; (c) business continuity, including backup, disaster recovery and crisis management; (d) supply-chain security; (e) secure acquisition, development and maintenance, including vulnerability handling and disclosure; (f) measuring the effectiveness of the measures; (g) basic cyber hygiene and training; (h) cryptography and, where appropriate, encryption; (i) human-resources security, access control and asset management; and (j) multi-factor or continuous authentication and secured communications where appropriate. Article 21
Incident reporting — Article 23
For a significant incident — one that causes or can cause severe operational disruption or financial loss, or considerable damage to others — the entity notifies its CSIRT or competent authority: an early warning within 24 hours of becoming aware, an incident notification within 72 hours, an intermediate report on request, and a final report within one month of the notification. Article 23
Registration — Article 3(4)
In-scope entities file their name, address, up-to-date contact details, sector and subsector, and the Member States where they provide services with the competent authority, and notify changes within two weeks. Article 3
Essential vs important entities
Same core duties; different supervision and different fine ceilings.
| Essential entity | Important entity | |
|---|---|---|
| Who | Large Annex I entities; qualified trust providers, TLD registries and DNS providers (any size); medium-or-larger public electronic-communications providers; central-government public administration; CER-critical entities. | Everyone else in scope — medium Annex I entities, Annex II entities, non-qualified trust providers, and Member-State-designated important entities. |
| Core duties | Articles 20, 21, 23 and 3(4) — identical. | Articles 20, 21, 23 and 3(4) — identical. |
| Supervision | Proactive and reactive: inspections, off-site supervision, regular and targeted audits, random checks and scans (Article 32). | Ex-post only: authorities act on evidence of non-compliance (Article 33). |
| Maximum fine | At least €10 million or 2% of total worldwide annual turnover, whichever is higher (Article 34). | At least €7 million or 1.4% of total worldwide annual turnover, whichever is higher (Article 34). |
A directive, not a regulation
The law that binds you is your Member State's implementation — and they vary.
NIS2 is a directive: it sets a floor that each Member State writes into national law, and that national law can be stricter. The transposition deadline was 17 October 2024, and several Member States met it late. The Netherlands' Cyberbeveiligingswet, for instance, enters into force on 15 August 2026. Until your national law is in force and you have read it, treat the directive as the shape of the obligations, not the exact text you are held to.
For financial entities, DORA (Regulation (EU) 2022/2554) is sector-specific Union law: where its cybersecurity and incident-reporting requirements are at least equivalent, the matching NIS2 provisions — including the Chapter VII supervision regime — do not apply to those entities (Article 4). Member States keep the lists of essential and important entities, first drawn up by 17 April 2025 and reviewed at least every two years (Article 3(3)). Ansvar serves national implementations where they are live — see coverage.
From scope question to cited gap analysis
Every answer is grounded in the article text, in the AI client your team already uses.
Start with the free NIS2 scope checker to see whether you are in scope and which tier you land in. When you are ready to build evidence, the free Article 21 gap analysis template gives you one row per measure, and the sample NIS2 gap analysis shows the full deliverable — an Article 21(2) register, incident-reporting readiness, and a remediation roadmap. The worked gap-analysis example traces every finding back to its ISO 27001, NIS2 and GDPR provision.
For the ISO-27001-versus-NIS2 question, the clause-by-clause mapping shows where an ISO 27001 certificate carries you and where the reporting clock, management liability and supplier diligence sit outside it.
NIS2 lands hardest in a few sectors. See the sector pages for energy, industrial / OT, and healthcare, each anchored on the duties that fall on essential and important entities.
Questions teams ask about NIS2
If your question is not here, email us — every message gets a human answer.
Does NIS2 apply to my company?
NIS2 applies if you provide services or carry out activities in the EU and you are either (1) a medium-sized or larger entity — 50+ staff, or turnover and balance sheet both above €10 million — in one of the Annex I or Annex II sectors, or (2) within one of the size-independent categories in Article 2(2) to 2(4), such as a public electronic-communications provider, a trust service provider, a TLD registry or DNS provider, a domain-name registration service, or an entity a Member State identifies as critical. Below the size threshold and outside those categories, you are generally out of scope — though Member States may extend the rules. The free checker walks this in two minutes.
What is the difference between an essential and an important entity?
Both tiers carry the same core duties — governance, the Article 21 risk-management measures, incident reporting, and registration. They differ on supervision and penalties. Essential entities (large Annex I entities; qualified trust providers, TLD registries and DNS providers of any size; medium-or-larger public electronic-communications providers; central-government public administration; and CER-critical entities) face proactive and reactive supervision under Article 32, and a fine ceiling of at least €10 million or 2% of worldwide turnover. Important entities — everyone else in scope — face ex-post supervision only under Article 33, and a ceiling of at least €7 million or 1.4% of worldwide turnover.
What are the ten NIS2 Article 21 security measures?
Article 21(2) lists ten minimum measures: (a) risk-analysis and information-system security policies; (b) incident handling; (c) business continuity, including backup management, disaster recovery and crisis management; (d) supply-chain security; (e) security in acquisition, development and maintenance, including vulnerability handling and disclosure; (f) policies to assess the effectiveness of the measures; (g) basic cyber hygiene and cybersecurity training; (h) cryptography and, where appropriate, encryption; (i) human-resources security, access control and asset management; and (j) multi-factor or continuous authentication and secured communications where appropriate.
What are the NIS2 incident-reporting deadlines?
Article 23 sets a staged clock for a significant incident — one that causes or could cause severe operational disruption or financial loss, or considerable damage to others. You send an early warning to your CSIRT or competent authority within 24 hours of becoming aware, a fuller incident notification within 72 hours, an intermediate report on request, and a final report within one month of the notification. Trust service providers have a 24-hour deadline for incidents affecting their trust services.
Does ISO 27001 make us NIS2 compliant?
No. An ISO 27001:2022 certificate is strong evidence for most of the Article 21(2) technical and organisational measures, but three NIS2 obligations sit outside the standard: the Article 23 legal reporting clock (24 hours / 72 hours / one month to a national authority), the Article 20 personal accountability and training duty for the management body, and the supplier-specific diligence in Article 21(2)(d) read with 21(3). Certification supports the measures; it does not replace the law. Our blog post maps every Article 21(2) measure to ISO 27001 Annex A and marks the three gaps.
What are the maximum NIS2 fines?
For infringing the Article 21 security measures or the Article 23 reporting duties, Article 34 sets the ceilings a Member State must at least provide for. Essential entities face a maximum of at least €10 million or at least 2% of the total worldwide annual turnover in the preceding financial year, whichever is higher. Important entities face a maximum of at least €7 million or at least 1.4% of total worldwide annual turnover, whichever is higher. National transposition can set higher figures.
Does a national law override NIS2?
NIS2 is a directive, so the law that binds you is your Member State's transposition, not the directive itself — and a transposition can be stricter than the floor NIS2 sets. The transposition deadline was 17 October 2024, and several Member States met it late; the Netherlands' Cyberbeveiligingswet, for example, enters into force on 15 August 2026. For financial entities, DORA (Regulation (EU) 2022/2554) is sector-specific Union law: where its requirements are at least equivalent, the matching NIS2 provisions do not apply to those entities (Article 4). Always check your national implementation.
See where you stand on NIS2
Two minutes in the free checker tells you whether NIS2 applies and which tier you land in — with every step cited to the directive. Then build the evidence with the free Article 21 template.