Skip to content
GlanceDeskJurisdiction

Home › Law library › NIS2

EU

NIS2

Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive)

Sourced. Last verified 9 October 2026

European Union Cybersecurity

Status
In force since 16 Jan 2023; transposition deadline 17 Oct 2024 (NIS1 repealed 18 Oct 2024). Applies via national laws.
Who it applies to
Medium and large public/private entities in Annex I (high-criticality) and Annex II (other critical) sectors providing services in the EU; some (e.g. DNS, TLD registries, trust services, telecoms) regardless of size. Non-EU digital providers must appoint an EU representative.
Size thresholds
Size-cap rule: generally 50+ employees or over EUR 10m annual turnover/balance sheet (EU SME definition). Large entities in Annex I are usually 'essential'; others 'important'.
Regulator
National competent authorities and CSIRTs in each Member State; ENISA and the NIS Cooperation Group at EU level
Breach or incident reporting
Significant incidents to CSIRT/authority: early warning within 24h, incident notification within 72h, final report within 1 month of the notification. Inform service recipients where relevant.
Data protection officer
No named officer, but management bodies must approve and oversee cybersecurity measures, take training, and can be held personally liable.
Local representative
Certain non-EU digital providers (e.g. cloud, DNS, online marketplaces, search, social platforms) offering services in the EU must designate an EU representative by written mandate.
Maximum penalty
Essential entities: maximum of at least EUR 10m or 2% of worldwide turnover; important entities: at least EUR 7m or 1.4% (whichever higher). National caps may be higher.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

As of May 2026, 4 Member States had not transposed; on 8 Jul 2026 the Commission referred Ireland, Spain, France and the Netherlands to the CJEU. Commission proposed targeted NIS2 simplifications on 20 Jan 2026 (pending).

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].