Home › Law library › NIS2
EU
NIS2
Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)
Sourced. Last verified 9 October 2026
European Union Cybersecurity
- Status
- In force since 16 Jan 2023; transposition deadline 17 Oct 2024 (NIS1 repealed 18 Oct 2024). Applies via national laws.
- Who it applies to
- Medium and large public/private entities in Annex I (high-criticality) and Annex II (other critical) sectors providing services in the EU; some (e.g. DNS, TLD registries, trust services, telecoms) regardless of size. Non-EU digital providers must appoint an EU representative.
- Size thresholds
- Size-cap rule: generally 50+ employees or over EUR 10m annual turnover/balance sheet (EU SME definition). Large entities in Annex I are usually 'essential'; others 'important'.
- Regulator
- National competent authorities and CSIRTs in each Member State; ENISA and the NIS Cooperation Group at EU level
- Breach or incident reporting
- Significant incidents to CSIRT/authority: early warning within 24h, incident notification within 72h, final report within 1 month of the notification. Inform service recipients where relevant.
- Data protection officer
- No named officer, but management bodies must approve and oversee cybersecurity measures, take training, and can be held personally liable.
- Local representative
- Certain non-EU digital providers (e.g. cloud, DNS, online marketplaces, search, social platforms) offering services in the EU must designate an EU representative by written mandate.
- Maximum penalty
- Essential entities: maximum of at least EUR 10m or 2% of worldwide turnover; important entities: at least EUR 7m or 1.4% (whichever higher). National caps may be higher.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- Check whether your sector (Annex I/II) and size bring you into scope; register with the national authority.
- Have management approve cybersecurity risk measures and complete training.
- Implement Art 21 measures: risk analysis, incident handling, backups, MFA, encryption, supply-chain security.
- Set up a process to send 24h early warnings and 72h notifications of significant incidents.
- Assess security of suppliers and service providers.
- Follow the national transposition law in each country where you operate.
Recent changes
As of May 2026, 4 Member States had not transposed; on 8 Jul 2026 the Commission referred Ireland, Spain, France and the Netherlands to the CJEU. Commission proposed targeted NIS2 simplifications on 20 Jan 2026 (pending).
Sources
- Primary source: https://digital-strategy.ec.europa.eu/en/policies/nis2-directive
- Second source: https://www.twobirds.com/en/insights/2025/understanding-key-eu-cybersecurity-legislative-acts-nis2,-cer,-and-cra
- Regulator: National competent authorities and CSIRTs in each Member State; ENISA and the NIS Cooperation Group at EU level
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].